S90.19 무료 덤프문제 온라인 액세스
| 시험코드: | S90.19 |
| 시험이름: | Advanced SOA Security |
| 인증사: | SOA |
| 무료 덤프 문항수: | 83 |
| 업로드 날짜: | 2026-08-25 |
An attacker is able to gain access to a service and invokes the service. Upon executing the service logic, the attacker is able to gain access to underlying service resources, including a private database. The attacker proceeds to delete data from the database. The attacker has successfully executed which type of attack?
The application of the Service Loose Coupling principle does not relate to the use of security policies as part of service contracts.
Service A requires message confidentiality using message-layer security. You are asked to create a security policy for Service A that communicates its confidentiality requirements.
However, you have not yet determined the type of encryption mechanism that will be used to enable message confidentiality. What types of binding assertions can you use to convey what service consumers should expect in the WS-Security header of SOAP messages exchanged by the service?
A utility service is responsible for encapsulating a legacy database and providing centralized access to the database for any of its service consumers. However, it is discovered that several service consumers are accessing the database directly. This is considered a security concern because much of the data in the database is classified as sensitive. How can this concern be addressed?