
EC-CouncilCertified Application Security Engineer (Java)
Domain 8Objective 1
Static and Dynamic Application Security Testing (SAST and DAST) CASEJAVA Practice Questions (Page 1)
Part of the Security Testing and Secure Deployment domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
11concepts
Questions 1–5
- 1
Which of the following is a limitation of SAST compared to DAST?
Select an answer first - 2
A security team is planning DAST scans for a Java application. The application has a staging environment that is not a perfect replica of production; some production-only features are not available in staging. The team wants to maximize coverage without risking production downtime. What is the best approach?
Select an answer first - 3
Why is DAST often performed in a production-like environment?
Select an answer first - 4
A security team has implemented both SAST and DAST in their SDLC. They still find vulnerabilities that neither tool detects, such as business logic flaws that require multiple steps to exploit. What is the most appropriate complementary testing method to address this gap?
Select an answer first - 5
Which of the following is a common SAST tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.