312-96 Sample Questions

312-96 Sample Questions & Answers

Application security fundamentals and secure design principles share the top weighting, alongside requirements engineering, input validation and authentication coding, cryptographic implementation, session security, error handling and logging, and deployment security.

Launch the full 312-96 simulator →

Free 312-96 Sample Questions with Answers

Real questions from the Certified Application Security Engineer (CASE) - Java practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Secure Coding Practices for Cryptography · Java Cryptography Architecture (JCA)

    A Java application uses the Java Cryptography Architecture (JCA) to encrypt sensitive data using AES. The development team wants to ensure the application can support strong encryption algorithms that may not be included in the default JDK distribution, and they want to do this without modifying the java.security file in the JDK installation. What is the standard mechanism in Java to achieve this?

    Show answer & explanation

    Correct answer: B

    The Java Cryptography Architecture is designed to be extensible through the use of providers. The standard way to add a new provider, like Bouncy Castle, without modifying the JDK installation is to include its JAR in the application's classpath and then call Security.addProvider(new BouncyCastleProvider()) in the application's startup code. This dynamically registers the provider for the current JVM instance, making its algorithms available to the application.

  2. Question 2IntermediateSelect 3

    Secure Coding Practices for Session Management · Session Hijacking

    During a security assessment of a Java application, you discover that session identifiers are being passed in the URL. Which of the following vulnerabilities does this practice directly introduce? (Select THREE)

    sequenceDiagram participant User participant Browser participant Server User->>Browser: Login with credentials Browser->>Server: POST /login Server-->>Browser: Redirect to /dashboard?jsessionid=xyz123 Browser->>Server: GET /dashboard?jsessionid=xyz123 Note over Browser: jsessionid is now in URL User->>Browser: Copies and pastes URL to a colleague Note right of User: Session Hijacking Occurs

    Show answer & explanation

    Correct answers: A, B, C

    URLs are stored in the browser's history, making the session ID accessible to anyone with access to that history.

    Web servers, proxies, and other network appliances often log the full URL of requests, which would include the session ID, potentially exposing it in log files.

    Users may unknowingly leak their session by sharing a link from their address bar, allowing others to hijack their session.

  3. Question 3Advanced

    Secure Coding Practices for Input Validation · Insecure Deserialization

    A developer is implementing a feature that deserializes user-provided data into a Java object using ObjectInputStream. The lead security engineer has warned about the risks of insecure deserialization. Which of the following is the most effective mitigation strategy against this vulnerability?

    Show answer & explanation

    Correct answer: B

    The most robust defense against insecure deserialization is to avoid it altogether. Using safe, structured data formats like JSON or XML with a secure parser (e.g., Jackson, GSON) is the recommended practice. These libraries do not execute code during deserialization and are not vulnerable to the gadget chain exploits that affect native Java serialization.

  4. Question 4Intermediate

    Secure Coding Practices for Error Handling · Information Disclosure

    A security analyst is performing a DAST scan on a new Java REST API. The scan reports a potential vulnerability: 'Verbose Error Messages - Stack Trace Disclosure'. The analyst investigates and finds that when an unhandled NullPointerException occurs, the API returns a 500 Internal Server Error response containing the full Java stack trace. Which is the most appropriate way to remediate this vulnerability in a Spring Boot application?

    Show answer & explanation

    Correct answer: C

    In Spring Boot, the standard and most maintainable way to handle exceptions globally is by creating a class annotated with @ControllerAdvice. Within this class, methods annotated with @ExceptionHandler can catch specific exceptions (or general ones like Exception.class) and define a consistent, safe JSON response structure. This centralizes error handling and prevents sensitive information like stack traces from being leaked to the client.

  5. Question 5Intermediate

    Secure Deployment and Maintenance · Code Signing

    A software architect is designing a secure deployment strategy for a fleet of Java-based IoT devices. The devices have limited resources and occasionally intermittent network connectivity. The architect needs to ensure that the application JAR file deployed to the devices has not been tampered with and originates from the company's build server. Which Java utility is best suited for this purpose?

    Show answer & explanation

    Correct answer: B

    The jarsigner utility is specifically designed to sign JAR files and verify the signatures of signed JAR files. The build server would use jarsigner with a private key to sign the application JAR. The IoT device would then have the corresponding public certificate and could use jarsigner -verify to confirm both the integrity (the file hasn't been altered) and authenticity (it was signed by the trusted build server) of the JAR before executing it.

  6. Question 6Intermediate

    Secure Coding Practices for Input Validation · SQL Injection Prevention

    True or False: Using Java's PreparedStatement is a complete defense against all forms of SQL Injection (SQLi) vulnerabilities.

    Show answer & explanation

    Correct answer: B

    False. While PreparedStatement is the primary defense against first-order SQLi by properly separating query logic from user data, it does not protect against all scenarios. For example, if user input is used to dynamically construct parts of the query that cannot be parameterized, such as table names, column names, or ORDER BY clauses, the application can still be vulnerable. It also does not inherently protect against second-order SQL injection, where malicious input is stored in the database and later executed in a different, vulnerable query.

  7. Question 7Beginner

    Understanding Application Security, Threats, and Attacks · Threat Classification Models

    A security architect is reviewing the design of a new Java application and wants to apply the STRIDE threat modeling methodology. The architect is concerned about a feature where users can upload and modify their own profile data. Which STRIDE category best describes the threat of a user modifying another user's profile data by guessing their user ID?

    Show answer & explanation

    Correct answer: B

    Tampering, in the context of STRIDE, refers to the unauthorized modification of data. In this scenario, one user is modifying data that does not belong to them, which is a clear case of data tampering. The corresponding security property to mitigate this is Integrity, which would be enforced by proper authorization checks.

  8. Question 8Advanced

    Secure Coding Practices for Cryptography · Random Number Generation

    A developer is using the Java SecureRandom class to generate a key for an AES encryption algorithm. Which of the following code snippets represents the most secure way to initialize SecureRandom on a Linux system?

    Show answer & explanation

    Correct answer: C

    The most secure and recommended way to initialize SecureRandom is to use the no-argument constructor: new SecureRandom(). This allows the JVM to select the best-configured and most secure Pseudo-Random Number Generator (PRNG) available in the underlying operating system. On Linux, this will typically seed from /dev/urandom or /dev/random, which are cryptographically strong sources of entropy. Manually seeding with a predictable value like System.currentTimeMillis() is insecure, and hardcoding an algorithm like SHA1PRNG is brittle and may not be the strongest option available.

  9. Question 9Intermediate

    Secure Coding Practices for Authentication and Authorization · Role-Based Access Control (RBAC)

    A team is building a high-security Java application that requires Role-Based Access Control (RBAC). The system must support a hierarchy of roles (e.g., an 'Administrator' role inherits all permissions of a 'Manager' role, which inherits from a 'User' role). The security engineer needs to implement checks to ensure a user has the required permission before performing an action. Which framework or technology provides the most comprehensive, out-of-the-box support for this type of hierarchical permission model?

    Show answer & explanation

    Correct answer: B

    While Spring Security is very popular, Apache Shiro is particularly well-known for its powerful and intuitive permission-based (or resource-based) authorization model. Shiro's WildcardPermission syntax is extremely flexible and naturally supports hierarchical permissions and instance-level access control (e.g., document:edit:12345). This makes it an excellent choice for applications with complex, fine-grained authorization requirements beyond simple role checks.

  10. Question 10Advanced

    Security Requirements Gathering · Compliance and Regulatory Requirements

    Case Study

    HealthTrack, a healthcare technology company, is developing a patient portal application using Java and the Spring Framework. During the requirements gathering phase, the security team identified that the application must be compliant with the Health Insurance Portability and Accountability Act (HIPAA).

    Application Components:

    • A front-end built with a modern JavaScript framework.
    • A back-end REST API built with Spring Boot.
    • A PostgreSQL database for storing patient data, including electronic Protected Health Information (ePHI).
    • The application is deployed on a public cloud provider.

    Security Requirements:

    1. All ePHI must be encrypted both at rest and in transit.
    2. Access to ePHI must be strictly controlled and logged.
    3. The application must be protected against common web vulnerabilities (OWASP Top 10).
    4. User sessions must automatically time out after 15 minutes of inactivity.

    Which of the following solution proposals best addresses the HIPAA compliance requirements for session management and data encryption?

    Show answer & explanation

    Correct answer: B

    This option provides a robust and compliant solution. TLS 1.3 is the current standard for secure transit. TDE provides strong encryption at rest at the database level. Critically, session timeouts must be enforced on the server-side, as client-side timeouts can be easily bypassed; configuring this in Spring Boot is the correct approach. The value 900s correctly corresponds to 15 minutes.

Ready for the real thing?

The full 312-96 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 312-96 simulator →