
EC-CouncilCertified Application Security Engineer (Java)
Domain 1Objective 1
Understanding Application Security, Threats, and Attacks CASEJAVA Practice Questions (Page 6)
Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 26–30
- 26
A Java application has a critical vulnerability that is highly exploitable and could lead to a data breach. The fix requires a significant refactor and would delay the release by two weeks. Management wants to release on time. What is the most appropriate risk treatment?
Select an answer first - 27
In a basic risk assessment, how is risk typically calculated?
Select an answer first - 28
A Java web application uses a session cookie that does not have the Secure or HttpOnly flags set. An attacker can execute JavaScript in the context of the application through a stored XSS vulnerability. Which attack is the attacker most likely to perform?
Select an answer first - 29
A security architect is using STRIDE to threat model a Java web application. They are analyzing the data flow between the web server and the database server. Which threat category is most relevant to the risk of an attacker intercepting and reading the data transmitted between these components?
Select an answer first - 30
A Java web application has multiple entry points: a public login page, a REST API for mobile clients, an admin panel accessible only from the internal network, and a file upload feature. The security team is conducting an attack surface analysis. Which entry point should be considered the highest risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.