
EC-CouncilCertified Application Security Engineer (Java)
Domain 8Objective 1
Static and Dynamic Application Security Testing (SAST and DAST) CASEJAVA Practice Questions (Page 11)
Part of the Security Testing and Secure Deployment domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
11concepts
Questions 51–55
- 51
A Java developer is reviewing a SAST report that flags a potential path traversal vulnerability. The code reads a user-supplied filename and uses it to open a file. The developer notices that the SAST tool traced the input from the HTTP request through several method calls to the file operation. Which SAST technique is the tool using?
Select an answer first - 52
A security team is configuring a SAST tool for a Java codebase. The tool produces many findings that are not actually exploitable because the code is legacy and uses patterns the scanner does not understand. The team wants to reduce noise while still catching real issues. What is the best approach?
Select an answer first - 53
A security team is using SAST and DAST for a Java application. They have noticed that SAST reports many false positives, and DAST misses some vulnerabilities that are only visible in the source code. The team wants to improve their testing program. What is the most effective way to address these limitations?
Select an answer first - 54
Which of the following is a limitation of SAST?
Select an answer first - 55
A SAST tool reports a high-severity SQL injection finding in a legacy Java module. The development team argues that the module is not exposed to user input because it is only called internally by other services. The security team must decide how to handle the finding. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CASEJAVA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.