
EC-CouncilCertified Application Security Engineer (Java)
Domain 1Objective 3
Software Security Standards, Models, and Frameworks CASEJAVA Practice Questions (Page 4)
Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
3concepts
Questions 16–19
- 16
A healthcare organization is developing a Java application that handles patient records. It must comply with data protection regulations. The security architect decides to use ISO/IEC 27034 as a guide. Which aspect of ISO/IEC 27034 is most directly relevant to ensuring the application meets regulatory requirements?
Select an answer first - 17
According to ISO/IEC 27034, what is the primary purpose of the 'Application Security Control' (ASC) concept?
Select an answer first - 18
A software application must ensure that data is not modified by unauthorized users and that transactions are well-formed. Which security model best fits these requirements?
Select an answer first - 19
A large enterprise is adopting OWASP SAMM to improve its software security. The team has limited resources and must prioritize which SAMM practices to implement first. They have identified that their biggest risk is SQL injection in their Java applications. Which SAMM practice should they prioritize?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CASEJAVA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.