Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 2Objective 1

Security Requirements Gathering CASEJAVA Practice Questions (Page 6)

Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
5concepts

Questions 26–30

  1. 26application · easy

    A security analyst is writing security requirements for a Java-based API. Which requirement statement is most testable?

    Select an answer first
  2. 27expert · hard

    A security consultant is gathering security requirements for a Java-based application that will be deployed in a public cloud environment. The client is subject to GDPR and also has internal policies requiring encryption of data at rest. The consultant must identify all relevant sources. Which combination of sources is most appropriate?

    Select an answer first
  3. 28application · medium

    A security analyst is validating the security requirements for a Java-based e-commerce site. The requirements include PCI-DSS compliance, encryption of customer data, and a custom authentication scheme. During validation, the analyst discovers that the custom authentication scheme does not meet PCI-DSS requirements. What should the analyst do?

    Select an answer first
  4. 29expert · hard

    A security analyst is eliciting security requirements for a Java-based application in a large enterprise. The stakeholders have conflicting priorities: the security team wants strict controls, the business wants rapid feature delivery, and operations wants minimal downtime. The analyst must gather requirements that are feasible and aligned. Which approach is most effective?

    Select an answer first
  5. 30application · medium

    During security requirements analysis for a Java web application, the team identifies two requirements: (1) mandatory two-factor authentication for all users, and (2) a frictionless login experience to maximize user adoption. These requirements conflict. What is the best approach to resolve this conflict?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.