Certified Application Security Engineer (CASE) Exam Prep
Free practice questions

Free CASE Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,050-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The CASE exam has 50 questions and runs 2 hours.

These 10 free CASE questions are organized by exam domain, so you can see how each part of the Certified Application Security Engineer (CASE) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Understanding Application Security, Threats, and Attacks

Question 1

A candidate preparing for the CASE exam plans to allocate study time according to how heavily each domain is weighted. According to the official CASE Exam Blueprint, which domain carries the LARGEST share of the exam?

Show answer & explanation

Correct answer: C - Understanding Application Security, Threats, and Attacks

Question 2

During the design phase of the SDLC, a team performs several activities. The CASE blueprint requires candidates to differentiate functional activities from security activities. Which of the following is a SECURITY activity rather than a functional one?

Show answer & explanation

Correct answer: A - Producing threat models of the application

Question 3

A developer studies the OWASP Top 10 2017 list referenced by the CASE curriculum, then compares it against the OWASP Top 10 2021. Which statement correctly describes what happened to Cross-Site Scripting (XSS) between those two versions?

Show answer & explanation

Correct answer: D - XSS was merged into the Injection category in the 2021 list

Question 4

A project manager argues that a security flaw discovered by customers after release can simply be patched in the next sprint at no real extra cost. Which principle taught in the CASE curriculum contradicts this reasoning?

Show answer & explanation

Correct answer: B - The relative cost of fixing a vulnerability rises sharply in later SDLC phases

Domain 2: Security Requirements Gathering

Question 5

While modelling security requirements, an analyst draws a UML diagram in which a malicious actor's action is shown acting against a legitimate use case. Which relationship is used to describe abuse case scenarios?

Show answer & explanation

Correct answer: A - Threatens Relationship

Question 6

An organization adopts OCTAVE before development begins. The analysis team starts by cataloguing what the business considers critical and identifying the threats against each item. Which OCTAVE phase is being performed?

Show answer & explanation

Correct answer: B - Phase 1: Build Asset-Based Threat Profiles

Domain 3: Secure Application Design and Architecture

Question 7

The threat modeling phase where applications are decomposed and their entry points are reviewed from an attacker's perspective is known as:

Show answer & explanation

Correct answer: C - Attack Surface Evaluation

Question 8

All of the following are categories in the STRIDE threat classification model **EXCEPT:**

Show answer & explanation

Correct answer: D - Reproducibility

Domain 4: Secure Coding Practices for Input Validation

Question 9

During a secure code review, an engineer finds a method that rejects a username if it contains any of the strings SCRIPT, SELECT, UNION, or WHERE, and accepts the input otherwise. What is the security mistake in this approach?

Show answer & explanation

Correct answer: A - It relies on a blacklist, so unlisted or encoded payloads pass

Question 10

An application filters the sequence ../ out of a path parameter and then decodes the value before using it. An attacker defeats the filter by submitting %2e%2e%2f. Which secure coding rule did the developer violate?

Show answer & explanation

Correct answer: C - Input must be canonicalized to its simplest form before validation occurs

The rest of the CASE blueprint

The CASE exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,050

The full bank has 1,040 more CASE questions with explanations.

Continue in the free practice test →

View plans