Prüfungsinhalte ändern sich, und veraltete Lernmaterialien kosten wertvolle Zeit. Auch 2026 überarbeiten die Experten von ZertSoft die 30 Übungsfragen zur S90.20 Prüfung fortlaufend; innerhalb von 365 Tagen erhalten Sie jede Aktualisierung kostenlos.
SOA S90.20 Prüfungsübersicht:
| Zertifizierungsanbieter: | Arcitura Education |
|---|---|
| Prüfungsname: | SOA Security Lab |
| Prüfungsnummer: | S90.20 |
| Prüfungsdauer: | 60 Minuten |
| Prüfungsgebühr: | Offizielle Preise variieren je nach Region und Prüfungsanbieter |
| Anzahl der Fragen: | 30 |
| Verfügbare Sprachen: | Englisch |
| Gültigkeitsdauer des Zertifikats: | In der Regel unbefristet (keine erneute Zertifizierung erforderlich, es sei denn, der Inhalt wird aktualisiert) |
| Mindestpunktzahl: | Nicht offiziell veröffentlicht |
| Prüfungsformat: | Szenariobasierte Aufgaben, Multiple-Choice-Fragen |
| Verwandte Zertifizierungen: | Certified SOA Security Specialist |
| Beispielfragen: | Kostenlose demo |
| Prüfungsmethode: | Weltweit durchführbar bei zugelassenen Prüfungszentren oder als Online-Prüfung mit Aufsicht (z. B. über Pearson VUE) |
| Voraussetzungen: | Keine formellen Teilnahmevoraussetzungen; Grundkenntnisse zu SOA-Konzepten sowie fortgeschrittene Grundlagen im Bereich Sicherheit werden empfohlen |
| Offizielle Syllabus-URL: | https://www.arcitura.com/ |
SOA S90.20 Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Sicherheitslabor für Dienste, Microservices und SOA | - Praktische Sicherheitsszenarien - Fehleranalyse und Steuerungsmaßnahmen im Bereich Sicherheit |
| Thema 2: Erweiterte Sicherheitsaspekte für Dienste, Microservices und SOA | - Sicherheit in hybriden und mandantenübergreifenden Umgebungen - Bedrohungsanalyse und Abwehrstrategien |
| Thema 3: Technische Grundlagen von Microservices | - API-Gateways und Service-Mesh - Grundlagen der Dienstetechnologie |
| Thema 4: Grundlagen von SOA, Diensten und Microservices | - Architektur von Microservices - Zentrale Konzepte der SOA |
| Thema 5: Grundlegende Sicherheitsaspekte für Dienste, Microservices und SOA | - Verschlüsselung und sichere Protokolle - Authentifizierung und Autorisierung |
Ihre Fragen zur SOA S90.20 Zertifizierungsprüfung – beantwortet
Die SOA Security Lab (S90.20) ist eine offizielle Zertifizierungsprüfung von SOA. Mit dem Bestehen erwerben Sie die Zertifizierung SOA Certification, die dem Level Spezialist zugeordnet ist. Im fachlichen Umfeld dieser Prüfung stehen außerdem die Zertifizierungen Certified SOA Security Specialist. Für eine systematische Vorbereitung nutzen Sie die 30 Übungsfragen von ZertSoft.
Laut Herstellerangaben umfasst die S90.20 Prüfung 30 Fragen, die Sie innerhalb von 60 Minuten bearbeiten. Rechnen Sie vorab aus, wie viel Zeit Ihnen damit im Durchschnitt pro Aufgabe bleibt, und trainieren Sie dieses Tempo gezielt. Ein zeitlich begrenzter Probedurchlauf in der Test Engine von ZertSoft zeigt Ihnen früh, bei welchen Themen Sie noch zu lange grübeln – so gehen Sie mit einem realistischen Zeitgefühl in die Prüfung.
Für das Bestehen der S90.20 Prüfung ist laut SOA ein Ergebnis von Nicht offiziell veröffentlicht erforderlich; die offizielle Prüfungsgebühr liegt bei Offizielle Preise variieren je nach Region und Prüfungsanbieter. Beachten Sie: Scheitern Sie, wird bei der Wiederholung die Gebühr erneut in voller Höhe fällig. Testen Sie Ihren Wissensstand deshalb vor der Anmeldung mit den 30 Übungsfragen von ZertSoft, bis Sie die geforderte Marke im Übungsbetrieb sicher erreichen.
Vor der Anmeldung zur S90.20 Prüfung gilt Folgendes zu beachten: Keine formellen Teilnahmevoraussetzungen; Grundkenntnisse zu SOA-Konzepten sowie fortgeschrittene Grundlagen im Bereich Sicherheit werden empfohlen. Da sich die Teilnahmebedingungen ändern können, bestätigen Sie die aktuellen Anforderungen am besten direkt beim Hersteller: offizielle Prüfungsübersicht von SOA.
Ja. Laden Sie vorab die kostenlose PDF-Demo zur S90.20 Prüfung herunter und verschaffen Sie sich einen ehrlichen Eindruck von Stil und Niveau der Fragen. Nach dem Kauf bleiben Sie zusätzlich abgesichert: 365 Tage lang erhalten Sie jede Aktualisierung der SOA Security Lab Materialien kostenlos, und danach verlängern Sie den Update-Service mit 50 % Rabatt.
Bestehen Sie die S90.20 Prüfung innerhalb von 60 Tagen nach dem Kauf nicht, erhalten Sie den vollen Kaufpreis zurück. Voraussetzungen: Sie senden uns innerhalb von zwei Tagen nach dem Prüfungstermin eine eingescannte Anmeldebestätigung (Enrollment Slip) sowie Ihren offiziellen Score Report als PDF; der Kandidatenname muss mit dem Namen des Käufers übereinstimmen. Nicht anwendbar ist die Regelung, wenn Sie die Prüfung innerhalb der ersten drei Tage nach dem Kauf ablegen, die Materialien nur heruntergeladen, aber keine Prüfung absolviert haben, oder wenn es sich um kostenlose Unterlagen beziehungsweise abgelaufene Bestellungen handelt. Ihr Antrag wird innerhalb von sieben Tagen bearbeitet. Alternativ zur Rückerstattung tauschen Sie das Produkt kostenlos gegen zwei gleichwertige Prüfungsmaterialien und behalten den Update-Service für Ihr ursprüngliches Produkt. Die Lieferung selbst erfolgt sofort: Nach der Bezahlung steht der Download bereit, und die E-Mail erreicht Sie in der Regel innerhalb einer Minute – sollte sie nach zwei Stunden nicht eingegangen sein, wenden Sie sich bitte an unseren Kundenservice. Eine Begrenzung der Anzahl der Installationen gibt es nicht.
Die S90.20 Prüfung gliedert sich laut offiziellem Lehrplan in 5 Themengebiete. Zu den wichtigsten zählen:
- Sicherheitslabor für Dienste, Microservices und SOA
- Erweiterte Sicherheitsaspekte für Dienste, Microservices und SOA
- Grundlagen von SOA, Diensten und Microservices
Die vollständige Übersicht aller Prüfungsinhalte finden Sie weiter oben im Abschnitt mit den Exam Topics. Arbeiten Sie jedes Gebiet anschließend gezielt mit den Übungsfragen von ZertSoft durch.
SOA Security Lab S90.20 Prüfungsfragen mit Lösungen
Service Consumer A sends a request to Service A (1). Service A replies with an acknowledgement message (2) and then processes the request and sends a request message to Service B (3). This message contains confidential financial data. Service B sends three different request messages together with its security credentials to Services C.
D.
and E (4, 5, 6). Upon successful authentication, Services C.
D. and E store the data from the message in separate databases (7.8, 9). Services B.
C.D, and E belong to Service Inventory A, which further belongs to Organization B.
Service Consumer A and Service A belong to Organization A.
Organization B decides to create a new service inventory (Service Inventory B) for services that handle confidential data. Access to these services is restricted by allocating Service Inventory B its own private network. Access to this private network is further restricted by a dedicated firewall. Services C, D and E are moved into Service Inventory B, and as a result. Service B can no longer directly access these services.
How can this architecture be changed to allow Service B to access Services C, D and E in a manner that does not jeopardize the security of Service Inventory B while also having a minimal impact on the service composition's performance?
- A. The Service Perimeter Guard pattern is applied together with the Message Screening pattern. A new perimeter service is created specifically for Service Inventory B.
This service filters all messages before they reach the firewall and further evaluates the IP address of the messages to verify the identity of the message originators. If the originator is successfully authenticated, then the perimeter guard checks the request message for potentially malicious content. If the request message does not contain malicious content, it is sent through the firewall to proceed to Services C, D, and E for further processing. - B. The Brokered Authentication pattern is applied by extending the firewall functionality with a single sign-on mechanism. Because the firewall already restricts accesses to Service Inventory B, adding authentication logic to the firewall optimizes the performance of the overall security architecture. Service B needs to be authenticated by the authentication broker only once in order to get a security token that can be used to access Services C, D, and E.
This eliminates the need for Service B to authenticate several times during the same service composition. - C. The Service Perimeter Guard pattern is applied together with the Brokered Authentication pattern. A new perimeter service is created to intercept all request messages sent to services inside the private network (inside Service Inventory B), before they reach the firewall. The perimeter service also acts as the authentication broker that authenticates request messages sent to Services C, D, and E by evaluating the accompanying security credentials and issuing a security token to be used by Service B when accessing Services C, D, and E.
- D. The Data Confidentiality pattern is applied together with the Direct Authentication pattern. A new utility service is created to validate request messages sent to Service Inventory B.
Service B must encrypt the message content using the utility service's public key and attach its own digital certificate to the request message. This message is first evaluated by the firewall to filter out requests from disallowed sources and can then be forwarded to the utility service, which then verifies the identity of the message originator (using a digital certificate) and decrypts the request message contents. If the originator is authorized to access Services C, D, and E, the appropriate request messages are sent to these services.
Antwort: C 🗳️
Service Consumer A sends a request message to Service A (1) after which Service A retrieves financial data from Database A (2). Service A then sends a request message with the retrieved data to Service B (3). Service B exchanges messages with Service C (4) and Service D (5), which perform a series of calculations on the data and return the results to Service A.
Service A uses these results to update Database A (7) and finally sends a response message to Service Consumer A (8). Component B has direct, independent access to Database A and is fully trusted by Database A.
Both Component B and Database A reside within Organization A.
Service Consumer A and Services A, B, C, and D are external to the organizational boundary of Organization A.
Service A has recently experienced an increase in the number of requests from Service Consumer A.
However, the owner of Service Consumer A has denied that Service Consumer A actually sent these requests. Upon further investigation it was determined that several of these disclaimed requests resulted in a strange behavior in Database A, including the retrieval of confidential data. The database product used for Database A has no feature that enables authentication of consumers. Furthermore, the external service composition (Services A, B, C, D) must continue to operate at a high level of runtime performance.
How can this architecture be improved to avoid unauthenticated access to Database A while minimizing the performance impact on the external service composition?
- A. Implement a firewall between Service Consumer A and Service A.
All access to Service A is then controlled by the firewall rules. The firewall contains embedded logic that authenticates request messages and then forwards permitted messages to Service A.
Moreover, the firewall can implement the Message Screening pattern so that each incoming message is screened for malicious content. This solution minimizes the security processing performed by Service A in order to maintain the performance requirements of the external service composition. - B. Service Consumer A generates a pair of private/public keys (Public Key E and Private Key D) and sends the public key to Service A.
Service A can use this key to send confidential messages to Service Consumer A because messages encrypted by the public key of Service Consumer A can only be decrypted by Service A The Data Origin Authentication pattern can be further applied so that Service A can authenticate Service Consumer A by verifying the digital signature on request messages. The Message Screening pattern is applied to a utility service that encapsulates Database A in order to prevent harmful input. - C. A utility service is established to encapsulate Database A and to carry out the authentication of all access to the database by Service A and any other service consumers.
To further support this functionality within the utility service, an identity store is introduced.
This identity store is also used by Service A which is upgraded with its own authentication logic to avoid access by malicious service consumers pretending to be legitimate service consumers. In order to avoid redundant authentication by services within the external service composition, Service A creates a signed SAML assertion that contains the service consumer's authentication and authorization information. - D. The Brokered Authentication pattern is applied so that each service consumer generates a pair of private/public keys and sends the public key to Service A.
When any service in the external service composition (Services A, B, C, and D) sends a request message to another service, the request message is signed with the private key of the requesting service (the service acting as the service consumer). The service then authenticates the request using the already established public key of the service consumer. If authentication is successful, the service generates a symmetric session key and uses the public key of the service consumer to securely send the session key back to the service consumer. All further communication is protected by symmetric key encryption. Because all service consumers are authenticated, all external access to Database A is secured.
Antwort: C 🗳️
Service Consumer A sends a request message to Service A (1), after which Service A sends a request message to Service B (2). Service B forwards the message to have its contents calculated by Service C (3). After receiving the results of the calculations via a response message from Service C (4), Service B then requests additional data by sending a request message to Service D (5). Service D retrieves the necessary data from Database A (6), formats it into an XML document, and sends the response message containing the XML-formatted data to Service B (7).
Service B appends this XML document with the calculation results received from Service C, and then records the entire contents of the XML document into Database B (8). Finally, Service B sends a response message to Service A (9) and Service A sends a response message to Service Consumer A (10).
Services A, B and D are agnostic services that belong to Organization A and are also being reused in other service compositions. Service C is a publicly accessible calculation service that resides outside of the organizational boundary. Database A is a shared database used by other systems within Organization A and Database B is dedicated to exclusive access by Service B.
Service B has recently been experiencing a large increase in the volume of incoming request messages. It has been determined that most of these request messages were auto-generated and not legitimate. As a result, there is a strong suspicion that the request messages originated from an attacker attempting to carry out denial-of-service attacks on Service B.
Additionally, several of the response messages that have been sent to Service A from Service B contained URI references to external XML schemas that would need to be downloaded in order to parse the message data. It has been confirmed that these external URI references originated with data sent to Service B by Service C.
The XML parser currently being used by Service A is configured to download any required XML schemas by default. This configuration cannot be changed.
What steps can be taken to improve the service composition architecture in order to avoid future denial-of-service attacks against Service B and to further protect Service A from data access-oriented attacks?
- A. Apply the Service Perimeter Guard pattern and the Message Screening pattern together to establish a service perimeter guard that can filter response messages from Service C before they reach Services A and B.
The filtering rules are based on the IP address of Service C.
If a request message originates from an IP address not listed as one of the IP addresses associated with Service C.
then the response message is rejected. - B. Apply the Direct Authentication pattern so that Service C is required to provide security credentials, such as Username tokens, with any response messages it sends to Service B.
Furthermore, add logic to Service A so that it can validate security credentials passed to it via response messages from Service B.
by using an identity store that is shared by Services A and B. - C. Apply the Data Origin Authentication pattern so that Service B can verify that request messages that claim to have been sent by Service A actually did originate from Service A.
Apply the Message Screening pattern to add logic to Service A so that it can verify that external URIs in response messages from Service B refer to trusted sources. - D. Apply the Service Perimeter Guard pattern to establish a perimeter service between Service B and Service C.
Apply the Brokered Authentication pattern by turning the perimeter service into an authentication broker that is capable of ensuring that only legitimate response messages are being sent to Service C from Service B Further apply the Data Origin Authentication pattern to enable the perimeter service to verify that messages that claim to have been sent by Service C actually originated from Service C.
Apply the Message Screening pattern to add logic to the perimeter service to also verify that URIs in request messages are validated against a list of permitted URIs from where XML schema downloads have been pre-approved.
Antwort: C 🗳️

1183 Kundenrezensionen
Wir sind zuversichtlich von unseren Produkten, die wir bieten keinen Mühe-Produkt-Austausch.







Randolf -
Gut gemacht! Ausgezeichnete Prüfungsaufgaben für die Zertifizierungsprüung SOA. Wenn du diese Prüfung auch bestehen möchtest, ist es eine gute Wahl.