312-96 Sample Questions & Answers
Application security fundamentals and secure design principles share the top weighting, alongside requirements engineering, input validation and authentication coding, cryptographic implementation, session security, error handling and logging, and deployment security.
Launch the full 312-96 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Secure Coding Practices for Cryptography · Java Cryptography Architecture (JCA)
A Java application uses the Java Cryptography Architecture (JCA) to encrypt sensitive data using AES. The development team wants to ensure the application can support strong encryption algorithms that may not be included in the default JDK distribution, and they want to do this without modifying the
java.securityfile in the JDK installation. What is the standard mechanism in Java to achieve this?Show answer & explanation
Correct answer: B
The Java Cryptography Architecture is designed to be extensible through the use of providers. The standard way to add a new provider, like Bouncy Castle, without modifying the JDK installation is to include its JAR in the application's classpath and then call
Security.addProvider(new BouncyCastleProvider())in the application's startup code. This dynamically registers the provider for the current JVM instance, making its algorithms available to the application. - Question 2IntermediateSelect 3
Secure Coding Practices for Session Management · Session Hijacking
During a security assessment of a Java application, you discover that session identifiers are being passed in the URL. Which of the following vulnerabilities does this practice directly introduce? (Select THREE)
sequenceDiagram participant User participant Browser participant Server User->>Browser: Login with credentials Browser->>Server: POST /login Server-->>Browser: Redirect to /dashboard?jsessionid=xyz123 Browser->>Server: GET /dashboard?jsessionid=xyz123 Note over Browser: jsessionid is now in URL User->>Browser: Copies and pastes URL to a colleague Note right of User: Session Hijacking OccursShow answer & explanation
Correct answers: A, B, C
URLs are stored in the browser's history, making the session ID accessible to anyone with access to that history.
Web servers, proxies, and other network appliances often log the full URL of requests, which would include the session ID, potentially exposing it in log files.
Users may unknowingly leak their session by sharing a link from their address bar, allowing others to hijack their session.
- Question 3Advanced
Secure Coding Practices for Input Validation · Insecure Deserialization
A developer is implementing a feature that deserializes user-provided data into a Java object using
ObjectInputStream. The lead security engineer has warned about the risks of insecure deserialization. Which of the following is the most effective mitigation strategy against this vulnerability?Show answer & explanation
Correct answer: B
The most robust defense against insecure deserialization is to avoid it altogether. Using safe, structured data formats like JSON or XML with a secure parser (e.g., Jackson, GSON) is the recommended practice. These libraries do not execute code during deserialization and are not vulnerable to the gadget chain exploits that affect native Java serialization.
- Question 4Intermediate
Secure Coding Practices for Error Handling · Information Disclosure
A security analyst is performing a DAST scan on a new Java REST API. The scan reports a potential vulnerability: 'Verbose Error Messages - Stack Trace Disclosure'. The analyst investigates and finds that when an unhandled
NullPointerExceptionoccurs, the API returns a 500 Internal Server Error response containing the full Java stack trace. Which is the most appropriate way to remediate this vulnerability in a Spring Boot application?Show answer & explanation
Correct answer: C
In Spring Boot, the standard and most maintainable way to handle exceptions globally is by creating a class annotated with
@ControllerAdvice. Within this class, methods annotated with@ExceptionHandlercan catch specific exceptions (or general ones likeException.class) and define a consistent, safe JSON response structure. This centralizes error handling and prevents sensitive information like stack traces from being leaked to the client. - Question 5Intermediate
Secure Deployment and Maintenance · Code Signing
A software architect is designing a secure deployment strategy for a fleet of Java-based IoT devices. The devices have limited resources and occasionally intermittent network connectivity. The architect needs to ensure that the application JAR file deployed to the devices has not been tampered with and originates from the company's build server. Which Java utility is best suited for this purpose?
Show answer & explanation
Correct answer: B
The
jarsignerutility is specifically designed to sign JAR files and verify the signatures of signed JAR files. The build server would usejarsignerwith a private key to sign the application JAR. The IoT device would then have the corresponding public certificate and could usejarsigner -verifyto confirm both the integrity (the file hasn't been altered) and authenticity (it was signed by the trusted build server) of the JAR before executing it. - Question 6Intermediate
Secure Coding Practices for Input Validation · SQL Injection Prevention
True or False: Using Java's
PreparedStatementis a complete defense against all forms of SQL Injection (SQLi) vulnerabilities.Show answer & explanation
Correct answer: B
False. While
PreparedStatementis the primary defense against first-order SQLi by properly separating query logic from user data, it does not protect against all scenarios. For example, if user input is used to dynamically construct parts of the query that cannot be parameterized, such as table names, column names, orORDER BYclauses, the application can still be vulnerable. It also does not inherently protect against second-order SQL injection, where malicious input is stored in the database and later executed in a different, vulnerable query. - Question 7Beginner
Understanding Application Security, Threats, and Attacks · Threat Classification Models
A security architect is reviewing the design of a new Java application and wants to apply the STRIDE threat modeling methodology. The architect is concerned about a feature where users can upload and modify their own profile data. Which STRIDE category best describes the threat of a user modifying another user's profile data by guessing their user ID?
Show answer & explanation
Correct answer: B
Tampering, in the context of STRIDE, refers to the unauthorized modification of data. In this scenario, one user is modifying data that does not belong to them, which is a clear case of data tampering. The corresponding security property to mitigate this is Integrity, which would be enforced by proper authorization checks.
- Question 8Advanced
Secure Coding Practices for Cryptography · Random Number Generation
A developer is using the Java
SecureRandomclass to generate a key for an AES encryption algorithm. Which of the following code snippets represents the most secure way to initializeSecureRandomon a Linux system?Show answer & explanation
Correct answer: C
The most secure and recommended way to initialize
SecureRandomis to use the no-argument constructor:new SecureRandom(). This allows the JVM to select the best-configured and most secure Pseudo-Random Number Generator (PRNG) available in the underlying operating system. On Linux, this will typically seed from/dev/urandomor/dev/random, which are cryptographically strong sources of entropy. Manually seeding with a predictable value likeSystem.currentTimeMillis()is insecure, and hardcoding an algorithm likeSHA1PRNGis brittle and may not be the strongest option available. - Question 9Intermediate
Secure Coding Practices for Authentication and Authorization · Role-Based Access Control (RBAC)
A team is building a high-security Java application that requires Role-Based Access Control (RBAC). The system must support a hierarchy of roles (e.g., an 'Administrator' role inherits all permissions of a 'Manager' role, which inherits from a 'User' role). The security engineer needs to implement checks to ensure a user has the required permission before performing an action. Which framework or technology provides the most comprehensive, out-of-the-box support for this type of hierarchical permission model?
Show answer & explanation
Correct answer: B
While Spring Security is very popular, Apache Shiro is particularly well-known for its powerful and intuitive permission-based (or resource-based) authorization model. Shiro's
WildcardPermissionsyntax is extremely flexible and naturally supports hierarchical permissions and instance-level access control (e.g.,document:edit:12345). This makes it an excellent choice for applications with complex, fine-grained authorization requirements beyond simple role checks. - Question 10Advanced
Security Requirements Gathering · Compliance and Regulatory Requirements
Case Study
HealthTrack, a healthcare technology company, is developing a patient portal application using Java and the Spring Framework. During the requirements gathering phase, the security team identified that the application must be compliant with the Health Insurance Portability and Accountability Act (HIPAA).
Application Components:
- A front-end built with a modern JavaScript framework.
- A back-end REST API built with Spring Boot.
- A PostgreSQL database for storing patient data, including electronic Protected Health Information (ePHI).
- The application is deployed on a public cloud provider.
Security Requirements:
- All ePHI must be encrypted both at rest and in transit.
- Access to ePHI must be strictly controlled and logged.
- The application must be protected against common web vulnerabilities (OWASP Top 10).
- User sessions must automatically time out after 15 minutes of inactivity.
Which of the following solution proposals best addresses the HIPAA compliance requirements for session management and data encryption?
Show answer & explanation
Correct answer: B
This option provides a robust and compliant solution. TLS 1.3 is the current standard for secure transit. TDE provides strong encryption at rest at the database level. Critically, session timeouts must be enforced on the server-side, as client-side timeouts can be easily bypassed; configuring this in Spring Boot is the correct approach. The value
900scorrectly corresponds to 15 minutes.
Ready for the real thing?
The full 312-96 simulator has every exam-style question, timed mode, and instant scoring.