Skip to content

312-96 Certified Application Security Engineer (CASE) - Java Practice Questions

Prepare for 312-96 with more than an answer.

244 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$330 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 10
  1. Understanding Application Security, Threats, and Attacks15%
  2. Security Requirements Gathering10%
  3. Secure Application Design and Architecture15%
  4. Secure Coding Practices for Input Validation12%
  5. Secure Coding Practices for Authentication and Authorization12%
  6. Secure Coding Practices for Cryptography10%
  7. Secure Coding Practices for Session Management10%
  8. Secure Coding Practices for Error Handling8%
  9. Static and Dynamic Application Security Testing (SAST & DAST)10%
  10. Secure Deployment and Maintenance8%
  1. 1

    A security engineer is configuring a Content Security Policy (CSP) for a Java web application to mitigate XSS attacks. The application needs to load scripts from its own domain and from https://apis.google.com. Which is the correct CSP directive to achieve this?

    Show answer details

    Correct answer: C

    The script-src directive controls which sources are allowed for JavaScript. The 'self' keyword permits scripts from the same origin (domain). Adding https://apis.google.com explicitly whitelists that domain as an additional valid source. This configuration correctly and securely enforces the stated requirement without allowing dangerous practices like 'unsafe-inline'.

  2. 2

    A developer is writing a Java servlet that handles sensitive user data. To prevent Cross-Site Request Forgery (CSRF), they decide to implement the synchronizer token pattern. Which of the following are essential steps in a correct implementation of this pattern? (Select TWO)

    Show answer details

    Correct answer: A, B

    This is the core of the pattern. A unique, unpredictable token is generated per-session (or per-request) and tied to the user's session on the server. It is then sent to the client to be included in subsequent state-changing requests.

    This is the validation step. The server must compare the token submitted by the client with the one it has stored for that user's session. If they match, the request is considered legitimate. If they don't match or the token is missing, the request is rejected.

  3. 3

    A DAST tool reports a possible XML External Entity (XXE) injection vulnerability in a Java application that parses XML documents. The vulnerable code uses javax.xml.parsers.DocumentBuilderFactory. What is the most effective way to configure the DocumentBuilderFactory to prevent XXE attacks?

    Show answer details

    Correct answer: A

    This is the most comprehensive and recommended approach. Setting disallow-doctype-decl to true completely disables DOCTYPE declarations, which is the root cause of XXE. Additionally, explicitly disabling external general and parameter entities provides a strong defense-in-depth strategy, protecting the parser even if DOCTYPE declarations are allowed for other reasons.

  4. 4

    A company's security policy mandates that all third-party libraries used in their Java projects must be scanned for known vulnerabilities. This process needs to be automated and integrated into their Maven build lifecycle. Which tool is most suitable for this purpose?

    Show answer details

    Correct answer: B

    OWASP Dependency-Check is a Software Composition Analysis (SCA) tool that specifically identifies project dependencies and checks if there are any known, publicly disclosed vulnerabilities (CVEs). It has a dedicated Maven plugin that can be configured to run during the build process and can even fail the build if vulnerabilities exceeding a certain severity are found.

  5. 5

    Which Java security principle dictates that a module of code should only have access to the information and resources that are necessary for its legitimate purpose?

    graph TD subgraph UserSpace[User Space] App[Application Code] Lib[Library Code] end subgraph KernelSpace[Kernel Space] FS[File System] Net[Network Stack] Mem[Memory Manager] end App -- Limited Access --> Lib Lib -- System Calls --> FS Lib -- System Calls --> Net style App fill:#f9f,stroke:#333,stroke-width:2px style Lib fill:#ccf,stroke:#333,stroke-width:2px
    Show answer details

    Correct answer: C

    The Principle of Least Privilege is a fundamental computer security concept that states that a user, program, or process should have only the minimum privileges necessary to perform its function. This minimizes the potential damage from a security breach or an accidental error.

  6. 6

    A financial services company is developing a Java application that processes international payments and must handle user data containing various Unicode characters. To prevent Cross-Site Scripting (XSS), a developer implements a filter using String.replace() to remove occurrences of and from all input fields. Which of the following statements best describes the primary security flaw in this approach?

    Show answer details

    Correct answer: B

    Blacklist validation is fundamentally flawed because it is impossible to anticipate all possible malicious inputs. Attackers can use various techniques like case variations ( ), different encodings, or alternative vectors like to bypass simple string replacement. The correct approach is to use a combination of whitelist validation for input and context-aware output encoding.

  7. 7

    A security team is integrating a Static Application Security Testing (SAST) tool into the CI/CD pipeline for a large Java microservices project. The initial scans produce a high volume of findings, many of which are deemed false positives by the development team, causing friction and delays. Which TWO of the following actions represent the most effective strategies for managing SAST results and improving the DevSecOps workflow? (Select TWO)

    Show answer details

    Correct answer: B, C

    A structured triage process is crucial for managing SAST findings. It allows the team to systematically review, classify, and suppress non-issues, making the results more relevant and actionable over time.

    Focusing on new vulnerabilities (delta scanning) in pull requests makes the feedback immediate and relevant to the developer's current changes. This 'shift-left' approach prevents new technical debt and is less overwhelming than scanning the full codebase on every commit.

  8. 8

    A developer is building a secure file upload feature for a Java web application. The application needs to store user-uploaded files on a server filesystem. To prevent directory traversal attacks (e.g., ../../etc/passwd), the developer uses the getCanonicalPath() method to resolve the final path before writing the file. Is this approach, by itself, sufficient to prevent directory traversal attacks?

    Show answer details

    Correct answer: B

    False. While using getCanonicalPath() and then validating that the result starts with the expected base directory is a key part of the defense, it is not sufficient on its own. An attacker could still use null byte injection (filename.zip%00.txt) in older versions of Java to bypass checks performed on the filename string after canonicalization. A robust solution requires multiple layers: validating the filename against a strict whitelist of characters, using getCanonicalPath(), and ensuring the resulting path is within the intended storage directory.

  9. 9

    A DevOps engineer is tasked with securing a containerized Java application deployed on a Kubernetes cluster. The application uses a log4j2.xml configuration file to manage logging. The engineer wants to prevent sensitive information, such as API keys and database credentials stored in environment variables, from being accidentally written to the application logs. Which Log4j2 feature should be used to accomplish this?

    ________ {env:API_KEY}

    Show answer details

    Correct answer: D

    Log4j2's property substitution feature allows referencing external sources like environment variables. To prevent accidental logging of a secret, you can provide a default value (e.g., :-[REDACTED]) that will be used if the environment variable is not found. The most robust approach for redaction is using rewrite policies or filters, but based on the provided code snippet, the blank represents the mechanism for substituting properties. The correct syntax would be ${env:API_KEY:-[REDACTED]}. The option describes this mechanism.

  10. 10

    Case Study

    A retail company, StyleSphere, is modernizing its e-commerce platform. The new architecture is based on Java microservices running in Docker containers and managed by Kubernetes. A central 'Auth Service' is responsible for user authentication and issues JSON Web Tokens (JWTs). Other microservices, such as 'Product Service' and 'Order Service', validate these JWTs to authorize user requests.

    The security architect has outlined the following requirements for the JWT implementation:

    1. Tokens must be protected against tampering.
    2. The identity of the token issuer (the Auth Service) must be verifiable.
    3. Tokens must have a limited lifespan to reduce the impact of a compromised token.
    4. The system must be able to handle a high volume of authentication requests without overloading the Auth Service with validation calls.

    During a design review, a debate arises about the best way to sign the JWTs. The team is considering two options: HMAC with a shared secret (HS256) and RSA with a public/private key pair (RS256). Given the microservices architecture and requirements, which signing algorithm is the most appropriate choice and why?

    Show answer details

    Correct answer: B

    In a distributed microservices architecture, using an asymmetric algorithm like RS256 is superior for security. The Auth Service is the single entity that holds the private key and can create (sign) tokens. All other services only need the public key to validate tokens. This adheres to the principle of least privilege, as a compromise of a downstream service (e.g., Product Service) will not lead to a compromise of the signing key. With HS256, every service that validates tokens must also possess the shared secret, increasing the attack surface and the risk of the secret key being leaked, which would allow an attacker to forge valid tokens.

Create an account to continue.