Arcitura certification preparation

S90-19 Practice Questions

Practice exam-style questions, check your answers, and review explanations and source references where they are available.

Exam
S90-19
Provider
Arcitura
Full set
83 questions
Last Update Check

Right here, you can practice S90-19 exam questions entirely for free before sitting for the real Arcitura certification test. These complimentary Advanced SOA Security S90-19 PDF questions are publicly available to all candidates who want to ensure their success. Engaging with these authentic S90-19 exam questions will undoubtedly assist you in rigorously preparing for the actual Advanced SOA Security exam. Optionally, if you desire an extra layer of assurance, you can instantly acquire our premium files which offer a massive number of highly accurate practice queries alongside the free S90-19 PDF sets.

A service is designed to respond to an error condition by issuing a message containing detailed error information. This message includes connection information for a database that is shared by numerous services within the service inventory. An attacker intentionally sends an invalid message to the service in order to trigger an error and receive the connection information. The attacker then proceeds to connect to the database and issues a series of malicious SQL queries that make the database non-responsive. As a result, a number of services within the service inventory are disabled. Which of the following types of attacks were successfully carried out?
Answer options
Because of a new security requirement, all messages received by Service A need to be logged. This requirement needs to be expressed in a policy that is part of Service A's service contract. However, the addition of this policy must not impact existing service consumers that have already formed dependencies on Service A's service contract. How can this be accomplished?
Answer options
Service A contains reporting logic that collects statistical data from different sources in order to produce a report document. One of the sources is a Web service that exists outside of the organizational boundary. Some of Service A's service consumers are encountering slow response times and periods of unavailability when invoking Service A . While investigating the cause, it has been discovered that some of the messages received from the external Web service contain excessive data and links to files (that are not XML schemas or policies). What can be done to address this issue?
Answer options
The application of the Message Screening pattern can help avoid which of the following attacks?
Answer options
The Exception Shielding pattern can be applied together with the Trusted Subsystem pattern.
Answer options
Which of the following types of attack always affect the availability of a service?
Answer options
The exception shielding logic resulting from the application of the Exception Shielding pattern can be centralized by applying which additional pattern?
Answer options
The use of derived keys is based on symmetric encryption. This is similar to asymmetric encryption because different keys can be derived from a session key and used separately for encryption and decryption.
Answer options
Service A is part of a large service composition. Following an attack, Service A becomes non- responsive. Which of the following attacks could be responsible for Service A's non-responsiveness?
Answer options
Service A contains a comprehensive message screening routine that can consume a lot of system resources. Service consumers are reporting that sometimes Service A becomes non-responsive, especially after it receives a message containing a large amount of content. This may be an indication of which types of attacks?
Answer options
Question 1 of 10

Source context

How this practice set is maintained

Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.

Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.

Scroll to Top