
EC-CouncilCertified Application Security Engineer (Java)
Domain 1Objective 1
Understanding Application Security, Threats, and Attacks CASEJAVA Practice Questions (Page 4)
Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 16–20
- 16
Which of the following is an example of an attack surface entry point in a web application?
Select an answer first - 17
A team is analyzing a Java web application's attack surface. The application exposes a public REST API, an admin console on an internal network, and a file upload feature. Which action would most effectively reduce the attack surface?
Select an answer first - 18
During a risk assessment, a team identifies two threats: (1) a SQL injection vulnerability in a public-facing login form, and (2) a verbose error message that reveals stack traces to authenticated users. Which threat should be prioritized for remediation?
Select an answer first - 19
A development team is under pressure to release a new feature quickly. The security team wants to ensure that security is not compromised. Which approach best balances speed and security?
Select an answer first - 20
A Java web application uses a session cookie without the Secure and HttpOnly flags. An attacker exploits this to steal a user's session token. Which attack vector is being exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.