最新的SOA Advanced SOA Security - S90.19免費考試真題
Security policies defined using WS-SecurityPolicy can be used to convey which of the following requirements to a service consumer?
正確答案: A,B,D
Which of the following types of attack always affect the availability of a service?
正確答案: C
SAML assertions are smaller than certificates and they do not require access to any remote system for verification purposes.
正確答案: A
How can the use of pre-compiled XPath expressions help avoid attacks?
正確答案: B
The use of XML schemas for data validation helps avoid several types of data-centric threats.
正確答案: B
A malicious active intermediary intercepts a message sent between two services. What concerns are raised by such an attack?
正確答案: B
An attacker is able to gain access to a service and invokes the service. Upon executing the service logic, the attacker is able to gain access to underlying service resources, including a private database. The attacker proceeds to delete data from the database. The attacker has successfully executed which type of attack?
正確答案: D
When considering the ESB as providing intermediary logic, which of the following types of subject confirmation methods relate to its access control issues?
正確答案: C
Service A's logic has been implemented using unmanaged code. An attacker sends a message to Service A that contains specially crafted data capable of manipulating the quoting within a particular XPath expression. This results in the release of confidential information. Service A is a victim of which kind of attack?
正確答案: D