Your information deserves the same protection as your money. TestInsides runs a strict data safety system for every S90.19 buyer in 2026, so preparing for the SOA Advanced SOA Security never means trading away your privacy.
SOA S90.19 Exam Overview:
| Certification Vendor: | Arcitura Education |
|---|---|
| Exam Name: | Advanced SOA Security |
| Exam Number: | S90.19 |
| Real Exam Qty: | 83 |
| Exam Price: | Varies by testing center / country |
| Exam Format: | Multiple Choice |
| Certificate Validity Period: | Lifetime (no fixed expiration) |
| Passing Score: | 80% |
| Related Certifications: | Arcitura Certified SOA Security Specialist SOACP-Gen Service Security Path |
| Available Languages: | English |
| Exam Duration: | 60 minutes |
| Sample Questions: | ![]() |
| Exam Way: | Online proctored or onsite through authorized testing partners. |
| Pre Condition: | Recommended experience in SOA fundamentals and basic security concepts. |
| Official Syllabus URL: | https://www.arcitura.com/soacp-gen-1/exams/exam-s90-19-advanced-soa-security/ |
SOA S90.19 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: API & ESB Security Controls | - Security extensions for Enterprise Service Bus (ESB) - Security controls for REST and HTTP services |
| Topic 2: Transport & Message Security | - Using WS-Trust, WS-SecureConversation and SAML - Message-level and transport-level security |
| Topic 3: Authentication & Secure Sessions | - Authentication sessions and secure conversations |
| Topic 4: Threats & Risk Assessment | - Federation and trust brokering - Understanding and preparing for SOA security threats |
| Topic 5: SOA Security Governance and Policy | - Security token structures and issuance - Security policy design and governance |
Planning Your SOA Advanced SOA Security? Start With These Answers
The current exam information lists 83 questions for the S90.19 exam, with 60 minutes minutes allowed. Practicing against the clock at home builds the pacing habits that exam day rewards.
The SOA Advanced SOA Security blueprint covers these main domains:
- API & ESB Security Controls
- Threats & Risk Assessment
- Authentication & Secure Sessions
Additional domains complete the official outline, and our bank covers the full range.
Your money is protected by clear conditions. If you fail the corresponding exam within 60 days of purchase, send us a scanned copy of your enrollment slip and your official Score Report PDF within two days of the exam date; verified claims receive a full refund within seven days. The exclusions: exams taken within three days of purchase, a candidate name that does not match the payer, and free or expired products. If you prefer, we can exchange your product for two others of equal value instead.
SOA lists the following prerequisites for the SOA Advanced SOA Security: Recommended experience in SOA fundamentals and basic security concepts..
Check the official certification page for the latest requirements before booking.
Because we remove the guesswork at every step. The S90.19 bank consolidates the SOA Advanced SOA Security knowledge points into expert-verified Q&As instead of leaving you to sift through the internet alone. A free demo shows the quality before you buy; instant delivery starts you the minute you do; 365 days of free updates — with a notification each time a new version releases — keep you current; and a strict information safety system plus a 7/24 golden-standard support team protect you throughout.
As of the latest information, the S90.19 exam requires a score of 80% to pass, and registration costs Varies by testing center / country. SOA sets both figures, so verify them on the official site when you book.
Upon successful payment, our system automatically emails the product to your mailbox and shows an instant download link — delivery typically takes about a minute. If nothing arrives within two hours, check your spam folder first, then contact our 7/24 support team. Installations are unlimited. Your purchase also includes 365 days of free updates: whenever we release a new version, we notify you to download it — no need to wait or worry about validity — and a 50% renewal discount applies when the period ends.
SOA Advanced SOA Security Sample Questions:
The Service Perimeter Guard pattern has been applied to help avoid denial of service attacks for a service inventory. As a result, services within the service inventory are only accessible via a perimeter service However, denial of service attacks continue to succeed and services within the service inventory become unavailable to external service consumers. What is the likely cause of this?
- A. The Trusted Subsystem pattern should have been applied so that each service has a dedicated trusted subsystem.
- B. The perimeter service itself is the victim of denial of service attacks. As a result, none of the services inside the service inventory can be accessed by external service consumers.
- C. The application of the Service Perimeter Guard pattern needs to be combined with the application of the Message Screening pattern in order to mitigate denial of service attacks.
- D. The Service Perimeter Guard pattern does not help avoid denial of service attacks.
Correct Answer: B 🗳️
Service A has recently been the victim of XPath injection attacks. Messages sent between Service A and Service C have traditionally been protected via transport-layer security. A redesign of the service composition architecture introduces Service B, which is positioned as an intermediary service between Service A and Service C.
The Message Screening pattern was applied to the design of Service B.
As part of the new service composition architecture, transport-layer security is replaced with message-layer security for all services, but Service A and Service C continue to share the same encryption key. After the new service composition goes live, Service A continues to be subjected to XPath injection attacks. What is the reason for this?
- A. Because message-layer security is being used, it is not possible for the message screening logic in Service B to inspect messages without having the encryption key that is shared by Service A and Service C.
- B. The message screening logic can only work for Service C.
Therefore, Service A is not protected. - C. None of the above.
- D. XPath injection attacks are not prevented by message screening logic or message-layer security.
Correct Answer: A 🗳️
Which of the following statements is true?
- A. When the maxOccurs attribute in an XML schema element is not specified it creates a security risk because attackers can specify this element multiple times.
- B. When the xsd:any element is used within an XML schema it can introduce a security risk because it allows attackers to extend the schema.
- C. All of above.
- D. When numeric ranges within an XML schema are not specified it creates a security risk because attackers can introduce very large numeric values within the message data.
Correct Answer: C 🗳️
The use of a perimeter service can centralize authentication and authorization logic and it can also prevent direct access to other services positioned behind a firewall.
- A. False
- B. True
Correct Answer: B 🗳️
Service A requires message confidentiality using message-layer security. You are asked to create a security policy for Service A that communicates its confidentiality requirements.
However, you have not yet determined the type of encryption mechanism that will be used to enable message confidentiality. What types of binding assertions can you use to convey what service consumers should expect in the WS-Security header of SOAP messages exchanged by the service?
- A. Asymmetric binding assertion
- B. Symmetric binding assertion
- C. Transport binding assertion
- D. Protection binding assertion
Correct Answer: A,B 🗳️




