Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Arcitura Education S90.20 Exam - Topic 3 Question 32 Discussion

Service Consumer A sends a request message with an authentication token to Service A, but before the message reaches Service A, it is intercepted by Service Agent A (1). Service Agent A validates the security credentials and also validates whether the message is compliant with Security Policy A .If either validation fails, Service Agent A rejects the request message and writes an error log to Database A (2A). If both validations succeed, the request message is sent to Service A (2B). Service A retrieves additional data from a legacy system (3) and then submits a request message to Service B Before arriving at Service B, the request message is intercepted by Service Agent B (4) which validates its compliance with Security Policy SIB then Service Agent C (5) which validates its compliance with Security Policy B .If either of these validations fails, an error message is sent back to Service A .that then forwards it to Service Agent A so that it the error can be logged in Database A (2A). If both validations succeed, the request message is sent to Service B (6). Service B subsequently stores the data from the message in Database B (7). Service A and Service Agent A reside in Service Inventory A .Service B and Service Agents B and C reside in Service Inventory B .Security Policy SIB is used by all services that reside in Service Inventory B .Service B can also be invoked by other service from within Service Inventory B .Request messages sent by these service consumers must also be compliant with Security Policies SIB and B .New services are being planned for Service Inventory A .To accommodate service inventory-wide security requirements, a new security policy (Security Policy SIA) has been created. Compliance to Security Policy SIA will be required by all services within Service Inventory A .Some parts of Security Policy A and Security Policy SIB are redundant with Security Policy SIA .How can the Policy Centralization pattern be correctly applied to Service Inventory A without changing the message exchange requirements of the service composition?
B) The parts of Security Policy A that are redundant with Security Policy SIA are removed so that there is no overlap between these two security policies. A new service agent is introduced into Service Inventory A to validate compliance to the new Security Policy SIA prior to messages being validated by Service Agent A .
C) The parts of Security Policy A and Security Policy SIB that are redundant with Security Policy SIA are removed so that there is no overlap among these three security policies. Service Agent A is updated so that it can validate messages for compliance with both Security Policy A and Security Policy SIA .Service Agent B is updated so that it can validate messages for compliance with both Security Policy SIA and Security Policy SIB .Service Agent C remains unchanged.
D) Due to the amount of overlap among Security Policy A, Security Policy SIA, and Security Policy SIB, the Policy Centralization pattern cannot be correctly applied without changing the message exchange requirements of the service composition.
A) The parts of Security Policy A and Security Policy SIB that are redundant with Security Policy SIA are removed so that there is no overlap among these three security policies. A new service agent is introduced into Service Inventory A to validate compliance to the new Security Policy SIA prior to messages being validated by Service Agent A .Another new service agent is introduced into Service Inventory B to validate compliance to the new Security Policy SIA prior to messages being validated by Service Agents B and C .

Arcitura Education S90.20 Exam - Topic 3 Question 32 Discussion

Actual exam question for Arcitura Education's S90.20 exam
Question #: 32
Topic #: 3
[All S90.20 Questions]

Service Consumer A sends a request message with an authentication token to Service A, but before the message reaches Service A, it is intercepted by Service Agent A (1). Service Agent A validates the security credentials and also validates whether the message is compliant with Security Policy A .If either validation fails, Service Agent A rejects the request message and writes an error log to Database A (2A). If both validations succeed, the request message is sent to Service A (2B). Service A retrieves additional data from a legacy system (3) and then submits a request message to Service B Before arriving at Service B, the request message is intercepted by Service Agent B (4) which validates its compliance with Security Policy SIB then Service Agent C (5) which validates its compliance with Security Policy B .If either of these validations fails, an error message is sent back to Service A .that then forwards it to Service Agent A so that it the error can be logged in Database A (2A). If both validations succeed, the request message is sent to Service B (6). Service B subsequently stores the data from the message in Database B (7). Service A and Service Agent A reside in Service Inventory A .Service B and Service Agents B and C reside in Service Inventory B .Security Policy SIB is used by all services that reside in Service Inventory B .Service B can also be invoked by other service from within Service Inventory B .Request messages sent by these service consumers must also be compliant with Security Policies SIB and B .New services are being planned for Service Inventory A .To accommodate service inventory-wide security requirements, a new security policy (Security Policy SIA) has been created. Compliance to Security Policy SIA will be required by all services within Service Inventory A .Some parts of Security Policy A and Security Policy SIB are redundant with Security Policy SIA .How can the Policy Centralization pattern be correctly applied to Service Inventory A without changing the message exchange requirements of the service composition?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Naomi
24 days ago
Just another day in the life of service orchestration!
upvoted 0 times
...
Laurel
29 days ago
I doubt this setup is as secure as they think.
upvoted 0 times
...
Destiny
1 month ago
Wait, are they really using redundant policies? That seems inefficient.
upvoted 0 times
...
Kara
1 month ago
Totally agree, but why so many layers?
upvoted 0 times
...
Gary
1 month ago
Sounds like a complex flow with all those validations!
upvoted 0 times
...
Naomi
2 months ago
I'm guessing the key is to identify the redundant parts of the existing policies and consolidate them into the new Security Policy SIA. Gotta love these architecture challenges!
upvoted 0 times
...
Audra
2 months ago
Haha, this reminds me of that time I had to navigate a maze of security policies just to send a simple request. Good luck, folks!
upvoted 0 times
...
Hyman
2 months ago
Hmm, this is a tricky one. Centralizing the security policies could help, but we need to be careful not to break the existing message exchange requirements.
upvoted 0 times
...
Rasheeda
2 months ago
I'm not sure I fully understand the scenario, but it sounds like there's a lot of security policies and validation happening across different services.
upvoted 0 times
...
Dorcas
2 months ago
The question seems to be about applying the Policy Centralization pattern to Service Inventory A without changing the message exchange requirements. Interesting!
upvoted 0 times
...
Felicitas
3 months ago
I recall that in a similar practice question, we had to ensure compliance without changing the message structure. Maybe we can implement a layer that checks compliance against SIA while still allowing A and SIB to function as they are?
upvoted 0 times
...
Delisa
3 months ago
I feel a bit confused about how to integrate the new policy without disrupting the current validations. I think we might need to create a mapping of the existing policies to see where they overlap.
upvoted 0 times
...
Eladia
3 months ago
This question reminds me of a practice scenario where we had to balance multiple security policies. I think we might need to ensure that Security Policy SIA encompasses the necessary elements of A and SIB without duplicating them.
upvoted 0 times
...
Shawn
4 months ago
I remember we discussed the importance of centralizing security policies to reduce redundancy, but I'm not entirely sure how to apply it without affecting the existing message flows.
upvoted 0 times
...
Fannie
4 months ago
Hmm, this is tricky. I'm not entirely sure where to begin, but I think breaking down the problem into smaller steps will be key. First, I'll need to fully understand the current architecture and policies. Then I can start brainstorming ways to apply the Policy Centralization pattern.
upvoted 0 times
...
Elke
4 months ago
This looks challenging, but I think I have a plan. I'll start by analyzing the security policies to find the overlapping requirements. Then I'll explore ways to centralize those common elements into a new, consolidated policy for Service Inventory A.
upvoted 0 times
...
Rasheeda
4 months ago
I'm a bit confused by all the different services, agents, and policies. I'll need to map out the flow and dependencies to get a clear picture before I can start strategizing a solution.
upvoted 0 times
...
Dallas
4 months ago
Okay, let's think this through step-by-step. The key seems to be applying the Policy Centralization pattern to Service Inventory A without changing the existing message exchange requirements. I'll need to identify the redundant parts of the policies and find a way to consolidate them.
upvoted 0 times
...
Herman
4 months ago
This is a complex question with a lot of moving parts. I'll need to carefully read through the details and diagram to understand the full service composition and security policies involved.
upvoted 0 times
...

Save Cancel