Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 6Objective 1

Session Management Techniques CASEJAVA Practice Questions (Page 1)

Part of the Secure Coding: Session Management domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
9concepts

Questions 1–5

  1. 1expert · hard

    A Spring Boot application uses Spring Security and is deployed behind a reverse proxy that handles SSL. The application sets the session cookie with the Secure flag. Users on HTTPS connections are still able to log in, but the session cookie is not being set in the browser. What is the most likely cause?

    Select an answer first
  2. 2foundation · easy

    Which testing technique is used to determine if a session ID is predictable?

    Select an answer first
  3. 3expert · hard

    A security audit of a Java application finds that session IDs are generated using java.util.Random seeded with the current time. The application is high-traffic and requires low latency. Which remediation is the best balance of security and performance?

    Select an answer first
  4. 4application · medium

    A Spring Security application uses form login. The security team wants to ensure that a session fixation attack cannot succeed. Which Spring Security feature should be enabled?

    Select an answer first
  5. 5foundation · easy

    Why should a session ID cookie be transmitted only over HTTPS?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.