
EC-CouncilCertified Application Security Engineer (Java)
Domain 1Objective 1
Understanding Application Security, Threats, and Attacks CASEJAVA Practice Questions (Page 5)
Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 21–25
- 21
Which attack vector occurs when an attacker tricks a user's browser into sending an unwanted request to a web application in which the user is authenticated?
Select an answer first - 22
A Java application has a large attack surface due to many legacy endpoints. The team wants to reduce risk without breaking existing clients. Which approach is most effective?
Select an answer first - 23
Which security principle states that a user or process should be granted only the minimum privileges necessary to perform its function?
Select an answer first - 24
A threat modeling team is using the DREAD model to evaluate a Java application's risks. Which of the following is a DREAD rating category?
Select an answer first - 25
A software development team is adopting a new SDLC process. They want to integrate security activities early in the lifecycle to reduce the cost and impact of vulnerabilities. Which approach best reflects the importance of application security in the SDLC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.