
EC-CouncilCertified Application Security Engineer (Java)
Domain 2Objective 3
Threat Modeling CASEJAVA Practice Questions (Page 3)
Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 11–15
- 11
A Java application logs all user actions, including financial transactions. The threat model identifies a risk that a user could deny performing a transaction. Which STRIDE category does this threat fall under, and what is the best mitigation?
Select an answer first - 12
A team is decomposing a Java application for threat modeling. The application has a web frontend, a REST API, a message queue, and a worker process that processes messages. The team is creating a data flow diagram (DFD). Which of the following is the most accurate way to represent the message queue in the DFD?
Select an answer first - 13
A Java application allows users to upload files that are then processed by a backend service. The threat model identifies a threat where an attacker uploads a file with a malicious payload that is executed by the backend. The team is considering two mitigations: (1) scan all uploads with an antivirus engine, and (2) run the backend service in a sandboxed environment. The team has budget for only one mitigation. Which mitigation is more effective in reducing the risk?
Select an answer first - 14
Why is it important to document a threat model clearly?
Select an answer first - 15
In threat modeling, what is an entry point?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.