S90.20 Practice Materials are highly similar to the real exam. S90.20 Study Guide covers all knowledge points for the customers. S90.20 Preparation Questions have been adapted and compiled carefully to ensure they are suitable for all people.

SOA S90.20 exam : SOA Security Lab

S90.20 Exam Questions
  • Exam Code: S90.20
  • Exam Name: SOA Security Lab
  • Updated: Oct 05, 2026
  • Q & A: 30 Questions and Answers
PDF
  • SOA S90.20 Q&A - in .pdf

  • Printable SOA S90.20 PDF Format. It is an electronic file format regardless of the operating system platform.
  • PDF Version Price: $49.99
  • Free Demo
Software
  • SOA S90.20 Q&A - Testing Engine

  • Install on multiple computers for self-paced, at-your-convenience training.
  • PC Test Engine Price: $49.99
  • Testing Engine
Online test
  • SOA S90.20 Value Pack

  • If you purchase Adobe 9A0-327 Value Pack, you will also own the free online test engine.
  • PDF Version + PC Test Engine + Online Test Engine (free)
  • Value Pack Total: $99.98  $69.99   (Save 50%)
    Online Engine (Free)

Contact US:

Support: Contact now 

Free Demo Download

Over 69418+ Satisfied Customers

About SOA S90.20 Exam Guide

The moment you decide to certify, momentum matters. TorrentExam delivers the S90.20 package by instant download, with an email copy within one minute of payment — 30 practice questions for the SOA Security Lab on your device before the motivation fades.

SOA S90.20 Exam Syllabus Topics:

SectionObjectives
Topic 1: Security Governance- Policy enforcement and compliance considerations
- Auditability and monitoring in SOA security
Topic 2: Message and Transport Security- WS-Security standards and message protection
- Encryption and digital signatures
Topic 3: Identity and Access Management- Federated identity and trust management
- Authentication and authorization mechanisms
Topic 4: SOA Security Fundamentals- Security principles in service-oriented architecture
- Security risks and threat models in SOA environments
Topic 5: Service Security Design- Secure service design patterns
- Service exposure and gateway security controls

S90.20 Exam FAQs: Everything Worth Knowing First

Delivery is immediate: download starts right after payment, and an email copy arrives within one minute. If nothing lands within 2 hours, check your spam folder and contact our support team — professional staff can even help you remotely if you hit difficulties with the download or installation. There is no limit on how many computers you may install the software on.

If you take the S90.20 exam within 60 days of purchase and do not pass, the TorrentExam money back guarantee applies: file your claim within 2 days of the exam with a scanned enrollment slip and the official score report (PDF), and it will be processed within 7 days. The candidate name must match the payer name; the policy does not cover exams taken within 3 days of purchase, purchases never used in an actual exam attempt, free materials, or expired orders. If you would rather continue learning than refund, you can exchange the product for two free exam packages of equal value and keep the update service on your original purchase.

Recommended: completion of SOA Security Specialist training or equivalent knowledge of SOA concepts and web service security.

Vendor rules change periodically, so before scheduling, confirm the latest requirements on the official SOA exam page.

For the SOA Security Lab, SOA recommends the following training:

Formal training builds understanding; focused practice builds exam-day performance. Combine either resource above with 30 practice questions from TorrentExam and you cover both.

The S90.20 exam — officially the SOA Security Lab — is SOA's certification test for professionals working with its technologies, and passing it awards the SOA Security Specialist certification at the Professional level. Whether you are a student, an office worker, or a veteran of the field, a vendor-issued credential is one of the few qualifications every employer reads the same way. It also leads naturally toward SOA Security Specialist.

The SOA Security Lab syllabus is divided into 5 domains, headlined by Security Governance, Message and Transport Security, and Service Security Design. The complete weighted outline is in the syllabus section above — let it direct your preparation toward the points that matter most.

Yes — a free trial comes before any payment at TorrentExam. You can download sample PDF questions of the S90.20 materials at no cost and see clearly how the PC and online versions operate, so the decision is fully informed. After purchase, 365 days of free updates are included, and an expired product's update service renews at a 50% discount from your member zone.

The SOA Security Lab is booked through these official channels:

When scheduling, note that the S90.20 exam is delivered Online proctored lab-based exam.

SOA Security Lab Sample Questions:

Question #1

Service A is a publically accessible service that provides free multimedia retrieval capabilities to a range of service consumers. To carry out this functionality, Service A is first invoked by Service Consumer A (1). Based on the nature of the request message received from Service Consumer A, Service A either invokes Service B or Service C.
When Service B is invoked by Service A (2A) it retrieves data from publicly available sources (not shown) and responds with the requested data (3A). When Service C is invoked by Service A (2B) it retrieves data from proprietary sources within the IT enterprise (not shown) and responds with the requested data (3B). After receiving a response from Service B or Service C, Service A sends the retrieved data to Service Consumer A (4).
Service B does not require service consumers to be authenticated, but Service C does require authentication of service consumers. The service contract for Service A therefore uses WS-Policy alternative policies in order to express the two different authentication requirements to Service Consumer A.
When Service Consumer A sends a request message (1), Service A determines whether the request requires the involvement of Service C and then checks to ensure that the necessary security credentials were received as part of the message. If the credentials provided by Service Consumer A are verified. Service A creates a signed SAML assertion and sends it with the request message to Service C (2B) This authentication information is protected by public key encryption However, responses to Service Consumer A's request message (3B, 4) are not encrypted for performance reasons.

The owner of Service C is planning two changes to the service architecture: 1. A fee will be charged to Service Consumer A (or any service consumer) using Service C.
2. The response messages issued by Service C need to be secured in order to prevent unauthorized access. An analysis of Service C's usage statistics reveals that a group of service consumers specifically request the retrieval of multimedia data on a frequent basis.
To promote the usage of Service C to these types of service consumers, the owner of Service C plans to offer a special discount by allowing unlimited multimedia retrievals for a fixed monthly price. Service consumers that do not subscribe to this promotion will need to pay for each request individually. It is anticipated that the new promotion will significantly increase the usage of Service C.
The owner of Service C therefore wants to ensure that the security added to the response messages has a minimal impact on Service C's runtime performance.
What steps can be taken to fulfill these requirements?

  • A. Design the service composition architecture so that the encryption of the response messages is performed by Service B and Service C.
    To reduce the performance impact, a policy can be added to Service A's service contract in order to require the encryption of all response messages, regardless of the type of service consumer making the request.
    Further, a new utility service can be added to the service composition. This service can be responsible for obtaining the public key of the service consumer and forwarding the key along with the request message to the appropriate service (Service B or Service C). The service receiving the message can then encrypt the response message with the received public key. Service A can then forward the encrypted response to the service consumer.
    This approach ensures that only authorized service consumers will be able to access response messages.
  • B. Design Service C to generate a message digest of the response message and encrypt it with the service consumer's public key. Because the message digest is typically small, the performance of public key encryption is acceptable. This approach also ensures that only the service consumer can decrypt the response message using the corresponding private key.
  • C. Use symmetric session keys so that for each response message, Service C generates a session key and encrypts the response message using this session key. The session key is then encrypted (using the service consumer's public key) and attached to the encrypted response. A single session key can then be used by Service C for communication with all service consumers that subscribe to the promotion.
  • D. Because the services in this service composition already rely on public key encryption to provide authentication, Service C can provide message confidentiality by encrypting the response message with Service Consumer A's public key. This will ensure that only the intended recipient, in possession of the corresponding private key, can decrypt the response message. To further reduce the performance impact of encryption, Service C can generate a new public-private key pair to be used by service consumers subscribed to the promotion. By securely distributing the private key to each of these service consumers, Service C only needs to encrypt the response messages once with the public key.
Reveal Solution  Discussion  0

Correct Answer: C  🗳️

Question #2

Service Consumer A sends a request to Service A (1). Service A replies with an acknowledgement message (2) and then processes the request and sends a request message to Service B (3). This message contains confidential financial data. Service B sends three different request messages together with its security credentials to Services C.
D.
and E (4, 5, 6). Upon successful authentication, Services C.
D. and E store the data from the message in separate databases (7.8, 9). Services B.
C.D, and E belong to Service Inventory A, which further belongs to Organization B.
Service Consumer A and Service A belong to Organization A.

Organization B decides to create a new service inventory (Service Inventory B) for services that handle confidential data. Access to these services is restricted by allocating Service Inventory B its own private network. Access to this private network is further restricted by a dedicated firewall. Services C, D and E are moved into Service Inventory B, and as a result. Service B can no longer directly access these services.
How can this architecture be changed to allow Service B to access Services C, D and E in a manner that does not jeopardize the security of Service Inventory B while also having a minimal impact on the service composition's performance?

  • A. The Data Confidentiality pattern is applied together with the Direct Authentication pattern. A new utility service is created to validate request messages sent to Service Inventory B.
    Service B must encrypt the message content using the utility service's public key and attach its own digital certificate to the request message. This message is first evaluated by the firewall to filter out requests from disallowed sources and can then be forwarded to the utility service, which then verifies the identity of the message originator (using a digital certificate) and decrypts the request message contents. If the originator is authorized to access Services C, D, and E, the appropriate request messages are sent to these services.
  • B. The Brokered Authentication pattern is applied by extending the firewall functionality with a single sign-on mechanism. Because the firewall already restricts accesses to Service Inventory B, adding authentication logic to the firewall optimizes the performance of the overall security architecture. Service B needs to be authenticated by the authentication broker only once in order to get a security token that can be used to access Services C, D, and E.
    This eliminates the need for Service B to authenticate several times during the same service composition.
  • C. The Service Perimeter Guard pattern is applied together with the Brokered Authentication pattern. A new perimeter service is created to intercept all request messages sent to services inside the private network (inside Service Inventory B), before they reach the firewall. The perimeter service also acts as the authentication broker that authenticates request messages sent to Services C, D, and E by evaluating the accompanying security credentials and issuing a security token to be used by Service B when accessing Services C, D, and E.
  • D. The Service Perimeter Guard pattern is applied together with the Message Screening pattern. A new perimeter service is created specifically for Service Inventory B.
    This service filters all messages before they reach the firewall and further evaluates the IP address of the messages to verify the identity of the message originators. If the originator is successfully authenticated, then the perimeter guard checks the request message for potentially malicious content. If the request message does not contain malicious content, it is sent through the firewall to proceed to Services C, D, and E for further processing.
Reveal Solution  Discussion  0

Correct Answer: C  🗳️

Question #3

Service Consumer A sends a request to Service A (1). Service A replies with an acknowledgement message (2) and then processes the request and sends a request message to Service B (3). This message contains confidential financial data. Service B sends three different request messages together with its security credentials to Services C, D, and E (4, 5, 6). Upon successful authentication, Services C, D, and E store the data from the message in separate databases (7, 8, 9) Services B, C, D, and E belong to Service Inventory A, which further belongs to Organization B.
Service Consumer A and Service A belong to Organization A.

The service contracts of Services A and B both comply with the same XML schema.
However, each organization employs different security technologies for their service architectures. To protect the confidential financial data sent by Service A to Service B, each organization decides to independently apply the Data Confidentiality and the Data Origin Authentication patterns to establish message-layer security for external message exchanges. However, when an encrypted and digitally signed test message is sent by Service A to Service B, Service B was unable to decrypt the message.
Which of the following statements describes a solution that solves this problem?

  • A. The problem with the test message occurred because Service A used incorrect keys to protect the message sent to Service B.
    Service A used its own public key to sign the message and then used Service B's public key to encrypt the message content. To correct the problem, Service A must use WS-SecureConversation to agree on a secret session key to be used to encrypt messages exchanged between Services A and B.
    Because this session key is only known by Services A and B, encrypting the messages with this key also provides authentication of the origin of the data.
  • B. The problem with the test message occurred because Service A needed the private key of Service B to digitally sign the message. An attacker pretending to be Service B likely sent a fake private/public keys pair to Service A.
    Using these fake keys to encrypt and digitally sign the message made the message incompatible for Service B.
    Because the fake private key was also used to sign the hash, it explains the source of the problem.
  • C. Although both of the organizations applied the Data Confidentiality and the Data Origin Authentication patterns, the security technologies used for the Service A and Service B architectures may be incompatible. Because there are several technologies and versions of technologies that can be used to apply these patterns, the organizations need to standardize implementation level details of the relevant security technologies.
  • D. Although both of the organizations successfully applied the Data Confidentiality and the Data Origin Authentication patterns, the order in which the patterns were applied is incorrect. The application of the Data Origin Authentication pattern must always follow the application of the Data Confidentiality pattern to ensure that the message confidentiality from a third party authenticates the origin of the message.
Reveal Solution  Discussion  0

Correct Answer: C  🗳️

Related Exam

Related Posts

What Clients Say About Us

Very good S90.20 dump. Do not hesitate, try it. I just passed my exam.

Joanna Joanna       4 star  

Hi guys, I took my S90.20 test this morning and passed. These S90.20 dumps are still valid, but be aware that some questions are similar. Good luck!

Zora Zora       4 star  

Many S90.20 exam questions are tricky hotspots. But with the help of S90.20 exam materials, I can handle all of them. Thanks!

Ted Ted       4 star  

Passed S90.20 exams with good scores in Italy. Thanks so much!

Cherry Cherry       5 star  

With my constant failures increasing every day and not being able to find anything suitable to study with, I felt hopeless. Fortunately encountered and try S90.20 exam dump, thank you!

Carl Carl       5 star  

I passed the S90.20 test today with a score of 964.

Francis Francis       4 star  

Today I passed S90.20 with 94%

Althea Althea       5 star  

I just want to let you know I passed my S90.20 exam today. My roommate introduced TorrentExam to me and he said your S90.20 study dumps are quite effective.

Xanthe Xanthe       4 star  

S90.20 exam materials are written with high quality, and I not only have learned lots of professional knowledge in the process of training, but also got the certification. I recommend TorrentExam!

Florence Florence       5 star  

With your new updated guide, I passed my S90.20 test today.

Gabrielle Gabrielle       4 star  

I have passed the exam with using TorrentExam S90.20 exam questions.

Afra Afra       4 star  

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

QUALITY AND VALUE

TorrentExam Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.

TESTED AND APPROVED

We are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.

EASY TO PASS

If you prepare for the exams using our TorrentExam testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.

TRY BEFORE BUY

TorrentExam offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.

Our Clients

amazon
centurylink
charter
comcast
bofa
timewarner
verizon
vodafone
xfinity
earthlink
marriot