EC-COUNCIL · 312-96

EC-Council 312-96 CASE Java Exam Practice Questions

49 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 49 questions in this pack

Question 1

Sam, an application security engineer working in INFRA INC., was conducting a secure code review on an application developed in Java. He found that the developer has used a piece of code as shown in the following screenshot.

Identify the security mistakes that the developer has coded?

Exhibit for question 1

  1. He is attempting to use client-side validation
  2. He is attempting to use whitelist input validation approach
  3. He is attempting to use regular expression for validation
  4. He is attempting to use blacklist input validation approach
Show answer and explanation

Correct answer: D. He is attempting to use blacklist input validation approach

approach The code implements a blacklist validation approach by checking if the username contains any of a predefined list of dangerous strings ('<SCRIPT>', 'SELECT', 'UNION', 'WHERE', '</SCRIPT>', '>', '<'). Blacklist validation attempts to block known bad inputs rather than allowing only known good inputs. This is a weaker security approach because it can be bypassed through encoding, case variation, or novel attack vectors not included in the blacklist. The developer is explicitly listing dangerous patterns to reject, which is the defining characteristic of blacklist validation.

Why the other options are wrong

  • A. This is server-side validation code written in Java (JSP), not client-side validation which would occur in the browser.
  • B. Whitelist validation would allow only known good inputs; this code instead rejects known bad inputs, making it a blacklist approach.
  • C. While the code contains string literals, it is not using regular expressions (regex patterns); it uses the String.contains() method for simple string matching.

Question 2

Identify the type of attack depicted in the following figure.

Exhibit for question 2

  1. SQL Injection Attacks
  2. Session Fixation Attack
  3. Parameter Tampering Attack
  4. Denial-of-Service Attack
Show answer and explanation

Correct answer: C. Parameter Tampering Attack

The figure shows multiple browser windows with URLs where query parameters have been modified to change application behavior. In the first two examples, the 'debit' parameter values are changed (2500 and 1500), and in the last two examples, the 'status' parameter is altered (from 'view' to 'delete'). These modifications to URL parameters directly affect the server-side application logic without the user having proper authorization. This is characteristic of parameter tampering attacks, where an attacker manipulates request parameters to bypass security controls, modify data, or execute unauthorized actions. The attacker is directly changing values that should not be modifiable by the client side.

Why the other options are wrong

  • A. SQL Injection attacks involve inserting malicious SQL code into input fields or parameters; these URLs show straightforward parameter value changes without any SQL syntax.
  • B. Session Fixation attacks involve forcing a user to use a specific session ID; these examples show parameter manipulation within normal URL structures, not session ID manipulation.
  • D. Denial-of-Service attacks aim to overwhelm resources and make services unavailable; these requests are attempting to modify application data and behavior, not to exhaust system resources.

Question 3

According to secure logging practices, programmers should ensure that logging processes are not disrupted by:

  1. Catching incorrect exceptions
  2. Multiple catching of incorrect exceptions
  3. Re-throwing incorrect exceptions
  4. Throwing incorrect exceptions
Show answer and explanation

Correct answer: D. Throwing incorrect exceptions

Secure logging processes should not be disrupted by throwing incorrect exceptions, as this can cause the logging mechanism itself to fail or behave unpredictably. Throwing exceptions during logging operations can prevent critical security events from being recorded. Catching, re-throwing, or catching multiple times are exception handling techniques that may be necessary for proper control flow, but throwing exceptions indiscriminately disrupts the logging process itself.

Why the other options are wrong

  • A. Catching incorrect exceptions is a defensive programming practice that prevents disruption of logging.
  • B. Multiple catching of incorrect exceptions, while redundant, does not inherently disrupt logging processes.
  • C. Re-throwing exceptions can be part of proper exception handling and does not necessarily disrupt logging.

See all 10 free questions Get the full pack, US$39

49 practice questions for EC-Council Certified Application Security Engineer, Java (CASE Java), exam 312-96, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 49 questions mapped to the CASE Java exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 312-96 attempt costs US$450. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 49 questions

What makes the CASE Java hard

312-96 is the Java edition of EC-Council’s Certified Application Security Engineer, the developer-facing exam in a catalogue that is otherwise aimed at attackers and defenders. It follows the software development lifecycle from requirements to deployment, and most questions show a servlet, a JDBC call or a Spring configuration and ask what is wrong with it or which fix closes the hole.

Eligibility is the official CASE training or two years of software or security experience with a US$100 application fee. The exam itself is 50 questions in two hours with a 70% pass mark.

The ten CASE modules follow the lifecycle, and the secure-coding modules carry the weight: input validation with whitelisting and parameterised queries, authentication and authorization with Java EE security and Spring Security, cryptography with the JCA and JCE, session management, and error handling and logging that does not leak. Static and dynamic application security testing and secure deployment round out the blueprint. The exam rewards developers who have actually fixed these bugs, since the distractors are the plausible half-fixes.

About the exam

312-96 (Certified Application Security Engineer, Java, CASE Java) validates the security skills and knowledge required throughout the software development lifecycle to build secure Java applications. It covers application security threats, security requirements, secure design, secure coding for input validation, authentication and authorization, cryptography, session management and error handling, application security testing, and secure deployment. Eligibility is official CASE training, or two years of experience in the information security or software domain with a US$100 application fee.

Exam modules

  • Understanding application security, threats and attacks
  • Security requirements gathering
  • Secure application design and architecture
  • Secure coding practices for input validation
  • Secure coding practices for authentication and authorization
  • Secure coding practices for cryptography
  • Secure coding practices for session management
  • Secure coding practices for error handling
  • Static and dynamic application security testing
  • Secure deployment and maintenance

EC-Council does not publish weightings. 50 multiple choice questions, 120 minutes, passing score 70%, US$450 per attempt, EC-Council Exam Center online proctored or Pearson VUE, certification valid for three years with ECE credits.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-96 CASE Java pack?

49 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.