Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Arcitura Education Fundamental SOA Security S90.18 Exam Questions

Page: 1 / 10 Total 98 questions

Want more questions? Get Premium Access.

Question 1

When working with SAML, a Security Token Service (STS) and a Service Provider refer to the same service.

Correct Answer: B. False

Question 2

A set of SAML tokens has been used as a result of the application of the Brokered Authentication pattern within a particular service inventory. Because SAML assertions normally contain a signature, the security specialist is confident that the integrity of messages will be maintained. What's wrong with this assumption?

Correct Answer: A. The signature contained within the SAML assertion protects the integrity of the assertion, not of the message itself.

Question 3

A set of services within a service inventory were originally each designed with a dedicated identity store. To reduce the need for service consumers to repeatedly authenticate themselves when having to access multiple services, a new ___________ has been added along with a____________.

Correct Answer: B. authentication broker, single identity store

Question 4

A service that was previously using a shared identity store is now given its own dedicated identity store instead. What are the likely impacts (positive or negative) that will result from this change?

Correct Answer: A. The service's autonomy is increased.; B. The operational responsibility is increased due to the need to keep the dedicated identity store in synch with a parent identity store.

Question 5

There are two XML documents that contain identical XML elements and data values. However, one XML document has more whitespace characters than the other. A message digest for each of these documents is created. Which of the following statements regarding these message digests is true?

Correct Answer: B. they are different

Question 6

A service contract includes a security policy that exposes specific details of the service's underlying implementation. This is an example of the application of which service-orientation principle?

Correct Answer: D. None of the above.

Question 7

The messages exchanged between two services are kept confidential by using symmetric encryption. The security specialist is quite strict about making sure that no attacker is able to intercept and decipher messages sent between these two services. As a result, periodic audits are conducted in order to ensure that shared keys are always kept confidential. A single shared key has been in use for quite some time now. The security specialist was confident that all keys were well guarded, but just recently their security was compromised. How is this possible given that the shared key was never lost?

Correct Answer: C. Because the same shared key was used for a long time, attackers were able to obtain the key by comparing messages sent between the two services.

Question 8

XML canonicalization is the process of standardizing the syntax of XML documents that are to be digitally signed. This way, when the digital signature is verified, it reproduces the same message digest for assessing message integrity.

Correct Answer: A. True

Question 9

The Direct Authentication pattern is best suited for point-to-point communication, while the Brokered Authentication pattern is best suited for service composition where a service consumer needs to re-authenticate itself with multiple services.

Correct Answer: A. True

Question 10

Which of the following is not a hashing algorithm?

Correct Answer: B. X.509