SOA Advanced SOA Security - S90.19 Exam Practice Test

As an SOA security specialist you are being asked to educate an IT team about how to best design security policies for a given set of services. Which of the following recommendations are valid?

Correct Answer: A,B,D Vote an answer
The application of the Message Screening pattern can help avoid which of the following attacks?

Correct Answer: B,C,D Vote an answer
An alternative to using a ___________ is to use a __________.

Correct Answer: C Vote an answer
A service is designed to respond to an error condition by issuing a message containing detailed error information. This message includes connection information for a database that is shared by numerous services within the service inventory. An attacker intentionally sends an invalid message to the service in order to trigger an error and receive the connection information. The attacker then proceeds to connect to the database and issues a series of malicious SQL queries that make the database non-responsive. As a result, a number of services within the service inventory are disabled. Which of the following types of attacks were successfully carried out?

Correct Answer: B,D Vote an answer
Which of the following statements regarding the usage of security tokens for authentication and authorization are true?

Correct Answer: B,D Vote an answer
Service A contains reporting logic that collects statistical data from different sources in order to produce a report document. One of the sources is a Web service that exists outside of the organizational boundary. Some of Service A's service consumers are encountering slow response times and periods of unavailability when invoking Service A.
While investigating the cause, it has been discovered that some of the messages received from the external Web service contain excessive data and links to files (that are not XML schemas or policies). What can be done to address this issue?

Correct Answer: A,B Vote an answer
A common alternative to_____________ is the use of a ____________.

Correct Answer: C Vote an answer
An ESB is introduced into an IT enterprise, primarily to enable communication between a set of disparate Web services. As a first step, the ESB needs to be configured to carry out data model transformation in order to overcome differences in the XML schemas used by the Web services. However, the messages exchanged by the Web services need to be encrypted. What needs to be done in order for the ESB to enable communication between the Web services without compromising message confidentiality?

Correct Answer: B Vote an answer
A denial of service attack can be the byproduct of an insufficient authorization attack.

Correct Answer: B Vote an answer

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday

Support: Contact now 

日本語 Deutsch 繁体中文 한국어