Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 2Objective 3

Threat Modeling CASEJAVA Practice Questions (Page 7)

Part of the Security Requirements and Secure Design domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
9concepts

Questions 31–35

  1. 31foundation · easy

    What is the primary purpose of threat modeling in the secure software development lifecycle?

    Select an answer first
  2. 32application · easy

    A team is creating a data flow diagram for a Java application that allows users to upload and share documents. They have identified a data flow from the user's browser to the web server, then to the application server, and finally to the database. Which element of the DFD should be used to represent the user's browser?

    Select an answer first
  3. 33application · easy

    During threat modeling of a Java application, the team is identifying assets and entry points. They have listed the following: user credentials, the login form, the database, and the REST API. Which of these is an entry point?

    Select an answer first
  4. 34application · easy

    A security team is evaluating threat modeling methodologies. They need a methodology that is simple to use and focuses on categorizing threats into six categories. Which methodology is the best fit?

    Select an answer first
  5. 35application · medium

    A Java-based e-commerce application allows customers to upload profile images. The images are stored in an Azure Blob Storage container with public read access, and the application generates a signed URL for each upload. During a threat modeling session, the team identifies that an attacker could upload a malicious file that is later served to other users. Which STRIDE category best describes this threat, and what is the most appropriate mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.