SOA S90.18 - Fundamental SOA Security Exam
Page: 3 / 20
Total 98 questions
Question #11 (Topic: )
Which of the following security mechanisms can provide centralized security measures for
all services within a service inventory?
all services within a service inventory?
A. public key infrastructure
B. single sign-on
C. hashed certificate repository
D. identity management system
Answer: A,B,D
Question #12 (Topic: )
The communication between two services operating within the same organization needs to
be protected using message-layer security. These services are only used within the
organizational boundary. The question is raised as to whether to use self-signed
certificates or certificates signed by a certificate authority. A security specialist states that
only certificates signed by an external certificate authority can be used to fulfill this security
requirement. Is this correct?
be protected using message-layer security. These services are only used within the
organizational boundary. The question is raised as to whether to use self-signed
certificates or certificates signed by a certificate authority. A security specialist states that
only certificates signed by an external certificate authority can be used to fulfill this security
requirement. Is this correct?
A. Yes
B. No
Answer: B
Question #13 (Topic: )
The manager of an IT department decides to split up an existing enterprise service
inventory into two domain service inventories. The public key used previously in the
enterprise service inventory can continue to be used in one of the domain service
inventories.
inventory into two domain service inventories. The public key used previously in the
enterprise service inventory can continue to be used in one of the domain service
inventories.
A. True
B. False
Answer: A
Question #14 (Topic: )
Service A is a utility service that has been designed to receive and send non-confidential
messages. Service A provides access to a legacy application. Since the launch of Service
messages. Service A provides access to a legacy application. Since the launch of Service
A. True
B. False
Answer: B
Question #15 (Topic: )
One of the primary industry standards used for the application of the Data Confidentiality
pattern is:
pattern is:
A. XML-Encryption
B. Canonical XML
C. XML-Signature
D. SAML
Answer: A