S90.18試験無料問題集「SOA Fundamental SOA Security 認定」

Which of the following approaches represents a valid means of utilizing generic security
logic?

Security mechanisms that are based on vendor-specific security technology will always
decrease the autonomy of services that are required to use these security mechanisms.

A valid signature issued by a certificate authority provides a guarantee that:

As a requirement for accessing Service B, Service A needs to encrypt its request message.
Service B decrypts the message, makes some changes, encrypts the message, and then
forwards it to Service C.
However, the message does not make it to Service C.
Instead, a runtime error is raised by a service agent that does not support encryption. This service
agent only requires access to the message header in order to route the message to the
appropriate instance of Service C.
It is therefore decided that the header part of the message will not be encrypted. Which of the following can be used to address this
requirement?

A certificate authority is generally responsible for

正解:A,B,C,D 解答を投票する
Symmetric and asymmetric encryption keys are always created in pairs.

Service A requires certificates signed by a trusted certificate authority. The certificate
authority publishes a Certificate Revocation List (CRL) on a frequent basis. As a result,
some of the service consumers that were previously authorized to access Service A will not
be able to after new CRLs are issued. How can this security requirement be enforced?

The services within a domain service inventory provide access to confidential data
retrieved from a shared database. These services need to be accessible from outside the
domain service inventory. Which of the following design options will preserve the
confidentiality of the data when the services are accessed from outside the service
inventory?

A service that was previously using a shared identity store is now given its own dedicated
identity store instead. What are the likely impacts (positive or negative) that will result from
this change?

The communication between two services operating within the same organization needs to
be protected using message-layer security. These services are only used within the
organizational boundary. The question is raised as to whether to use self-signed
certificates or certificates signed by a certificate authority. A security specialist states that
only certificates signed by an external certificate authority can be used to fulfill this security
requirement. Is this correct?