2026년 SOA Security Lab 시험을 준비할 시간이 부족하신가요? ExamPassdump의 S90.20 연습문제는 최신 출제 경향을 반영한 30문항으로 구성되어 있어 짧은 시간에 핵심 내용만 집중적으로 학습하실 수 있습니다.
SOA S90.20 시험 개요:
| 인증 벤더: | Arcitura Education |
|---|---|
| 시험명: | SOA 보안 실습 |
| 시험 번호: | S90.20 |
| 시험 시간: | 180–240 |
| 자격증 유효 기간: | 3년 |
| 실제 시험 문항 수: | 3–5개의 실무 기반 실습 과제 |
| 지원 언어: | 영어 |
| 합격 점수: | 70% 또는 700/1000점 |
| 관련 자격증: | 공인 SOA 전문가 공인 마이크로서비스 전문가 |
| 시험 형식: | 다이어그램 작성, 시나리오 중심, 실습 기반, 설계 과제, 수동 평가, 서술형 답변 |
| 응시료: | 249달러(USD) |
| 권장 교육: | SOACP 제19과정: 고급 SOA 보안 마이크로서비스 및 SOA 보안 과정 |
| 시험 등록: | Pearson VUE Arcitura 시험 센터 Arcitura 공식 시험 등록 |
| 샘플 문제: | SOA S90.20 샘플 문제 |
| 응시 방법: | Arcitura 디지털 플랫폼을 통한 온라인 감독 방식 또는 공인 교육 과정 현장에서 응시 |
| 전제 조건: | 권장 사항: S90.18 기초 SOA 보안 및 S90.19 고급 SOA 보안 과정 이수, SOA/마이크로서비스 보안 관련 실무 경험 보유 |
| 공식 요강 URL: | https://www.arcitura.com/soacp-gen-1/exams/exam-s90-20-soa-security-lab/ |
SOA S90.20 시험 요강 주제:
| 섹션 | 비중 | 목표 |
|---|---|---|
| SOA 보안 아키텍처 및 패턴 | 25% | - 신뢰 가능한 하위 시스템 및 보안 게이트웨이 - 서비스 체인 전반에서의 신원 전파 - 안전한 서비스 구성 및 오케스트레이션 - 정책 기반 접근 제어 및 XACML |
| 안전한 서비스 상호작용 | 30% | - 메시지 수준 보안(WS-Security, XML Encryption, XML Signature) - 보안 토큰 관리(SAML, JWT, OAuth) - 전송 계층 보안(TLS/SSL) - 안전한 서비스 검색 및 레지스트리 |
| 인프라 및 고급 보안 | 20% | - 고급 SOA 보안 패턴 적용 - 보안 모니터링 및 사고 대응 - API 게이트웨이 및 서비스 메시 보안 강화 |
| 위협 완화 및 리스크 관리 | 25% | - 보안 거버넌스 및 규정 준수 - 기밀성, 무결성, 부인 방지 제어 방안 - 삽입 공격, DoS 공격, 재전송 공격에 대한 대응책 - 위협 모델링 및 취약점 평가 |
S90.20 시험 자주 묻는 질문 총정리
S90.20 시험은 Arcitura Education이 시행하는 공인 인증시험으로, 통과하시면 공인 SOA 보안 전문가 / 공인 서비스 보안 전문가 인증을 취득하실 수 있습니다. 이 인증은 전문가 등급에 해당합니다. 공인 SOA 전문가,공인 마이크로서비스 전문가 등의 관련 인증과도 연계되어 있어 커리어 확장에 도움이 됩니다. ExamPassdump에서는 해당 시험 대비용 30문항의 연습문제를 제공하고 있습니다.
S90.20 시험은 3–5개의 실무 기반 실습 과제문항이 출제되며 시험 시간은 180–240입니다. 문항당 배정 시간을 미리 계산해 두시면 풀이 속도를 조절하기 쉬우며, 어려운 문제에 시간을 과도하게 쓰지 않고 표시 후 넘어가는 전략이 유효합니다. ExamPassdump의 모의고사로 실제 시험과 동일하게 제한 시간을 설정하고 연습하시면 시간 압박에 대한 대응력을 높이실 수 있습니다.
S90.20 시험의 합격 기준 점수는 70% 또는 700/1000점이며 공식 응시료는 249달러(USD)입니다. 불합격하시면 재응시 시 응시료를 다시 전액 납부하셔야 하므로 한 번의 응시로 충분히 대비하시는 것이 경제적입니다. 응시 전에 ExamPassdump의 30문항 모의고사로 실력을 점검하시고, 안정적으로 합격 기준을 넘는 점수가 나올 때 시험에 응시하시기를 권장합니다.
S90.20 시험의 응시 조건은 다음과 같습니다. 권장 사항: S90.18 기초 SOA 보안 및 S90.19 고급 SOA 보안 과정 이수, SOA/마이크로서비스 보안 관련 실무 경험 보유 응시 조건은 변경될 수 있으므로 최신 정보는 공식 안내 페이지에서 반드시 확인하시기 바랍니다.
S90.20 시험은 아래 공식 접수 채널에서 신청하실 수 있습니다.
시험 방식은 Arcitura 디지털 플랫폼을 통한 온라인 감독 방식 또는 공인 교육 과정 현장에서 응시입니다. 접수 전에 시험 방식과 일정을 함께 확인하시기 바랍니다.
Arcitura Education에서는 S90.20 시험 대비용으로 다음과 같은 공식 교육 과정을 권장하고 있습니다.
공식 교육으로 이론을 학습하신 후 ExamPassdump의 30문항 연습문제로 실전 감각을 보완하시면 학습 효율이 더욱 높아집니다.
가능합니다. ExamPassdump에서는 S90.20 무료 샘플 문제를 제공하고 있어 구매 전에 문제 품질과 구성을 직접 확인하실 수 있습니다. 또한 제품 구매 후에는 365일 동안 무료 업데이트가 제공되며, 업데이트 기간이 만료된 이후에는 50% 할인된 가격으로 갱신하실 수 있습니다.
ExamPassdump은 환불 보장 정책을 운영하고 있습니다. 구매 후 60일 이내에 S90.20 시험에 응시하여 불합격하신 경우, 응시 등록 확인서 사본과 공식 성적표(Score Report) PDF를 시험일로부터 2일 이내에 제출하시면 전액 환불을 신청하실 수 있으며 접수 후 7일 이내에 처리됩니다. 구매 후 3일 이내 응시, 다운로드 후 미응시, 무료 자료 및 만료된 주문은 적용 대상이 아니며 수험자 명의와 결제자 명의가 일치해야 합니다. 환불 대신 동일한 가치의 다른 시험 자료 2개를 무료로 받고 기존 제품의 업데이트 서비스를 유지하는 방법도 선택하실 수 있습니다. 제품은 결제 즉시 다운로드 가능하며 결제 후 1분 이내에 이메일로도 발송됩니다. 2시간이 지나도 받지 못하신 경우 고객센터로 문의해 주시기 바랍니다. 설치 가능한 컴퓨터 대수에는 제한이 없습니다.
S90.20 시험은 총 4개의 출제 영역으로 구성되어 있습니다. 주요 영역으로는 인프라 및 고급 보안(20%),위협 완화 및 리스크 관리(25%),안전한 서비스 상호작용(30%) 등이 있습니다. 각 영역의 세부 항목과 배점 비율은 위에 정리된 전체 시험 범위에서 확인하시기 바랍니다.
최신 SOA Certification S90.20 무료샘플문제
문제 #1
Service Consumer A sends a request to Service A (1). Service A replies with an acknowledgement message (2) and then processes the request and sends a request message to Service B (3). This message contains confidential financial data. Service B sends three different request messages together with its security credentials to Services C.
D.
and E (4, 5, 6). Upon successful authentication, Services C.
D. and E store the data from the message in separate databases (7.8, 9). Services B.
C.D, and E belong to Service Inventory A, which further belongs to Organization B.
Service Consumer A and Service A belong to Organization A.
Organization B decides to create a new service inventory (Service Inventory B) for services that handle confidential data. Access to these services is restricted by allocating Service Inventory B its own private network. Access to this private network is further restricted by a dedicated firewall. Services C, D and E are moved into Service Inventory B, and as a result. Service B can no longer directly access these services.
How can this architecture be changed to allow Service B to access Services C, D and E in a manner that does not jeopardize the security of Service Inventory B while also having a minimal impact on the service composition's performance?
A. The Service Perimeter Guard pattern is applied together with the Message Screening pattern. A new perimeter service is created specifically for Service Inventory B.
This service filters all messages before they reach the firewall and further evaluates the IP address of the messages to verify the identity of the message originators. If the originator is successfully authenticated, then the perimeter guard checks the request message for potentially malicious content. If the request message does not contain malicious content, it is sent through the firewall to proceed to Services C, D, and E for further processing.
B. The Service Perimeter Guard pattern is applied together with the Brokered Authentication pattern. A new perimeter service is created to intercept all request messages sent to services inside the private network (inside Service Inventory B), before they reach the firewall. The perimeter service also acts as the authentication broker that authenticates request messages sent to Services C, D, and E by evaluating the accompanying security credentials and issuing a security token to be used by Service B when accessing Services C, D, and E.
C. The Brokered Authentication pattern is applied by extending the firewall functionality with a single sign-on mechanism. Because the firewall already restricts accesses to Service Inventory B, adding authentication logic to the firewall optimizes the performance of the overall security architecture. Service B needs to be authenticated by the authentication broker only once in order to get a security token that can be used to access Services C, D, and E.
This eliminates the need for Service B to authenticate several times during the same service composition.
D. The Data Confidentiality pattern is applied together with the Direct Authentication pattern. A new utility service is created to validate request messages sent to Service Inventory B.
Service B must encrypt the message content using the utility service's public key and attach its own digital certificate to the request message. This message is first evaluated by the firewall to filter out requests from disallowed sources and can then be forwarded to the utility service, which then verifies the identity of the message originator (using a digital certificate) and decrypts the request message contents. If the originator is authorized to access Services C, D, and E, the appropriate request messages are sent to these services.
문제 #2
Service Consumer A sends a request message to Service A (1) after which Service A retrieves financial data from Database A (2). Service A then sends a request message with the retrieved data to Service B (3). Service B exchanges messages with Service C (4) and Service D (5), which perform a series of calculations on the data and return the results to Service A.
Service A uses these results to update Database A (7) and finally sends a response message to Service Consumer A (8). Component B has direct, independent access to Database A and is fully trusted by Database A.
Both Component B and Database A reside within Organization A.
Service Consumer A and Services A, B, C, and D are external to the organizational boundary of Organization A.
Service A has recently experienced an increase in the number of requests from Service Consumer A.
However, the owner of Service Consumer A has denied that Service Consumer A actually sent these requests. Upon further investigation it was determined that several of these disclaimed requests resulted in a strange behavior in Database A, including the retrieval of confidential data. The database product used for Database A has no feature that enables authentication of consumers. Furthermore, the external service composition (Services A, B, C, D) must continue to operate at a high level of runtime performance.
How can this architecture be improved to avoid unauthenticated access to Database A while minimizing the performance impact on the external service composition?
A. A utility service is established to encapsulate Database A and to carry out the authentication of all access to the database by Service A and any other service consumers.
To further support this functionality within the utility service, an identity store is introduced.
This identity store is also used by Service A which is upgraded with its own authentication logic to avoid access by malicious service consumers pretending to be legitimate service consumers. In order to avoid redundant authentication by services within the external service composition, Service A creates a signed SAML assertion that contains the service consumer's authentication and authorization information.
B. Service Consumer A generates a pair of private/public keys (Public Key E and Private Key D) and sends the public key to Service A.
Service A can use this key to send confidential messages to Service Consumer A because messages encrypted by the public key of Service Consumer A can only be decrypted by Service A The Data Origin Authentication pattern can be further applied so that Service A can authenticate Service Consumer A by verifying the digital signature on request messages. The Message Screening pattern is applied to a utility service that encapsulates Database A in order to prevent harmful input.
C. Implement a firewall between Service Consumer A and Service A.
All access to Service A is then controlled by the firewall rules. The firewall contains embedded logic that authenticates request messages and then forwards permitted messages to Service A.
Moreover, the firewall can implement the Message Screening pattern so that each incoming message is screened for malicious content. This solution minimizes the security processing performed by Service A in order to maintain the performance requirements of the external service composition.
D. The Brokered Authentication pattern is applied so that each service consumer generates a pair of private/public keys and sends the public key to Service A.
When any service in the external service composition (Services A, B, C, and D) sends a request message to another service, the request message is signed with the private key of the requesting service (the service acting as the service consumer). The service then authenticates the request using the already established public key of the service consumer. If authentication is successful, the service generates a symmetric session key and uses the public key of the service consumer to securely send the session key back to the service consumer. All further communication is protected by symmetric key encryption. Because all service consumers are authenticated, all external access to Database A is secured.
문제 #3
Service A exchanges messages with Service B multiple times during the same runtime service activity. Communication between Services A and B has been secured using transport-layer security. With each service request message sent to Service B (1A. IB), Service A includes an X.509 certificate, signed by an external Certificate Authority (CA).
Service B validates the certificate by retrieving the public key of the CA (2A. 2B) and verifying the digital signature of the X.509 certificate. Service B then performs a certificate revocation check against a separate external CA repository (3A, 3B). No intermediary service agents reside between Service A and Service B.
Service B has recently suffered from poor runtime performance plus it has been the victim of an access-oriented attack. As a result, its security architecture must be changed to fulfill the following new requirements: 1. The performance of security-related processing carried out by Service B when communicating with Service A must be improved. 2. All request messages sent from Service A to Service B must be screened to ensure that they do not contain malicious content.
Which of the following statements describes a solution that fulfills these requirements?
A. Apply the Trusted Subsystem pattern by introducing a new utility service between Service A and Service B.
When Service A sends request messages, the utility service verifies the provided credentials and creates a customized security profile for Service A.
The security profile contains authentication and access control statements that are then inherited by all subsequent request messages issued by Service A.
As a result, performance is improved because Service A does not need to resubmit any additional credentials during subsequent message exchanged as part of the same runtime service activity. Furthermore, the utility service performs message screening logic to filter out malicious content.
B. Eliminate the need to retrieve the public key from the Certificate Authority and to verify the certificate revocation information by extending the service contract of Service B to accept certificates only from pre-registered Certificate Authorities. This form of pre- registration ensures that Service B has the public key of the corresponding Certificate Authority.
C. Apply the Trusted Subsystem pattern to by introducing a new utility service. Because Service B is required to limit the use of external resources. Service A must ensure that no other services can request processing from Service B in order to prevent malicious content from infiltrating messages. This is achieved by creating a dedicated replica of Service B to be used by the utility service only. Upon receiving the request message and the accompanying security credentials from Service A.
the utility service verifies the authentication information and the validity of the X.509 signature. If the authentication information is correct, then the utility service replicates the code of Service B, performs the necessary processing, and returns the response to Service A.
D. Add a service agent to screen messages sent from Service A to Service B.
The service agent can reject any message containing malicious content so that only verified messages are passed through to Service B.
Instead of using X.509 certificates, use WS- SecureConversation sessions. Service A can request a Security Context Token (SCT) from a Security Token Service and use the derived keys from the session key to secure communication with Service B.
Service B retrieves the session key from the Security Token Service.
질문과 대답:
| 문제 #1 정답: B | 문제 #2 정답: A | 문제 #3 정답: D |



917 분의 상품리뷰 


자격증에 매달려 -
SOA S90.20덤프를 찾아헤메었는데 여기서 드디어 찾았네요.
DC받아 구매했는데 가격도 저렴하고 주요하게는 시험패스보장 가능해서 기쁘네요.
ExamPassdump는 믿고 구매하셔도 좋은 곳입니다.