SOA Fundamental SOA Security - S90.18 FREE EXAM DUMPS QUESTIONS & ANSWERS
Using transport-layer security, an active intermediary that takes possession of a message
can compromise:
can compromise:
Correct Answer: A
Vote an answer
With SAML, the _____________ element is used by the relying party to confirm that a
given message came from the subject specified in the assertion.
given message came from the subject specified in the assertion.
Correct Answer: D
Vote an answer
Which of the following are valid security considerations specific to the application of the
Service Autonomy principle?
Service Autonomy principle?
Correct Answer: C
Vote an answer
Which of the following tasks directly relates to the application of the Service Loose
Coupling principle?
Coupling principle?
Correct Answer: C
Vote an answer
A service contract includes a security policy that exposes specific details of the service's
underlying implementation. This is an example of the application of which service-
orientation principle?
underlying implementation. This is an example of the application of which service-
orientation principle?
Correct Answer: B
Vote an answer
The application of the Brokered Authentication pattern is best suited for a scenario whereby
a service consumer does not need to re-authenticate itself with multiple services.
a service consumer does not need to re-authenticate itself with multiple services.
Correct Answer: B
Vote an answer
Which of the following industry standards enable non-repudiation?
Correct Answer: A,C
Vote an answer
The X.509 token can be used to express a ______________ security token that provides
an X.509 digital certificate.
an X.509 digital certificate.
Correct Answer: D
Vote an answer
The application of the Service Composability principle can be supported by the application
of the Brokered Authentication pattern.
of the Brokered Authentication pattern.
Correct Answer: A
Vote an answer
Responses issued by Certificate Revocation Lists (CRLs) and Online Certificate Status
Protocol (OCSP) services need to be ___________ and ___________ so that it can be
determined whether these responses were sent by a trusted certificate authority or a
malicious program pretending to be a certificate authority.
Protocol (OCSP) services need to be ___________ and ___________ so that it can be
determined whether these responses were sent by a trusted certificate authority or a
malicious program pretending to be a certificate authority.
Correct Answer: A
Vote an answer