SOA S90.20 echte frage : SOA Security Lab

  • Prüfungscode: S90.20
  • Prüfungsname: SOA Security Lab
  • Aktualisiert: 04-09-2026
  • Anzahl: 30 Fragen und Antworten

PDF Version

€49.98 PDF Version Demo

PC Simulationssoftware

Online Test Engine

Preis: €49.98

Auch 2026 gehört die Zertifizierung hinter der SOA Security Lab zu den gefragten Nachweisen der IT-Branche. Mit den 30 Übungsfragen von EchteFrage bereiten Sie sich praxisnah auf die S90.20 Prüfung vor.

SOA S90.20 Prüfungsübersicht:

Zertifizierungsanbieter:Arcitura Education
Prüfungsname:SOA Security Lab
Prüfungsnummer:S90.20
Gültigkeitsdauer des Zertifikats:In der Regel unbefristet (keine erneute Zertifizierung erforderlich, es sei denn, der Inhalt wird aktualisiert)
Prüfungsgebühr:Offizielle Preise variieren je nach Region und Prüfungsanbieter
Prüfungsformat:Multiple-Choice-Fragen, Szenariobasierte Aufgaben
Anzahl der Fragen:30
Verwandte Zertifizierungen:Certified SOA Security Specialist
Mindestpunktzahl:Nicht offiziell veröffentlicht
Prüfungsdauer:60 Minuten
Verfügbare Sprachen:Englisch
Beispielfragen:S90.20 echte Fragen
Prüfungsmethode:Weltweit durchführbar bei zugelassenen Prüfungszentren oder als Online-Prüfung mit Aufsicht (z. B. über Pearson VUE)
Voraussetzungen:Keine formellen Teilnahmevoraussetzungen; Grundkenntnisse zu SOA-Konzepten sowie fortgeschrittene Grundlagen im Bereich Sicherheit werden empfohlen
Offizielle Syllabus-URL:https://www.arcitura.com/

SOA S90.20 Prüfungsthemen:

AbschnittZiele
Erweiterte Sicherheitsaspekte für Dienste, Microservices und SOA- Sicherheit in hybriden und mandantenübergreifenden Umgebungen
- Bedrohungsanalyse und Abwehrstrategien
Technische Grundlagen von Microservices- API-Gateways und Service-Mesh
- Grundlagen der Dienstetechnologie
Sicherheitslabor für Dienste, Microservices und SOA- Praktische Sicherheitsszenarien
- Fehleranalyse und Steuerungsmaßnahmen im Bereich Sicherheit
Grundlegende Sicherheitsaspekte für Dienste, Microservices und SOA- Authentifizierung und Autorisierung
- Verschlüsselung und sichere Protokolle
Grundlagen von SOA, Diensten und Microservices- Zentrale Konzepte der SOA
- Architektur von Microservices

S90.20 Prüfungs-FAQ: Ihre Fragen, unsere Antworten

Die S90.20 Prüfung (SOA Security Lab) ist eine offizielle Zertifizierungsprüfung von SOA. Mit dem Bestehen erlangen Sie die Zertifizierung SOA Certification. Sie ist der Stufe Spezialist zugeordnet. In engem Zusammenhang stehen außerdem die Zertifizierungen Certified SOA Security Specialist.

Die S90.20 Prüfung umfasst 30 Fragen in 60 Minuten. Daraus ergibt sich ein straffes Antworttempo: Verlieren Sie sich nicht zu lange in einzelnen Fragen, markieren Sie unsichere Punkte und behalten Sie am Ende eine Zeitreserve für den zweiten Durchgang. Am wirksamsten trainieren Sie dieses Zeitmanagement, indem Sie die 30 Übungsfragen von EchteFrage mehrfach unter realen Zeitbedingungen durcharbeiten – die Desktop- und die Online Test Engine begleiten Sie dabei mit einem Zeitlimit wie im Prüfungszentrum.

Zum Bestehen der S90.20 Prüfung benötigen Sie Nicht offiziell veröffentlicht. Die offizielle Prüfungsgebühr beträgt Offizielle Preise variieren je nach Region und Prüfungsanbieter; beachten Sie, dass bei einem Nichtbestehen der volle Betrag für jeden Wiederholungsversuch erneut anfällt. Messen Sie daher Ihren Wissensstand vor der Anmeldung mit den Übungsfragen von EchteFrage: Liegen Ihre Ergebnisse in den Übungstests stabil über der Bestehensgrenze, ist der Prüfungstermin eine gut investierte Entscheidung.

Für die S90.20 Prüfung gilt: Keine formellen Teilnahmevoraussetzungen; Grundkenntnisse zu SOA-Konzepten sowie fortgeschrittene Grundlagen im Bereich Sicherheit werden empfohlen Da Hersteller ihre Zulassungsbedingungen gelegentlich anpassen, bestätigen Sie die aktuellen Vorgaben bitte vor der Anmeldung auf der offiziellen Seite von SOA: Offizielle Prüfungsinformationen zur SOA Security Lab.

Ja. Laden Sie einfach die kostenlose PDF-Demo zur S90.20 Prüfung herunter und prüfen Sie Qualität und Schwierigkeitsgrad der Fragen, bevor Sie sich entscheiden. Nach dem Kauf erhalten Sie außerdem 365 Tage lang kostenlose Updates: Sobald sich die Prüfungsinhalte ändern, sendet Ihnen EchteFrage die aktualisierte Version automatisch per E-Mail. Nach Ablauf des Jahres verlängern Sie den Update-Service mit 50 % Rabatt.

Sollten Sie die entsprechende Prüfung innerhalb von 60 Tagen nach dem Kauf nicht bestehen, erstatten wir Ihnen den Kaufpreis vollständig (100% Money Back Guarantee). Voraussetzungen: Die Prüfung wurde frühestens drei Tage nach dem Kauf abgelegt, der Name des Prüflings stimmt mit dem des Zahlenden überein, und Sie reichen innerhalb von zwei Tagen nach der Prüfung die Anmeldebestätigung (Enrollment Slip) als Scan sowie das offizielle Score Report als PDF ein – die Bearbeitung erfolgt innerhalb von sieben Tagen. Ausgenommen sind kostenlose Materialien und abgelaufene Bestellungen. Alternativ zur Rückerstattung können Sie kostenlos zwei gleichwertige Prüfungsvorbereitungen wählen und behalten dabei den Update-Service Ihres gekauften Produkts. Die Lieferung erfolgt unmittelbar nach Zahlungseingang als Sofort-Download: Ihre Unterlagen erreichen Sie innerhalb einer Minute per E-Mail; sollte die Nachricht nach zwei Stunden noch nicht eingegangen sein, wenden Sie sich bitte an unseren Kundendienst. Eine Begrenzung der Installationen auf verschiedenen Computern gibt es nicht.

Die S90.20 Prüfung gliedert sich in 5 Themenbereiche. Zu den wichtigsten zählen:

  • Grundlagen von SOA, Diensten und Microservices
  • Sicherheitslabor für Dienste, Microservices und SOA
  • Grundlegende Sicherheitsaspekte für Dienste, Microservices und SOA

Die vollständige Aufstellung aller Bereiche samt Gewichtung finden Sie in der Prüfungsübersicht weiter oben auf dieser Seite.

SOA Security Lab S90.20 Prüfungsfragen mit Lösungen

Frage #1

Service Consumer A sends a request message to Service A (1), after which Service A sends a request message to Service B (2). Service B forwards the message to have its contents calculated by Service C (3). After receiving the results of the calculations via a response message from Service C (4), Service B then requests additional data by sending a request message to Service D (5). Service D retrieves the necessary data from Database A (6), formats it into an XML document, and sends the response message containing the XML-formatted data to Service B (7).
Service B appends this XML document with the calculation results received from Service C, and then records the entire contents of the XML document into Database B (8). Finally, Service B sends a response message to Service A (9) and Service A sends a response message to Service Consumer A (10).

Services A, B and D are agnostic services that belong to Organization A and are also being reused in other service compositions. Service C is a publicly accessible calculation service that resides outside of the organizational boundary. Database A is a shared database used by other systems within Organization A and Database B is dedicated to exclusive access by Service B.
Service B has recently been experiencing a large increase in the volume of incoming request messages. It has been determined that most of these request messages were auto-generated and not legitimate. As a result, there is a strong suspicion that the request messages originated from an attacker attempting to carry out denial-of-service attacks on Service B.
Additionally, several of the response messages that have been sent to Service A from Service B contained URI references to external XML schemas that would need to be downloaded in order to parse the message data. It has been confirmed that these external URI references originated with data sent to Service B by Service C.
The XML parser currently being used by Service A is configured to download any required XML schemas by default. This configuration cannot be changed.
What steps can be taken to improve the service composition architecture in order to avoid future denial-of-service attacks against Service B and to further protect Service A from data access-oriented attacks?

A. Apply the Service Perimeter Guard pattern to establish a perimeter service between Service B and Service C.
Apply the Brokered Authentication pattern by turning the perimeter service into an authentication broker that is capable of ensuring that only legitimate response messages are being sent to Service C from Service B Further apply the Data Origin Authentication pattern to enable the perimeter service to verify that messages that claim to have been sent by Service C actually originated from Service C.
Apply the Message Screening pattern to add logic to the perimeter service to also verify that URIs in request messages are validated against a list of permitted URIs from where XML schema downloads have been pre-approved.
B. Apply the Service Perimeter Guard pattern and the Message Screening pattern together to establish a service perimeter guard that can filter response messages from Service C before they reach Services A and B.
The filtering rules are based on the IP address of Service C.
If a request message originates from an IP address not listed as one of the IP addresses associated with Service C.
then the response message is rejected.
C. Apply the Data Origin Authentication pattern so that Service B can verify that request messages that claim to have been sent by Service A actually did originate from Service A.
Apply the Message Screening pattern to add logic to Service A so that it can verify that external URIs in response messages from Service B refer to trusted sources.
D. Apply the Direct Authentication pattern so that Service C is required to provide security credentials, such as Username tokens, with any response messages it sends to Service B.
Furthermore, add logic to Service A so that it can validate security credentials passed to it via response messages from Service B.
by using an identity store that is shared by Services A and B.


Frage #2

Service Consumer A sends a request message to Service A (1) after which Service A retrieves financial data from Database A (2). Service A then sends a request message with the retrieved data to Service B (3). Service B exchanges messages with Service C (4) and Service D (5), which perform a series of calculations on the data and return the results to Service A.
Service A uses these results to update Database A (7) and finally sends a response message to Service Consumer A (8). Component B has direct, independent access to Database A and is fully trusted by Database A.
Both Component B and Database A reside within Organization A.
Service Consumer A and Services A, B, C, and D are external to the organizational boundary of Organization A.

Component B is considered a mission critical program that requires guaranteed access to and fast response from Database A.
Service A was recently the victim of a denial of service attack, which resulted in Database A becoming unavailable for extended periods of time (which further compromised Component B). Additionally, Services B, C, and D have repeatedly been victims of malicious intermediary attacks, which have further destabilized the performance of Service A.
How can this architecture be improved to prevent these attacks?

A. The Direct Authentication pattern is applied so that when Service Consumer A submits security credentials, Service A will be able to evaluate the credentials in order to authenticate the request message. If the request message is permitted, Service A invokes the other services and accesses Database A.
Database A is replicated so that only the replicated version of the database can be accessed by Service A and other external service consumers.
B. Service Consumer A generates a private/public key pair and sends this public key and identity information to Service A.
Service A generates its own private/public key pair and sends it back to Service Consumer A.
Service Consumer A uses the public key of Service A to encrypt a randomly generated session key and then sign the encrypted session key with the private key. The encrypted, signed session key is sent to Service A.
Now, this session key can be used for secure message-layer communication between Service Consumer A and Service A.
The Service Perimeter Guard pattern is applied to establish a perimeter service that encapsulates Database A in order to authenticate all external access requests.
C. Services B, C, and D randomly generate Session Key K, and use this key to encrypt request and response messages with symmetric encryption. Session Key K is further encrypted itself asymmetrically. When each service acts as a service consumer by invoking another service, it decrypts the encrypted Session Key K and the invoked service uses the key to decrypt the encrypted response. Database A is replicated so that only the replicated version of the database can be accessed by Service A and other external service consumers.
D. A utility service is created to encapsulate Database A and to assume responsibility for authenticating all access to the database by Service A and any other service consumers.
Due to the mission critical requirements of Component B, the utility service further contains logic that strictly limits the amount of concurrent requests made to Database A from outside the organizational boundary. The Data Confidentiality and Data Origin Authentication patterns are applied to all message exchanged within the external service composition in order to establish message-layer security.


Frage #3

Service Consumer A sends a request message with an authentication token to Service A, but before the message reaches Service A, it is intercepted by Service Agent A (1). Service Agent A validates the security credentials and also validates whether the message is compliant with Security Policy A.
If either validation fails, Service Agent A rejects the request message and writes an error log to Database A (2A). If both validations succeed, the request message is sent to Service A (2B).
Service A retrieves additional data from a legacy system (3) and then submits a request message to Service B Before arriving at Service B, the request message is intercepted by Service Agent B (4) which validates its compliance with Security Policy SIB then Service Agent C (5) which validates its compliance with Security Policy B.
If either of these validations fails, an error message is sent back to Service A.
that then forwards it to Service Agent A so that it the error can be logged in Database A (2A). If both validations succeed, the request message is sent to Service B (6). Service B subsequently stores the data from the message in Database B (7).
Service A and Service Agent A reside in Service Inventory A.
Service B and Service Agents B and C reside in Service Inventory B.
Security Policy SIB is used by all services that reside in Service Inventory B.
Service B can also be invoked by other service consumers from Service Inventory B.
Request messages sent by these service consumers must also be compliant with Security Policies SIB and B.

Access to the legacy system in Service Inventory A is currently only possible via Service A, which means messages must be validated for compliance with Security Policy A.
A new requirement has emerged to allow services from Service Inventory B to access the legacy system via a new perimeter service that will be dedicated to processing request messages from services residing in Service Inventory B.
Because the legacy system has no security features, all security processing will need to be carried out by the perimeter service.
However, there are parts of Security Policy A that are specific to Service A and do not apply to the legacy system or the perimeter service. Furthermore, response messages sent by the perimeter service to services from Service Inventory B will still need to be validated for compliance to Security Policy B and Security Policy SIB.
How can the Policy Centralization pattern be correctly applied without compromising the policy compliance requirements of services in both service inventories?

A. A single centralized security policy can be created by combining Security Policy A, Security Policy B.
and Security Policy SIB into a single security policy that is shared by services in both Service Inventory A and Service Inventory B.
This means that the new perimeter service can share the same new security policy with Service A.
This further simplifies message exchange processing because request messages sent by services in Service Inventory B to the new perimeter service need to comply to the same security policy as the response messages sent back by the perimeter service to the services in Service Inventory B.
B. Due to the amount of overlap among Security Policy A, Security Policy B, and Security Policy SIB, the Policy Centralization pattern cannot be correctly applied to enable the described message exchange between the perimeter service in Service Inventory A and services in Service Inventory B.
C. In order for Security Policy A to be centralized so that it can be shared by Service A and the new perimeter service, messages sent to the perimeter service from services in Service Inventory B will need to continue complying with Security Policy A, even if it requires that the messages contain content that does not relate to accessing the legacy system. In order to centralize Security Policy B it will need to be combined with Security Policy SIB, which means that the functionality within Service Agents B and C can be combined into a single service agent.
D. The parts of Security Policy A that are required for access to the new perimeter service need to be removed and placed into a new security policy that is shared by Service A and the perimeter service. Messages sent by services accessing the perimeter service from Service Inventory B will need to be compliant with the new security policy. Because the perimeter service is dedicated to message exchange with services from Service Inventory B, response messages sent by the perimeter service can be designed for compliance to Security Policy B and Security Policy SIB.


Fragen und Antworten:

Frage #1
Antwort: C
Frage #2
Antwort: D
Frage #3
Antwort: D

1050 KundenrezensionenNeueste Kommentare

Adick - 

Ich habe heute die S90.20 Prüfung mit hohen Noten bestanden, nachdem ich ihr neusetes Studienmaterial aus EchteFrage gelernt hatte. Es ist sehr nützlich. Dringend empfehlen!

Altwicker - 

Ich habe gerade die Prüfung mit hohen Noten bei meinem ersten Versuch bestanden. Dieses Studienmaterial ist sehr gut. Es deckt alle Schwerpunkte der Prüfung ab. Der Inhalt scheint ziemlich präzis für mich.

Glasenapp - 

Ich habe neulich die Prüfung S90.20 abgelegt und bestanden, nachdem ich die Prüfungsaufgaben von EchteFrage S90.20 benutzt habe. Wenn du über sie verfügst, wirst du dich gut bei der Prüfung SOA verhalten.

Mönnich - 

Ich kann nicht glauben, dass ich meine Prüfung S90.20 so mühlos bestand. Ich bin zufrieden mit meinen Noten. Ich habe vor, die Prüfung S90.20 abzulegen. Und ich bin sicher, dass ich sie mithilfe der EchteFrage bestimmt bestehen kann.

Billinger - 

Ich habe ihre Prüfungsaufgaben für die S90.20 Prüfung vor zwei Wochen gekauft. Und ich bestand die Prüfung. Ich habe diese Prüfungsaufgaben meienen Freuden empfohlen. Später werde ich ihre Prüfungsaufgaben wieder benutzen. Vielen vielen Dank.

Anslow - 

Gutes Lernmaterial für die Prüfung. Ich habe heute meine Prüfung S90.20 bestanden. Ohne dieses Lernmaterial würde ich die Prüfung S90.20 niemals bestehen. Vielen Dank!

Popper - 

Ihr habt sehr gut gemacht! Ich bin zufireden mit den Studienmaterialen von EchteFrage. Ich habe die Prüfung mühlos bestanden. Vielen Dank.

Auquet - 

Vor einigen Monaten entschluss ich mich, die Prüfung SOA S90.20& C90.01 abzulegen. Ich mochte kein Geld für Ausbildungskurs ausgeben, daher kaufte ich die neueste Studienführung von dieser zwei Prüfungen. Ich habe in der letzten Woche diese zwei Prüfungen bestanden. Vielen Dank für Ihre Hilfe!

Cranz - 

Ich habe gerade die Prüfung S90.20 mit hohen Noten bestanden. Ich bereite die Prüfung mithilfe des Lernmaterials von EchteFrage SOA. Viele Dank für ihre Hilfe.

Anten - 

Diese Ausbildungsunterlagen sind gute Studienführung für die Prüfung S90.20. Ich habe dieses Lernmaterial Seite für Seite gelernt und die Prüfung bestanden. Ich empfehle jedem dieses Material, der sich auf die Prüfung S90.20 vorbereitet.

Reginald - 

Ich bin ziemlich zufrieden mit den Prüfungsaufgaben von EchteFrage für meine S90.20 Prüfung. Ich bestand mit hohen Noten.

Anschau - 

Ich bestand S90.20 PRrüfung mühlos. Ich will EchteFrage den anderen Kandidaten empfehlen. Vielen Dank für ihr gute Studienmaterialien und guten Kundendienst.

Buchner - 

Ich habe zweimal die S90.20 Prüfung abgelegt, und ich scheitere zweimal. Mein Freund schlägt vor, dass ich die Studienmaterialien aus EchteFrage benutzen kann. Dann kaufte ich die Prüfungsfragen in PDF-Version aus EchteFrage. Ich bin mit dem Ergebnis sehr zufrieden. Vielen Dank!

Abraham - 

Ausgezeichnet für die Vorbereitung der Prüfung S90.20! Ich habe diese Trainingsunterlagen benutzt und meine Prüfung S90.20 mit hohen Punktzahlen bestanden. Es ist mir das Geld wert. Ich empfehle es Ihnen dringend.

Zapp - 

Eine vollständige Studienführung für die S90.20 Prüfung. Ich habe sie heute bestanden. Danke.

Walden - 

Ich kaufte die alte Version von Prüfungsaufgaben für S90.20, aber dann bietet EchteFrage eine neue Version, die für das Bestehen der Prüfung ganz effektiv ist. Dank für den guten Kundendienst von EchteFrage.

Kommentar hinfügen

Qualität und Wert

Zertifizierungsfragen von EchteFrage werden nach den höchsten technischen Kriterien nur von denjenigen analysiert und ausgewählt, die schon zertifiziert und als bekannte Fachleute in der IT-Branche betrachtet sind.

Überprüft und Zertifiziert

Wir widmen uns dem Angebot der hochqualitiven Produkte, das von den Lieferanten und der dritten Seite als rechtlich und effizient bestätigt wird. Wir haben eine Profi-Lizenz, so dass wir Ihnen die Qualität und Vielfältigkeit unserer Produkte gewährleisten können.

Schlüssel zum leichten Erfolg

Benutzen Sie unsere Prüfungsunterlagen bei der Vorbereitung der Zertifizierungsprüfung, wird es leichter sein, beim ersten Versuch zu bestehen. Die Bestehensquote ist höher als 98%. Schaffen Sie die Prüfung nicht, versprechen wir Ihnen eine volle Rückerstattung.

Probe vor dem Kauf

Vor dem Kauf können Sie zunächt kostenlose Demo herunterladen. Während Sie die Demo probeweise gebrauchen, können Sie das Aussehen, die Qualität und Brauchbarkeit unserer Prüfungsunterlagen kennenlernen, dann ist es noch nicht spät, sich für den Kauf entscheiden.