Eccouncil Certified Application Security Engineer (CASE) JAVA 312-96 Exam Practice Test

Page: 1 / 14
Total 47 questions
Question 1

Ted is an application security engineer who ensures application security activities are being followed during the entire lifecycle of the project. One day, he was analyzing various interactions of users depicted in the use cases of the project under inception. Based on the use case in hand, he started depicting the scenarios where attacker could misuse the application. Can you identify the activity on which Ted is working?



Answer : A


Question 2

The threat modeling phase where applications are decomposed and their entry points are reviewed from an attacker's perspective is known as ________



Answer : A


Question 3

Jacob, a Security Engineer of the testing team, was inspecting the source code to find security vulnerabilities.

Which type of security assessment activity Jacob is currently performing?



Answer : D


Question 4

A US-based ecommerce company has developed their website www.ec-sell.com to sell their products online. The website has a feature that allows their customer to search products based on the price. Recently, a bug bounty has discovered a security flaw in the Search page of the website, where he could see all products from the database table when he altered the website URL http://www.ec-sell.com/products.jsp?val=100 to http://www.ec-sell.com/products.jsp?val=200 OR '1'='1 -. The product.jsp page is vulnerable to



Answer : C


Question 5

Which line of the following example of Java Code can make application vulnerable to a session attack?



Answer : B


Question 6

Identify the type of attack depicted in the figure below:



Answer : D


Question 7

Oliver is a web server admin and wants to configure the Tomcat server in such a way that it should not serve index pages in the absence of welcome files. Which of the following settings in CATALINA_HOME/conf/ in web.xml will solve his problem?



Answer : B


Page:    1 / 14   
Total 47 questions