Quiz S90.20: Arcitura Education SOA Security Lab
Quiz
data from Database A (2). Service A then sends a request message with the retrieved data to Service
B (3). Service B exchanges messages with Service C (4) and Service D (5), which perform a series of
calculations on the data and return the results to Service A .Service A uses these results to update
Database A (7) and finally sends a response message to Service Consumer A (8). Component B has
direct, independent access to Database A and is fully trusted by Database A .Both Component B and
Database A reside within Organization A .Service Consumer A and Services A, B, C, and D are external
to the organizational boundary of Organization A .

Component B is considered a mission critical program that requires guaranteed access to and fast
response from Database A .Service A was recently the victim of a denial of service attack, which
resulted in Database A becoming unavailable for extended periods of time (which further
compromised Component B). Additionally, Services B, C, and D have repeatedly been victims of
malicious intermediary attacks, which have further destabilized the performance of Service A .How
can this architecture be improved to prevent these attacks?
Quiz
activity. Communication between Services A and B has been secured using transport-layer security.
With each service request message sent to Service B (1A .IB), Service A includes an X.509 certificate,
signed by an external Certificate Authority (CA). Service B validates the certificate by retrieving the
public key of the CA (2A .2B) and verifying the digital signature of the X.509 certificate. Service B then
performs a certificate revocation check against a separate external CA repository (3A, 3B). No
intermediary service agents reside between Service A and Service B .

To fulfill a new security requirement, Service A needs to be able to verify that the response message
sent by Service B has not been modified during transit. Secondly, the runtime performance between
Services A and B has been unacceptably poor and therefore must be improved without losing the
ability to verify Service A's security credentials. It has been determined that the latency is being
caused by redundant security processing carried out by Service B .Which of the following statements
describes a solution that fulfills these requirements?
Quiz
message with security credentials to Service B (2). Service B authenticates the request and, if the
authentication is successful, writes data from the request message into Database B (3). Service B
then sends a request message to Service C (4), which is not required to issue a response message.
Service B then sends a response message back to Service A (5). After processing Service B's response,
Service A sends another request message with security credentials to Service B (6). After successfully
authenticating this second request message from Service A, Service B sends a request message to
Service D (7). Service D is also not required to issue a response message. Finally, Service B sends a
response message to Service A (8), after which Service A records the response message contents in
Database A (9) before sending its own response message to Service Consumer A (10).

Services A and B use digital certificates to support message integrity and authentication. With every
message exchange between the two services (2, 5, 6, 8), the digital certificates are used. It has been
determined that both Databases A and B are vulnerable to malicious attackers that may try to
directly access sensitive data records. Furthermore, performance logs have revealed that the current
exchange of digital certificates between Services A and B is unacceptably slow. How can the integrity
and authenticity of messages exchanged between Services A and B be maintained, but with
improved runtime performance - and - how can Databases A and B be protected with minimal
additional impact on performance?
Quiz
number of service consumers permitted to access Service A concurrently is strictly controlled. Service
A validates request messages based on the supplied credentials (1). If the authentication of the
request message is successful, Service A sends a message to Service B (2) to retrieve the required
data from Database A (3). Service A stores the response from Service B (4) in memory and then issues
a request message to Service C (5). Service C retrieves a different set of data from Database A (6) and
sends the result back to Service A (7). Service A consolidates the data received from Services B and C
and sends the generated report in the response message to its service consumer (8).

This service composition was recently shut down after it was discovered that Database A had been
successfully attacked twice in a row. The first type of attack consisted of a series of coordinated
request messages sent by the same malicious service consumer, with the intention of triggering a
range of exception conditions within the database in order to generate various error messages. The
second type of attack consisted of a service consumer sending request messages with malicious
input with the intention of gaining control over the database server. This attack resulted in the
deletion of database records and tables. An investigation revealed that both attacks were carried out
by malicious service consumers that were authorized. How can the service composition security
architecture be improved to prevent these types of attacks?
Quiz
service consumers are required to provide security credentials in order for Service A to perform
authentication using an identity store (2). If a service consumer's request message is successfully
authenticated, Service A processes the request by exchanging messages with Service B (3) and then
Service C (4). With each of these message exchanges, Service A collects data necessary to perform a
query against historical data stored in a proprietary legacy system. Service A's request to the legacy
system must be authenticated (5). The legacy system only provides access control using a single
account. If the request from Service A is permitted, it will be able to access all of the data stored in
the legacy system. If the request is not permitted, none of the data stored in the legacy system can
be accessed. Upon successfully retrieving the requested data (6), Service A generates a response
message that is sent back to either Service Consumer A or B .The legacy system is also used
independently by Service D without requiring any authentication. Furthermore, the legacy system
has no auditing feature and therefore cannot record when data access from Service A or Service D
occurs. If the legacy system encounters an error when processing a request, it generates descriptive
error codes. This service composition architecture needs to be upgraded in order to fulfill the
following new security requirements:
1. Service Consumers A and B have different permission levels, and therefore, response messages
sent to a service consumer must only contain data for which the service consumer is authorized.
2. All data access requests made to the legacy system must be logged.
3. Services B and C must be provided with the identity of Service A's service consumer in order to
provide Service A with the requested data.
4. Response messages generated by Service A cannot contain confidential error information about
the legacy system. Which of the following statements provides solutions that satisfy these
requirements?

Quiz
message to Service B (2). Service B forwards the message to have its contents calculated by Service C
(3). After receiving the results of the calculations via a response message from Service C (4), Service
B then requests additional data by sending a request message to Service D (5). Service D retrieves the
necessary data from Database A (6), formats it into an XML document, and sends the response
message containing the XML-formatted data to Service B (7). Service B appends this XML document
with the calculation results received from Service C, and then records the entire contents of the XML
document into Database B (8). Finally, Service B sends a response message to Service A (9) and
Service A sends a response message to Service Consumer A (10). Services A, B and D are agnostic
services that belong to Organization A and are also being reused in other service compositions.
Service C is a publicly accessible calculation service that resides outside of the organizational
boundary. Database A is a shared database used by other systems within Organization A and
Database B is dedicated to exclusive access by Service B .Recently, Service D received request
messages containing improperly formatted database retrieval requests. All of these request
messages contained data that originated from Service C .There is a strong suspicion that an attacker
from outside of the organization has been attempting to carry out SOL injection attacks.
Furthermore, it has been decided that each service that writes data to a database must keep a
separate log file that records a timestamp of each database record change. Because of a data privacy
disclosure requirement used by Organization A, the service contracts of these services need to
indicate that this logging activity may occur. How can the service composition architecture be
improved to avoid SQL injection attacks originating from Service C - and - how can the data privacy
disclosure requirement be fulfilled?

Quiz
identity store that Service A needs to use in order to authenticate the security credentials can only be
accessed via a legacy system that resides in a different service inventory. Therefore, to authenticate
Service Consumer A, Service A must first forward the security credentials to the legacy system (2).
The legacy system then returns the requested identity to Service A (3). Service A authenticates
Service Consumer A against the identity received from the legacy system. If the authentication is
successful, Service A retrieves the requested data from Database A (4), and returns the data in a
response message sent back to Service Consumer A (5). Service A belongs to Service Inventory A
which further belongs to Security Domain A and the legacy system belongs to Service Inventory B
which further belongs to Security Domain B .(The legacy system is encapsulated by other services
within Service Inventory B, which are not shown in the diagram.) These two security domains trust
each other. Communication between Service A and the legacy system is kept confidential using
transport-layer security. It was recently discovered that a malicious attacker, posing as Service
Consumer A, has been accessing Service A .An investigation revealed that these attacks occurred
because security credentials supplied by Service Consumer A were transmitted in plaintext.
Furthermore, vulnerabilities to replay attacks and malicious intermediaries have been detected.
Which of the following statements describes a solution that can counter these types of attacks?
Also, list the industry standards required by the proposed solution.

Quiz
message (2) and then processes the request and sends a request message to Service B (3). This
message contains confidential financial data. Service B sends three different request messages
together with its security credentials to Services C .D .and E (4, 5, 6). Upon successful authentication,
Services C .D .and E store the data from the message in separate databases (7.8, 9). Services B .C .D,
and E belong to Service Inventory A, which further belongs to Organization B .Service Consumer A
and Service A belong to Organization A .Organization B decides to create a new service inventory
(Service Inventory B) for services that handle confidential data. Access to these services is restricted
by allocating Service Inventory B its own private network. Access to this private network is further
restricted by a dedicated firewall. Services C, D and E are moved into Service Inventory B, and as a
result. Service B can no longer directly access these services. How can this architecture be changed to
allow Service B to access Services C, D and E in a manner that does not jeopardize the security of
Service Inventory B while also having a minimal impact on the service composition's performance?

Quiz
including Service Consumer A .In order to retrieve the necessary data, Service Consumer A first sends
a request message to Service A (1). Service A then exchanges request and response messages with
Service B (2, 3), Service C (4, 5), and Service D (6. 7). After receiving all three response messages
from Services B .C .and D, Service A assembles the collected data into a response message that it
returns to Service Consumer A (8). The owner of Service A charges service consumers for each usage
of the data retrieval capability. Recently, the owner of Service Consumer A has complained that the
data returned by Service A is incorrect, incomplete, and from invalid sources. As evidence, the
Service Consumer A owner has presented the owner of Service A with sample messages containing
the incorrect and incomplete contents. As a result, the Service Consumer A owner has refused to pay
the usage fees. Subsequent to an internal investigation, the owner of Service A determines that the
data returned by Service A is consistently correct and complete. There are suspicions that the Service
Consumer A owner is altering the original messages and issuing these complaints fraudulently in
order to avoid paying the usage fees. How can the owner of Service A prove that Service A is
returning correct and complete data and that this data originated from the correct sources?

Quiz
database records accessed by Service A are classified as either private or public. There are two types
of service consumers that use Service A:
Service consumers with public access permissions (allowed to access only public data records) and
service consumers with private access permissions (allowed to access all data records). For
performance reasons the Service A architecture uses a single database, named Database A .Each
record in Database A is classified as either private or public. After Service A is invoked by a service
consumer (1), it authenticates the request message using an identity store and retrieves the
corresponding authorization (2, 3). Once authorized, the service consumer's request is submitted to
Database A (4), which then returns the requested data (5) If the service consumer has private access
permissions, all of the returned data is included in Service A's response message (6). If the service
consumer has public access permissions, then Service A first filters the data in order to remove all
unauthorized private data records before sending to the response message to the service consumer
(6). In addition to retrieving data, Service A's data access capability can be used to update database
records. An investigation recently revealed an information leakage problem that can occur when
service consumers with public access permissions attempt to update the ID value of a database
record The ID values of all database records (private or public) must be unique. When a service
consumer with public access permissions updates a public database record with an ID value that is
already assigned to a private database record, the database returns an error message describing this
conflict. This error text reveals confidential information by stating that the ID value submitted by the
service consumer with public access permissions already exists within a private database record.
What steps can be taken to avoid this problem while preserving the requirement that all database
records (private and public) have unique ID values?

S90.20: Arcitura Education SOA Security Lab Practice test unlocks all online simulator questions
Thank you for choosing the free version of the S90.20: Arcitura Education SOA Security Lab practice test! Further deepen your knowledge on Arcitura Education Simulator; by unlocking the full version of our S90.20: Arcitura Education SOA Security Lab Simulator you will be able to take tests with over 30 constantly updated questions and easily pass your exam. 98% of people pass the exam in the first attempt after preparing with our 30 questions.
BUY NOWWhat to expect from our S90.20: Arcitura Education SOA Security Lab practice tests and how to prepare for any exam?
The S90.20: Arcitura Education SOA Security Lab Simulator Practice Tests are part of the Arcitura Education Database and are the best way to prepare for any S90.20: Arcitura Education SOA Security Lab exam. The S90.20: Arcitura Education SOA Security Lab practice tests consist of 30 questions and are written by experts to help you and prepare you to pass the exam on the first attempt. The S90.20: Arcitura Education SOA Security Lab database includes questions from previous and other exams, which means you will be able to practice simulating past and future questions. Preparation with S90.20: Arcitura Education SOA Security Lab Simulator will also give you an idea of the time it will take to complete each section of the S90.20: Arcitura Education SOA Security Lab practice test . It is important to note that the S90.20: Arcitura Education SOA Security Lab Simulator does not replace the classic S90.20: Arcitura Education SOA Security Lab study guides; however, the Simulator provides valuable insights into what to expect and how much work needs to be done to prepare for the S90.20: Arcitura Education SOA Security Lab exam.
BUY NOWS90.20: Arcitura Education SOA Security Lab Practice test therefore represents an excellent tool to prepare for the actual exam together with our Arcitura Education practice test . Our S90.20: Arcitura Education SOA Security Lab Simulator will help you assess your level of preparation and understand your strengths and weaknesses. Below you can read all the quizzes you will find in our S90.20: Arcitura Education SOA Security Lab Simulator and how our unique S90.20: Arcitura Education SOA Security Lab Database made up of real questions:
Info quiz:
- Quiz name:S90.20: Arcitura Education SOA Security Lab
- Total number of questions:30
- Number of questions for the test:50
- Pass score:80%
You can prepare for the S90.20: Arcitura Education SOA Security Lab exams with our mobile app. It is very easy to use and even works offline in case of network failure, with all the functions you need to study and practice with our S90.20: Arcitura Education SOA Security Lab Simulator.
Use our Mobile App, available for both Android and iOS devices, with our S90.20: Arcitura Education SOA Security Lab Simulator . You can use it anywhere and always remember that our mobile app is free and available on all stores.
Our Mobile App contains all S90.20: Arcitura Education SOA Security Lab practice tests which consist of 30 questions and also provide study material to pass the final S90.20: Arcitura Education SOA Security Lab exam with guaranteed success. Our S90.20: Arcitura Education SOA Security Lab database contain hundreds of questions and Arcitura Education Tests related to S90.20: Arcitura Education SOA Security Lab Exam. This way you can practice anywhere you want, even offline without the internet.
BUY NOW