Arcitura Education S90.19 Exam
Advanced SOA Security (Page 6 )

Updated On: 7-Feb-2026

When designing XML schemas to avoid data-centric threats, which of the following are valid considerations?

  1. The maxOccurs attribute needs to be specified using a restrictive value.
  2. The <xsd:any> element needs to be avoided.
  3. The <xsd:restriction> element can be used to create more restrictive user-defined simple types.
  4. All of the above.

Answer(s): B,D



___________ is an industry standard that describes mechanisms for issuing, validating, renewing and cancelling security tokens.

  1. WS-Security
  2. WS-Trust
  3. WS-SecureConversation
  4. WS-SecurityPolicy

Answer(s): B



Security policies defined using WS-SecurityPolicy can be used to convey which of the following requirements to a service consumer?

  1. Whether transport-layer or message-layer security needs to be used
  2. The encryption type that needs to be used for transport-layer security
  3. The algorithms that need to be used for cryptographic operations
  4. The type of security token that must be used

Answer(s): A,C,D



Service A needs to be designed so that it supports message integrity and so that only part of the messages exchanged by the service are encrypted. You are asked to create the security policy for this service.
What type of policy assertions should you use?

  1. Token assertions
  2. Protection assertions
  3. Security binding assertions
  4. Service A's security requirements cannot be expressed in a policy

Answer(s): B



How can the use of pre-compiled XPath expressions help avoid attacks?

  1. Pre-compiled XPath expressions execute faster and therefore help avoid denial of service attacks.
  2. Pre-compiled XPath expressions reduce the chance of missing escape characters, which helps avoid XPath injection attacks
  3. Pre-compiled XPath expressions contain no white space, which helps avoid buffer overrun attacks
  4. They can't because XPath expressions cannot be pre-compiled

Answer(s): B






Post your Comments and Discuss Arcitura Education S90.19 exam prep with other Community members:

Join the S90.19 Discussion