
EC-CouncilCertified Application Security Engineer (Java)
Domain 8Objective 1
Static and Dynamic Application Security Testing (SAST and DAST) CASEJAVA Practice Questions (Page 5)
Part of the Security Testing and Secure Deployment domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 3–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
11concepts
Questions 21–25
- 21
What is the primary purpose of Static Application Security Testing (SAST)?
Select an answer first - 22
When interpreting DAST results, what does it mean to correlate findings with attack scenarios?
Select an answer first - 23
A DAST scan of a Java web application reports a potential command injection in a file upload feature. The scanner sent a payload that caused the application to execute a system command. The security analyst wants to confirm the vulnerability is real and not a false positive. What should the analyst do?
Select an answer first - 24
A SAST scan of a Java application reports a high-severity finding in a method that is called only from a background job that runs with elevated privileges. The finding is a potential SQL injection. The developer argues that the input to the method comes from a trusted internal queue, not from user input. The security team must decide whether to require a fix before release. What is the best decision?
Select an answer first - 25
What is a best practice for configuring SAST tools to reduce false positives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.