Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Arcitura Education Advanced SOA Security S90.19 Exam Questions

Page: 1 / 9 Total 83 questions

Want more questions? Get Premium Access.

Question 1

The service contract for Service A uses an XML schema that does not specify the maximum length for the Customer-Address XML element. A service consumer sends a message that contains a very long string of characters inside the Customer-Address XML element. This can be an indication of what types of attacks?

Correct Answer: A. XML parser attack; B. Buffer overrun attack

Question 2

The Message Screening pattern can be used to avoid which of the following types of attacks?

Correct Answer: A. buffer overrun attack; B. XPath injection attack; C. SQL injection attack

Question 3

Service A acts as a trusted subsystem for a shared database. The database contains sensitive information and performs strict validation on all incoming data modification requests. In case of any invalid input values, the database throws detailed error messages that are required for debugging purposes and are automatically relayed back to service consumers by Service A . Recently, while going through the access logs of the database, it has been reported that attempts have been made to connect to the database from outside the organization. What can be done to prevent such attacks while preserving the existing database debugging requirements?

Correct Answer: D. None of the above.

Question 4

The use of XML schemas for data validation helps avoid several types of data-centric threats.

Correct Answer: A. True

Question 5

The Service Perimeter Guard pattern is applied to position a perimeter service outside of the firewall. The firewall only permits the perimeter service to access services within a specific service inventory. Which of the following statements describes a valid problem with this security architecture?

Correct Answer: D. None of the above

Question 6

Which of the following statements is true?

Correct Answer: D. All of above.

Question 7

The application of the Service Perimeter Guard pattern establishes a perimeter service that hides internal services from unauthorized external service consumers. However, the perimeter service grants authorized external services direct access to internal services.

Correct Answer: B. False

Question 8

Service A contains reporting logic that issues SOL queries against a database to generate reports. The actual SQL query syntax is determined at runtime. It has been reported that some of these queries ended up retrieving highly confidential data by accessing tables that service consumers were not authorized for. How can this be avoided?

Correct Answer: C. The database security should be increased so that the account under which Service A executes SQL queries has restricted access.

Question 9

A utility service is responsible for encapsulating a legacy database and providing centralized access to the database for any of its service consumers. However, it is discovered that several service consumers are accessing the database directly. This is considered a security concern because much of the data in the database is classified as sensitive. How can this concern be addressed?

Correct Answer: A. The Trusted Subsystem pattern can be applied to establish an architecture whereby service consumers are required to access the utility service in order to gain access to the data in the database

Question 10

As an SOA security specialist you are being asked to educate an IT team about how to best design security policies for a given set of services. Which of the following recommendations are valid?

Correct Answer: A. common security requirements can be centralized into shared security policies; C. security policies can be decoupled from service logic; D. security policies can be part of service contracts and are therefore subject to the Service Loose Coupling principle