Question 1
When working with SAML, a Security Token Service (STS) and a Service Provider refer to the same service.
When working with SAML, a Security Token Service (STS) and a Service Provider refer to the same service.
A set of SAML tokens has been used as a result of the application of the Brokered Authentication pattern within a particular service inventory. Because SAML assertions normally contain a signature, the security specialist is confident that the integrity of messages will be maintained. What's wrong with this assumption?
A set of services within a service inventory were originally each designed with a dedicated identity store. To reduce the need for service consumers to repeatedly authenticate themselves when having to access multiple services, a new ___________ has been added along with a____________.
A service that was previously using a shared identity store is now given its own dedicated identity store instead. What are the likely impacts (positive or negative) that will result from this change?
There are two XML documents that contain identical XML elements and data values. However, one XML document has more whitespace characters than the other. A message digest for each of these documents is created. Which of the following statements regarding these message digests is true?
A service contract includes a security policy that exposes specific details of the service's underlying implementation. This is an example of the application of which service-orientation principle?
The messages exchanged between two services are kept confidential by using symmetric encryption. The security specialist is quite strict about making sure that no attacker is able to intercept and decipher messages sent between these two services. As a result, periodic audits are conducted in order to ensure that shared keys are always kept confidential. A single shared key has been in use for quite some time now. The security specialist was confident that all keys were well guarded, but just recently their security was compromised. How is this possible given that the shared key was never lost?
XML canonicalization is the process of standardizing the syntax of XML documents that are to be digitally signed. This way, when the digital signature is verified, it reproduces the same message digest for assessing message integrity.
The Direct Authentication pattern is best suited for point-to-point communication, while the Brokered Authentication pattern is best suited for service composition where a service consumer needs to re-authenticate itself with multiple services.
Which of the following is not a hashing algorithm?