Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Application Security Engineer (Java)

Domain 1Objective 1

Understanding Application Security, Threats, and Attacks CASEJAVA Practice Questions (Page 9)

Part of the Application Security Foundations domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 41–42

  1. 41application · medium

    A Java web application exposes a REST API that allows users to update their profile information. The API also includes an administrative endpoint that is not documented but is accessible without authentication. During an attack surface analysis, which entry point should be considered the highest risk?

    Select an answer first
  2. 42expert · medium

    A Java application has a vulnerability that allows an attacker to perform a CSRF attack to change a user's email address. The application uses a session cookie for authentication. Which control would be most effective in mitigating this vulnerability?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CASEJAVA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CASEJAVA” is a trademark of its owner, used for identification only.