MultipleChoice
The use of session keys and symmetric cryptography results in:
OptionsMultipleChoice
Service A's logic has been implemented using unmanaged code. An attacker sends a message to Service A that contains specially crafted data capable of manipulating the quoting within a particular XPath expression. This results in the release of confidential information. Service A is a victim of which kind of attack?
OptionsMultipleChoice
The difference between the Exception Shielding and Message Screening patterns is in how the core service logic processes incoming messages received by malicious service consumers?
OptionsMultipleChoice
An IT enterprise has three domain service inventories that map to three different departments. Each service inventory uses a security token service (STS) based authentication broker to enable single sign-on for services within the respective service inventory boundary. The tokens used for all single sign-on mechanisms are based on SAML assertions. You are given a new requirement to extend this security architecture so that services from different domain service inventories can communicate. What new security mechanisms are required to fulfill this requirement?
OptionsMultipleChoice
Architects responsible for a domain service inventory are being asked to make some of their services available to service consumers from outside the organization. However, they are reluctant to do so and consult you to help define a security architecture that will keep all of the existing services within the domain service inventory hidden within a private network. Which option best is a valid approach for fulfilling this requirement?
OptionsMultipleChoice
The Service Perimeter Guard pattern is applied to position a perimeter service outside of the firewall. The firewall only permits the perimeter service to access services within a specific service inventory. Which option best statements describes a valid problem with this security architecture?
OptionsMultipleChoice
Which of the following are types of security sessions?
OptionsMultipleChoice
A malicious passive intermediary intercepts messages sent between two services. Which option best is the main security concern raised by this situation?
Options