Summer Special Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 60certs

SOA S90.19 Dumps

Page: 1 / 3
Total 83 questions

Advanced SOA Security Questions and Answers

Question 1

An IT enterprise has three domain service inventories that map to three different departments. Each service inventory uses a security token service (STS) based authentication broker to enable single sign-on for services within the respective service inventory boundary. The tokens used for all single sign-on mechanisms are based on SAML assertions. You are given a new requirement to extend this security architecture so that services from different domain service inventories can communicate. What new security mechanisms are required to fulfill this requirement?

Options:

A.

The individual authentication brokers need to be replaced with one single authentication broker so that one single token can be used by services across all domain service inventories.

B.

An additional authentication broker needs to be added in between each domain service inventory in order to enable communication between services using disparate security tokens.

C.

There is no need to introduce a new security mechanism. The individual domain service inventories need to be combined into a single enterprise service inventory. That way, the Service Perimeter Guard pattern can be applied so that services won't need to authenticate each other.

D.

There is no need to introduce a new security mechanism. The existing SAML tokens can be used by services across the domain service inventories as long as the existing authentication brokers are configured to issue service inventory-specific assertions for SAML tokens from specific domain service inventories.

Question 2

Service A is only authorized to access one service capability of Service B. Service B acts as a trusted subsystem for several underlying resources which it accesses using its own set of credentials. Service B can therefore not become a victim of an insufficient authorization attack initiated by Service A.

Options:

A.

True

B.

False

Question 3

Service A is a Web service with an implementation that uses managed code. To perform a graphics-related operation, this managed code needs to access a graphics function that exist as unmanaged code. A malicious service consumer sends a message to Service A containing a very large numeric value. This value is forwarded by Service A' s logic to the graphics function. As a result, the service crashes and becomes unavailable. The service consumer successfully executed which attack?

Options:

A.

Buffer overrun attack

B.

Exception generation attack

C.

XML parser attack

D.

None of the above

Question 4

A denial of service attack can be the byproduct of an insufficient authorization attack.

Options:

A.

True

B.

False

Question 5

A service uses specialized screening logic that compares the size of a message against a maximum allowable size value. This value is specified for an incoming request message for a specific service capability. Upon a mismatch, the service rejects the request message and instead generates an error message. What type of attack has this security architecture not addressed?

Options:

A.

XML parser attack

B.

Buffer overrun attack

C.

Exception shielding attack

D.

None of the above

Question 6

Service A retrieves data from third-party services that reside outside the organizational boundary. The quality of the data provided by these third-party services is not guaranteed. Service A contains exception shielding logic that checks all outgoing messages. It is discovered that service consumers are still sometimes receiving malicious content from Service A. Because digital signatures are being used, it is confirmed that Service A is, in fact, the sender of these messages and that the messages are not being altered by any intermediaries. Why do messages from Service A continue to contain malicious content?

Options:

A.

Messages received from third-party services are the likely source of the malicious content.

B.

Digital signatures alone are not sufficient. They need to be used in conjunction with asymmetric encryption in order to ensure that no intermediary can alter messages.

C.

Exception shielding logic needs to be used in conjunction with asymmetric encryption in order to guarantee that malicious content is not spread to service consumers.

D.

None of the above.

Question 7

A service composition is made up of services from a particular domain service inventory. All of the services belonging to the domain service inventory are deployed on the same server. Service A is part of the same domain inventory but is not part of this service composition. Service A becomes a victim of an XML parser attack resulting in its unavailability. However, because the services in the service composition rely on the same XML parser used by Service A. the service composition can also be affected by this attack.

Options:

A.

True

B.

False

Question 8

Service A expresses its requirement for message-layer security to service consumers via a security policy. Since the launch of Service A, its popularity has grown and it is decided that a fee should be charged for its use. Consequently, the design of Service A is changed so that it is capable of keeping a log of all request messages received from service consumers. The fact that Service A is logging all incoming messages is something that can also be expressed via a policy.

Options:

A.

True

B.

False

Question 9

Which of the following types of attack always affect the availability of a service?

Options:

A.

Exception generation attack

B.

SQL injection attack

C.

XPath injection attack

D.

None of the above

Question 10

Service A accesses a legacy system. There is a requirement to secure Service A so that it can only be accessed by authorized service consumers. The current service architecture doesn't allow the delegation of service consumer credentials to the legacy system. Which pattern needs to be applied in order to fulfill this security requirement?

Options:

A.

Brokered Authentication

B.

Direct Authentication

C.

Data Origin Authentication

D.

None of the above.

Question 11

A common alternative to_____________ is the use of a ____________.

Options:

A.

Public key cryptography, private key

B.

Digital signatures, symmetric key

C.

Public key cryptography, public key

D.

Private keys, digital signatures

Question 12

As an SOA security specialist you are being asked to educate an IT team about how to best design security policies for a given set of services. Which of the following recommendations are valid?

Options:

A.

common security requirements can be centralized into shared security policies

B.

security policies are defined by using WSDL and XML Schema industry standards together

C.

security policies can be decoupled from service logic

D.

security policies can be part of service contracts and are therefore subject to the Service Loose Coupling principle

Page: 1 / 3
Total 83 questions