Certified Application Security Engineer (CASE) - Java Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 244 questions. Use the simulator for timed and flashcard mode.

Try Simulator

312-96 Sample Questions

  1. Question 1

    Q1

    A financial services company is developing a Java application that processes international payments and must handle user data containing various Unicode characters. To prevent Cross-Site Scripting (XSS), a developer implements a filter using String.replace() to remove occurrences of and from all input fields. Which of the following statements best describes the primary security flaw in this approach?

    Show answer & explanation

    Correct answer: B

    Blacklist validation is fundamentally flawed because it is impossible to anticipate all possible malicious inputs. Attackers can use various techniques like case variations ( ), different encodings, or alternative vectors like to bypass simple string replacement. The correct approach is to use a combination of whitelist validation for input and context-aware output encoding.

  2. Question 2

    Q2Multiple answers

    A security team is integrating a Static Application Security Testing (SAST) tool into the CI/CD pipeline for a large Java microservices project. The initial scans produce a high volume of findings, many of which are deemed false positives by the development team, causing friction and delays. Which TWO of the following actions represent the most effective strategies for managing SAST results and improving the DevSecOps workflow? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    A structured triage process is crucial for managing SAST findings. It allows the team to systematically review, classify, and suppress non-issues, making the results more relevant and actionable over time.

    Focusing on new vulnerabilities (delta scanning) in pull requests makes the feedback immediate and relevant to the developer's current changes. This 'shift-left' approach prevents new technical debt and is less overwhelming than scanning the full codebase on every commit.

  3. Question 3

    Q3

    A developer is building a secure file upload feature for a Java web application. The application needs to store user-uploaded files on a server filesystem. To prevent directory traversal attacks (e.g., ../../etc/passwd), the developer uses the getCanonicalPath() method to resolve the final path before writing the file. Is this approach, by itself, sufficient to prevent directory traversal attacks?

    Show answer & explanation

    Correct answer: B

    False. While using getCanonicalPath() and then validating that the result starts with the expected base directory is a key part of the defense, it is not sufficient on its own. An attacker could still use null byte injection (filename.zip%00.txt) in older versions of Java to bypass checks performed on the filename string after canonicalization. A robust solution requires multiple layers: validating the filename against a strict whitelist of characters, using getCanonicalPath(), and ensuring the resulting path is within the intended storage directory.

  4. Question 4

    Q4

    A DevOps engineer is tasked with securing a containerized Java application deployed on a Kubernetes cluster. The application uses a log4j2.xml configuration file to manage logging. The engineer wants to prevent sensitive information, such as API keys and database credentials stored in environment variables, from being accidentally written to the application logs. Which Log4j2 feature should be used to accomplish this?

    ________ {env:API_KEY}

    Show answer & explanation

    Correct answer: D

    Log4j2's property substitution feature allows referencing external sources like environment variables. To prevent accidental logging of a secret, you can provide a default value (e.g., :-[REDACTED]) that will be used if the environment variable is not found. The most robust approach for redaction is using rewrite policies or filters, but based on the provided code snippet, the blank represents the mechanism for substituting properties. The correct syntax would be ${env:API_KEY:-[REDACTED]}. The option describes this mechanism.

  5. Question 5

    Q5

    Case Study

    A retail company, StyleSphere, is modernizing its e-commerce platform. The new architecture is based on Java microservices running in Docker containers and managed by Kubernetes. A central 'Auth Service' is responsible for user authentication and issues JSON Web Tokens (JWTs). Other microservices, such as 'Product Service' and 'Order Service', validate these JWTs to authorize user requests.

    The security architect has outlined the following requirements for the JWT implementation:

    1. Tokens must be protected against tampering.
    2. The identity of the token issuer (the Auth Service) must be verifiable.
    3. Tokens must have a limited lifespan to reduce the impact of a compromised token.
    4. The system must be able to handle a high volume of authentication requests without overloading the Auth Service with validation calls.

    During a design review, a debate arises about the best way to sign the JWTs. The team is considering two options: HMAC with a shared secret (HS256) and RSA with a public/private key pair (RS256). Given the microservices architecture and requirements, which signing algorithm is the most appropriate choice and why?

    Show answer & explanation

    Correct answer: B

    In a distributed microservices architecture, using an asymmetric algorithm like RS256 is superior for security. The Auth Service is the single entity that holds the private key and can create (sign) tokens. All other services only need the public key to validate tokens. This adheres to the principle of least privilege, as a compromise of a downstream service (e.g., Product Service) will not lead to a compromise of the signing key. With HS256, every service that validates tokens must also possess the shared secret, increasing the attack surface and the risk of the secret key being leaked, which would allow an attacker to forge valid tokens.

  6. Question 6

    Q6

    A Java application uses the Java Cryptography Architecture (JCA) to encrypt sensitive data using AES. The development team wants to ensure the application can support strong encryption algorithms that may not be included in the default JDK distribution, and they want to do this without modifying the java.security file in the JDK installation. What is the standard mechanism in Java to achieve this?

    Show answer & explanation

    Correct answer: B

    The Java Cryptography Architecture is designed to be extensible through the use of providers. The standard way to add a new provider, like Bouncy Castle, without modifying the JDK installation is to include its JAR in the application's classpath and then call Security.addProvider(new BouncyCastleProvider()) in the application's startup code. This dynamically registers the provider for the current JVM instance, making its algorithms available to the application.

  7. Question 7

    Q7Multiple answers

    During a security assessment of a Java application, you discover that session identifiers are being passed in the URL. Which of the following vulnerabilities does this practice directly introduce? (Select THREE)

    sequenceDiagram participant User participant Browser participant Server User->>Browser: Login with credentials Browser->>Server: POST /login Server-->>Browser: Redirect to /dashboard?jsessionid=xyz123 Browser->>Server: GET /dashboard?jsessionid=xyz123 Note over Browser: jsessionid is now in URL User->>Browser: Copies and pastes URL to a colleague Note right of User: Session Hijacking Occurs

    Show answer & explanation

    Correct answers: A, B, C

    URLs are stored in the browser's history, making the session ID accessible to anyone with access to that history.

    Web servers, proxies, and other network appliances often log the full URL of requests, which would include the session ID, potentially exposing it in log files.

    Users may unknowingly leak their session by sharing a link from their address bar, allowing others to hijack their session.

  8. Question 8

    Q8

    A developer is implementing a feature that deserializes user-provided data into a Java object using ObjectInputStream. The lead security engineer has warned about the risks of insecure deserialization. Which of the following is the most effective mitigation strategy against this vulnerability?

    Show answer & explanation

    Correct answer: B

    The most robust defense against insecure deserialization is to avoid it altogether. Using safe, structured data formats like JSON or XML with a secure parser (e.g., Jackson, GSON) is the recommended practice. These libraries do not execute code during deserialization and are not vulnerable to the gadget chain exploits that affect native Java serialization.

  9. Question 9

    Q9

    A security analyst is performing a DAST scan on a new Java REST API. The scan reports a potential vulnerability: 'Verbose Error Messages - Stack Trace Disclosure'. The analyst investigates and finds that when an unhandled NullPointerException occurs, the API returns a 500 Internal Server Error response containing the full Java stack trace. Which is the most appropriate way to remediate this vulnerability in a Spring Boot application?

    Show answer & explanation

    Correct answer: C

    In Spring Boot, the standard and most maintainable way to handle exceptions globally is by creating a class annotated with @ControllerAdvice. Within this class, methods annotated with @ExceptionHandler can catch specific exceptions (or general ones like Exception.class) and define a consistent, safe JSON response structure. This centralizes error handling and prevents sensitive information like stack traces from being leaked to the client.

  10. Question 10

    Q10

    A software architect is designing a secure deployment strategy for a fleet of Java-based IoT devices. The devices have limited resources and occasionally intermittent network connectivity. The architect needs to ensure that the application JAR file deployed to the devices has not been tampered with and originates from the company's build server. Which Java utility is best suited for this purpose?

    Show answer & explanation

    Correct answer: B

    The jarsigner utility is specifically designed to sign JAR files and verify the signatures of signed JAR files. The build server would use jarsigner with a private key to sign the application JAR. The IoT device would then have the corresponding public certificate and could use jarsigner -verify to confirm both the integrity (the file hasn't been altered) and authenticity (it was signed by the trusted build server) of the JAR before executing it.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 312-96 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 244 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon