SOA S90.19 - Advanced SOA Security Exam

Question #11 (Topic: )
The Trusted Subsystem pattern is applied to a service that provides access to a database.
Select the answer that best explains why this service is still at risk of being subjected to an
insufficient authorization attack.
A. Attackers can steal confidential data by monitoring the network traffic that occurs between the service and the database. B. Because the Service Perimeter Guard pattern was also not applied, the database is not protected by a firewall. C. If an attacker gains access to the security credentials used by the service to access the database, the attacker can access the database directly. D. None of the above.
Answer: C
Question #12 (Topic: )
A service receives a message containing an XML document that expands to a very large
size as it is processed by the parser. As a result, the service becomes unavailable to
service consumers. The service was subjected to which type of attack?
A. XML parser attack B. Exception generation attack C. XPath injection attack D. None of the above.
Answer: A
Question #13 (Topic: )
Security policies defined using WS-SecurityPolicy can be used to convey which of the
following requirements to a service consumer?
A. Whether transport-layer or message-layer security needs to be used B. The encryption type that needs to be used for transport-layer security C. The algorithms that need to be used for cryptographic operations D. The type of security token that must be used
Answer: A,C,D
Question #14 (Topic: )
The Service Perimeter Guard pattern has been applied to help avoid denial of service
attacks for a service inventory. As a result, services within the service inventory are only
accessible via a perimeter service However, denial of service attacks continue to succeed
and services within the service inventory become unavailable to external service
consumers. What is the likely cause of this?
A. The application of the Service Perimeter Guard pattern needs to be combined with the application of the Message Screening pattern in order to mitigate denial of service attacks. B. The perimeter service itself is the victim of denial of service attacks. As a result, none of the services inside the service inventory can be accessed by external service consumers. C. The Trusted Subsystem pattern should have been applied so that each service has a dedicated trusted subsystem. D. The Service Perimeter Guard pattern does not help avoid denial of service attacks.
Answer: B
Question #15 (Topic: )
The application of the Message Screening pattern can help avoid which of the following
attacks?
A. Buffer overrun attack B. XPath injection attack C. SQL injection attack D. Insufficient authorization attack
Answer: A,B,C
Download Exam
Page: 3 / 17
Total 83 questions