
EC-CouncilCertified Application Security Engineer (Java)
Domain 8Objective 1
Static and Dynamic Application Security Testing (SAST and DAST) CASEJAVA Practice Questions (Page 10)
Part of the Security Testing and Secure Deployment domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
11concepts
Questions 46–50
- 46
A development team is adopting SAST in a large legacy Java codebase. The initial scan produces thousands of findings, many of which are false positives. The team is overwhelmed and considering abandoning the tool. What is the best strategy to make the SAST program sustainable?
Select an answer first - 47
Which of the following is a key difference between SAST and DAST?
Select an answer first - 48
What is the primary purpose of Dynamic Application Security Testing (DAST)?
Select an answer first - 49
A security team uses SAST and DAST in their SDLC. They want to reduce the number of false positives reported by SAST without missing real vulnerabilities. Which practice is most effective?
Select an answer first - 50
How can SAST be integrated into a CI/CD pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.