
EC-CouncilCertified Application Security Engineer (Java)
Domain 8Objective 1
Static and Dynamic Application Security Testing (SAST and DAST) CASEJAVA Practice Questions (Page 3)
Part of the Security Testing and Secure Deployment domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
11concepts
Questions 11–15
- 11
A development team wants to reduce the number of security defects reaching the code review stage. They have a SAST tool that can run locally. Which integration point is most effective for catching vulnerabilities before a developer commits code?
Select an answer first - 12
Which of the following is a common DAST tool?
Select an answer first - 13
A security team wants to run DAST against a Java application that is deployed in a staging environment. The application requires authentication to access most features. What is the most important configuration step to ensure the DAST scan is effective?
Select an answer first - 14
A SAST scan of a Java application reports a potential SQL injection in a method that builds a query using string concatenation. The developer reviews the code and sees that the input is sanitized with a custom function that escapes single quotes. The SAST tool does not recognize the sanitization. What is the most appropriate action?
Select an answer first - 15
In which environment is DAST typically performed to test the application before production release?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.