
EC-CouncilCertified Application Security Engineer (Java)
Domain 6Objective 1
Session Management Techniques CASEJAVA Practice Questions (Page 4)
Part of the Secure Coding: Session Management domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 16–20
- 16
What is the primary purpose of session management in a web application?
Select an answer first - 17
Which Java EE annotation or configuration can be used to set the session timeout for a servlet?
Select an answer first - 18
A Java servlet application uses HttpSession to store user data after login. The developer notices that the session ID remains the same before and after login. Which code change should be made to improve security?
Select an answer first - 19
In Java EE, which method is used to invalidate an HttpSession?
Select an answer first - 20
A security tester discovers that a Java application's session cookie is not marked HttpOnly, and the application has a stored XSS vulnerability. The tester is able to steal the session cookie via JavaScript. Which combination of fixes would most effectively mitigate this attack chain?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.