SOA S90.20 Q&A - in .pdf

S90.20 pdf
  • 시험 번호/코드: S90.20
  • 시험 이름: SOA Security Lab
  • 업데이트: 2026-09-03
  • Q & A: 30 문항
  • PDF가격: $49.98

SOA S90.20 패키지
파격적인 가격에 구매하기

S90.20 Online Test Engine

온라인버전은 WEB브라우저를 기초로 한 소프트웨어이기에 Windows / Mac / Android / iOS 등 시스템에서 사용가능합니다.

  • 시험 번호/코드: S90.20
  • 시험 이름: SOA Security Lab
  • 업데이트: 2026-09-03
  • Q & A: 30 문항
  • PDF버전 + PC테스트엔진 + 온라인테스트엔진
  • 패키지가격: $99.96  $69.98
  • Save 50%

SOA S90.20 Q&A - 테스트엔진

S90.20 Testing Engine
  • 시험 번호/코드: S90.20
  • 시험 이름: SOA Security Lab
  • 업데이트: 2026-09-03
  • Q & A: 30 문항
  • 소프트가격: $49.98
  • 소프트버전 데모

SOA S90.20 시험덤프에 관하여

2026년 SOA Security Lab 시험을 준비할 시간이 부족하신가요? ExamPassdump의 S90.20 연습문제는 최신 출제 경향을 반영한 30문항으로 구성되어 있어 짧은 시간에 핵심 내용만 집중적으로 학습하실 수 있습니다.

SOA S90.20 시험 개요:

인증 벤더:Arcitura Education
시험명:SOA 보안 실습
시험 번호:S90.20
시험 시간:180–240
자격증 유효 기간:3년
실제 시험 문항 수:3–5개의 실무 기반 실습 과제
지원 언어:영어
합격 점수:70% 또는 700/1000점
관련 자격증:공인 SOA 전문가
공인 마이크로서비스 전문가
시험 형식:다이어그램 작성, 시나리오 중심, 실습 기반, 설계 과제, 수동 평가, 서술형 답변
응시료:249달러(USD)
권장 교육:SOACP 제19과정: 고급 SOA 보안
마이크로서비스 및 SOA 보안 과정
시험 등록:Pearson VUE Arcitura 시험 센터
Arcitura 공식 시험 등록
샘플 문제:SOA S90.20 샘플 문제
응시 방법:Arcitura 디지털 플랫폼을 통한 온라인 감독 방식 또는 공인 교육 과정 현장에서 응시
전제 조건:권장 사항: S90.18 기초 SOA 보안 및 S90.19 고급 SOA 보안 과정 이수, SOA/마이크로서비스 보안 관련 실무 경험 보유
공식 요강 URL:https://www.arcitura.com/soacp-gen-1/exams/exam-s90-20-soa-security-lab/

SOA S90.20 시험 요강 주제:

섹션비중목표
SOA 보안 아키텍처 및 패턴25%- 신뢰 가능한 하위 시스템 및 보안 게이트웨이
- 서비스 체인 전반에서의 신원 전파
- 안전한 서비스 구성 및 오케스트레이션
- 정책 기반 접근 제어 및 XACML
안전한 서비스 상호작용30%- 메시지 수준 보안(WS-Security, XML Encryption, XML Signature)
- 보안 토큰 관리(SAML, JWT, OAuth)
- 전송 계층 보안(TLS/SSL)
- 안전한 서비스 검색 및 레지스트리
인프라 및 고급 보안20%- 고급 SOA 보안 패턴 적용
- 보안 모니터링 및 사고 대응
- API 게이트웨이 및 서비스 메시 보안 강화
위협 완화 및 리스크 관리25%- 보안 거버넌스 및 규정 준수
- 기밀성, 무결성, 부인 방지 제어 방안
- 삽입 공격, DoS 공격, 재전송 공격에 대한 대응책
- 위협 모델링 및 취약점 평가

S90.20 시험 자주 묻는 질문 총정리

S90.20 시험은 Arcitura Education이 시행하는 공인 인증시험으로, 통과하시면 공인 SOA 보안 전문가 / 공인 서비스 보안 전문가 인증을 취득하실 수 있습니다. 이 인증은 전문가 등급에 해당합니다. 공인 SOA 전문가,공인 마이크로서비스 전문가 등의 관련 인증과도 연계되어 있어 커리어 확장에 도움이 됩니다. ExamPassdump에서는 해당 시험 대비용 30문항의 연습문제를 제공하고 있습니다.

S90.20 시험은 3–5개의 실무 기반 실습 과제문항이 출제되며 시험 시간은 180–240입니다. 문항당 배정 시간을 미리 계산해 두시면 풀이 속도를 조절하기 쉬우며, 어려운 문제에 시간을 과도하게 쓰지 않고 표시 후 넘어가는 전략이 유효합니다. ExamPassdump의 모의고사로 실제 시험과 동일하게 제한 시간을 설정하고 연습하시면 시간 압박에 대한 대응력을 높이실 수 있습니다.

S90.20 시험의 합격 기준 점수는 70% 또는 700/1000점이며 공식 응시료는 249달러(USD)입니다. 불합격하시면 재응시 시 응시료를 다시 전액 납부하셔야 하므로 한 번의 응시로 충분히 대비하시는 것이 경제적입니다. 응시 전에 ExamPassdump의 30문항 모의고사로 실력을 점검하시고, 안정적으로 합격 기준을 넘는 점수가 나올 때 시험에 응시하시기를 권장합니다.

S90.20 시험의 응시 조건은 다음과 같습니다. 권장 사항: S90.18 기초 SOA 보안 및 S90.19 고급 SOA 보안 과정 이수, SOA/마이크로서비스 보안 관련 실무 경험 보유 응시 조건은 변경될 수 있으므로 최신 정보는 공식 안내 페이지에서 반드시 확인하시기 바랍니다.

S90.20 시험은 아래 공식 접수 채널에서 신청하실 수 있습니다.

시험 방식은 Arcitura 디지털 플랫폼을 통한 온라인 감독 방식 또는 공인 교육 과정 현장에서 응시입니다. 접수 전에 시험 방식과 일정을 함께 확인하시기 바랍니다.

Arcitura Education에서는 S90.20 시험 대비용으로 다음과 같은 공식 교육 과정을 권장하고 있습니다.

공식 교육으로 이론을 학습하신 후 ExamPassdump의 30문항 연습문제로 실전 감각을 보완하시면 학습 효율이 더욱 높아집니다.

가능합니다. ExamPassdump에서는 S90.20 무료 샘플 문제를 제공하고 있어 구매 전에 문제 품질과 구성을 직접 확인하실 수 있습니다. 또한 제품 구매 후에는 365일 동안 무료 업데이트가 제공되며, 업데이트 기간이 만료된 이후에는 50% 할인된 가격으로 갱신하실 수 있습니다.

ExamPassdump은 환불 보장 정책을 운영하고 있습니다. 구매 후 60일 이내에 S90.20 시험에 응시하여 불합격하신 경우, 응시 등록 확인서 사본과 공식 성적표(Score Report) PDF를 시험일로부터 2일 이내에 제출하시면 전액 환불을 신청하실 수 있으며 접수 후 7일 이내에 처리됩니다. 구매 후 3일 이내 응시, 다운로드 후 미응시, 무료 자료 및 만료된 주문은 적용 대상이 아니며 수험자 명의와 결제자 명의가 일치해야 합니다. 환불 대신 동일한 가치의 다른 시험 자료 2개를 무료로 받고 기존 제품의 업데이트 서비스를 유지하는 방법도 선택하실 수 있습니다. 제품은 결제 즉시 다운로드 가능하며 결제 후 1분 이내에 이메일로도 발송됩니다. 2시간이 지나도 받지 못하신 경우 고객센터로 문의해 주시기 바랍니다. 설치 가능한 컴퓨터 대수에는 제한이 없습니다.

S90.20 시험은 총 4개의 출제 영역으로 구성되어 있습니다. 주요 영역으로는 인프라 및 고급 보안(20%),위협 완화 및 리스크 관리(25%),안전한 서비스 상호작용(30%) 등이 있습니다. 각 영역의 세부 항목과 배점 비율은 위에 정리된 전체 시험 범위에서 확인하시기 바랍니다.

최신 SOA Certification S90.20 무료샘플문제

문제 #1

Service Consumer A sends a request to Service A (1). Service A replies with an acknowledgement message (2) and then processes the request and sends a request message to Service B (3). This message contains confidential financial data. Service B sends three different request messages together with its security credentials to Services C.
D.
and E (4, 5, 6). Upon successful authentication, Services C.
D. and E store the data from the message in separate databases (7.8, 9). Services B.
C.D, and E belong to Service Inventory A, which further belongs to Organization B.
Service Consumer A and Service A belong to Organization A.

Organization B decides to create a new service inventory (Service Inventory B) for services that handle confidential data. Access to these services is restricted by allocating Service Inventory B its own private network. Access to this private network is further restricted by a dedicated firewall. Services C, D and E are moved into Service Inventory B, and as a result. Service B can no longer directly access these services.
How can this architecture be changed to allow Service B to access Services C, D and E in a manner that does not jeopardize the security of Service Inventory B while also having a minimal impact on the service composition's performance?

A. The Service Perimeter Guard pattern is applied together with the Message Screening pattern. A new perimeter service is created specifically for Service Inventory B.
This service filters all messages before they reach the firewall and further evaluates the IP address of the messages to verify the identity of the message originators. If the originator is successfully authenticated, then the perimeter guard checks the request message for potentially malicious content. If the request message does not contain malicious content, it is sent through the firewall to proceed to Services C, D, and E for further processing.
B. The Service Perimeter Guard pattern is applied together with the Brokered Authentication pattern. A new perimeter service is created to intercept all request messages sent to services inside the private network (inside Service Inventory B), before they reach the firewall. The perimeter service also acts as the authentication broker that authenticates request messages sent to Services C, D, and E by evaluating the accompanying security credentials and issuing a security token to be used by Service B when accessing Services C, D, and E.
C. The Brokered Authentication pattern is applied by extending the firewall functionality with a single sign-on mechanism. Because the firewall already restricts accesses to Service Inventory B, adding authentication logic to the firewall optimizes the performance of the overall security architecture. Service B needs to be authenticated by the authentication broker only once in order to get a security token that can be used to access Services C, D, and E.
This eliminates the need for Service B to authenticate several times during the same service composition.
D. The Data Confidentiality pattern is applied together with the Direct Authentication pattern. A new utility service is created to validate request messages sent to Service Inventory B.
Service B must encrypt the message content using the utility service's public key and attach its own digital certificate to the request message. This message is first evaluated by the firewall to filter out requests from disallowed sources and can then be forwarded to the utility service, which then verifies the identity of the message originator (using a digital certificate) and decrypts the request message contents. If the originator is authorized to access Services C, D, and E, the appropriate request messages are sent to these services.


문제 #2

Service Consumer A sends a request message to Service A (1) after which Service A retrieves financial data from Database A (2). Service A then sends a request message with the retrieved data to Service B (3). Service B exchanges messages with Service C (4) and Service D (5), which perform a series of calculations on the data and return the results to Service A.
Service A uses these results to update Database A (7) and finally sends a response message to Service Consumer A (8). Component B has direct, independent access to Database A and is fully trusted by Database A.
Both Component B and Database A reside within Organization A.
Service Consumer A and Services A, B, C, and D are external to the organizational boundary of Organization A.

Service A has recently experienced an increase in the number of requests from Service Consumer A.
However, the owner of Service Consumer A has denied that Service Consumer A actually sent these requests. Upon further investigation it was determined that several of these disclaimed requests resulted in a strange behavior in Database A, including the retrieval of confidential data. The database product used for Database A has no feature that enables authentication of consumers. Furthermore, the external service composition (Services A, B, C, D) must continue to operate at a high level of runtime performance.
How can this architecture be improved to avoid unauthenticated access to Database A while minimizing the performance impact on the external service composition?

A. A utility service is established to encapsulate Database A and to carry out the authentication of all access to the database by Service A and any other service consumers.
To further support this functionality within the utility service, an identity store is introduced.
This identity store is also used by Service A which is upgraded with its own authentication logic to avoid access by malicious service consumers pretending to be legitimate service consumers. In order to avoid redundant authentication by services within the external service composition, Service A creates a signed SAML assertion that contains the service consumer's authentication and authorization information.
B. Service Consumer A generates a pair of private/public keys (Public Key E and Private Key D) and sends the public key to Service A.
Service A can use this key to send confidential messages to Service Consumer A because messages encrypted by the public key of Service Consumer A can only be decrypted by Service A The Data Origin Authentication pattern can be further applied so that Service A can authenticate Service Consumer A by verifying the digital signature on request messages. The Message Screening pattern is applied to a utility service that encapsulates Database A in order to prevent harmful input.
C. Implement a firewall between Service Consumer A and Service A.
All access to Service A is then controlled by the firewall rules. The firewall contains embedded logic that authenticates request messages and then forwards permitted messages to Service A.
Moreover, the firewall can implement the Message Screening pattern so that each incoming message is screened for malicious content. This solution minimizes the security processing performed by Service A in order to maintain the performance requirements of the external service composition.
D. The Brokered Authentication pattern is applied so that each service consumer generates a pair of private/public keys and sends the public key to Service A.
When any service in the external service composition (Services A, B, C, and D) sends a request message to another service, the request message is signed with the private key of the requesting service (the service acting as the service consumer). The service then authenticates the request using the already established public key of the service consumer. If authentication is successful, the service generates a symmetric session key and uses the public key of the service consumer to securely send the session key back to the service consumer. All further communication is protected by symmetric key encryption. Because all service consumers are authenticated, all external access to Database A is secured.


문제 #3

Service A exchanges messages with Service B multiple times during the same runtime service activity. Communication between Services A and B has been secured using transport-layer security. With each service request message sent to Service B (1A. IB), Service A includes an X.509 certificate, signed by an external Certificate Authority (CA).
Service B validates the certificate by retrieving the public key of the CA (2A. 2B) and verifying the digital signature of the X.509 certificate. Service B then performs a certificate revocation check against a separate external CA repository (3A, 3B). No intermediary service agents reside between Service A and Service B.

Service B has recently suffered from poor runtime performance plus it has been the victim of an access-oriented attack. As a result, its security architecture must be changed to fulfill the following new requirements: 1. The performance of security-related processing carried out by Service B when communicating with Service A must be improved. 2. All request messages sent from Service A to Service B must be screened to ensure that they do not contain malicious content.
Which of the following statements describes a solution that fulfills these requirements?

A. Apply the Trusted Subsystem pattern by introducing a new utility service between Service A and Service B.
When Service A sends request messages, the utility service verifies the provided credentials and creates a customized security profile for Service A.
The security profile contains authentication and access control statements that are then inherited by all subsequent request messages issued by Service A.
As a result, performance is improved because Service A does not need to resubmit any additional credentials during subsequent message exchanged as part of the same runtime service activity. Furthermore, the utility service performs message screening logic to filter out malicious content.
B. Eliminate the need to retrieve the public key from the Certificate Authority and to verify the certificate revocation information by extending the service contract of Service B to accept certificates only from pre-registered Certificate Authorities. This form of pre- registration ensures that Service B has the public key of the corresponding Certificate Authority.
C. Apply the Trusted Subsystem pattern to by introducing a new utility service. Because Service B is required to limit the use of external resources. Service A must ensure that no other services can request processing from Service B in order to prevent malicious content from infiltrating messages. This is achieved by creating a dedicated replica of Service B to be used by the utility service only. Upon receiving the request message and the accompanying security credentials from Service A.
the utility service verifies the authentication information and the validity of the X.509 signature. If the authentication information is correct, then the utility service replicates the code of Service B, performs the necessary processing, and returns the response to Service A.
D. Add a service agent to screen messages sent from Service A to Service B.
The service agent can reject any message containing malicious content so that only verified messages are passed through to Service B.
Instead of using X.509 certificates, use WS- SecureConversation sessions. Service A can request a Security Context Token (SCT) from a Security Token Service and use the derived keys from the session key to secure communication with Service B.
Service B retrieves the session key from the Security Token Service.


질문과 대답:

문제 #1
정답: B
문제 #2
정답: A
문제 #3
정답: D

917 분의 상품리뷰 상품리뷰 (* 일부 내용이 비슷한 리뷰와 오래된 리뷰는 숨겨졌습니다.)

자격증에 매달려 - 

SOA S90.20덤프를 찾아헤메었는데 여기서 드디어 찾았네요.
DC받아 구매했는데 가격도 저렴하고 주요하게는 시험패스보장 가능해서 기쁘네요.
ExamPassdump는 믿고 구매하셔도 좋은 곳입니다.

invite - 

ExamPassdump 자료가 정말 정확하니 좋더라구요.
SOA S90.20덤프가 아직 유효하니 모두 합격하세요.^^

날아라 연봉 - 

ExamPassdump 덤프도움을 많이 받았습니다.
S90.20덤프문제 그대로 출제되어 시험패스는 별 어려움이 없다고 생각되네요.

bongo - 

S90.20덤프만 달달 외우면 시험 합격가능해요.
ExamPassdump덤프가 있는 자격증따기는 말그대로 정말 쉬운거 같아요.
좋아해야할지 슬퍼해야할지는 ……

구름 - 

1주일전만해도 S90.20시험을 어떻게 준비해야 하는지 잘 몰랐었는데
ExamPassdump덤프를 알게 되고 공부하며 모르는것들을 하나씩 알아가면 준비했습니다.
덤프제공해주신 담당자분께 정말 감사드립니다.

블링블링 - 

학생이어서 시험비가 어마어마하여 덤프선택에 많은 고민이 있었는데 아무래도 시험봐야하는데 ExamPassdump덤프를
빌려쓰는 셈치고 구매결정을 내렸습니다. 어차피 시험은 봐야하는것이고 덤프가 있는편이 더 좋은것이니까.
시험탈락하면 덤프비용환불서비스도 있고해서...다행이도 환불까지 오지 않고 S90.20시험패스했네요.
그냥 감사할 마음뿐입니다.

패스가 좋다 - 

인터넷에 떠돌아 다니는 덤프도 있지만 그래도 ExamPassdump유료 덤프로 시험준비했어요.
덤프만 달달 외우면 당연히 붙을수 있는 시험일지라도 시험비가 너무 비싸서 신중해집니다.
가장 최신일자 덤프를 보내주기에 굳게 믿고 S90.20 덤프만 공부하고 합격했어요.

키를 찾아야해 - 

SOA S90.20 시험준비는 2주전부터 했는데 회사가 너무 바빠서 야근도 많이 하다보니
실제로 덤프공부한 시간은 3일정도였던것 같습니다. 시험전날은 밤세면서 외웠습니다.
결과가 pass여서 참 다행이라고 생각합니다.

복뎅이 - 

여러 사이트를 알아보다가 ExamPassdump에서 구매했는데 업데이트가 다른 사이트보다 좀 빠른거 같습니다.
SOA S90.20 가장 최신버전으로 시험패스하고 자격증을 기다리고 있습니다.
믿고 구매하셔도 되는 좋은 자료입니다.

둘리둘리 - 

IT 분야에 취업하다보니 자격증 취득이 필수네요.
S90.20 시험을 봐야 해서 ExamPassdump에서 덤프를 구입했는데 2문제정도는
덤프에 없는 문제였고 다른 문제는 거의 적중해서 한방에 패스가능했습니다. 감사합니다.

매운 짬뽕 - 

인터넷에 떠돌아 다니는 덤프도 있지만 그래도 ExamPassdump유료 덤프로 시험준비했어요.
덤프만 달달 외우면 당연히 붙을수 있는 시험일지라도 시험비가 너무 비싸서 신중해집니다.
가장 최신일자 덤프를 보내주기에 굳게 믿고 S90.20 덤프만 공부하고 합격했어요.

브이패스 - 

S90.20시험날짜 잡히니 긴장이 되어서 후기도 많이 찾아보고 덤프도 열심히 공부하고 했습니다.
ExamPassdump최신버전덤프 잘 외우시면 수월하게 합격할수 있을거 같아요.
98%정도 덤프와 일치하게 나왔구요. 다들 파이팅요!

navyya - 

ExamPassdump에서 덤프결제하니 바로 다운로드 링크를 보내주셔서
덤프발송시간이 참 빠르구나 했는데 적중율도 또한 좋아 시험을 수월하게 합격했습니다.
조금만 신중히 공부하면 SOA자격증을 어려움 없이 취득할듯하니 여러분들도 자격증 많이 취득하세요.

해물찜 - 

영어가 약해서 부담스러웠는데 영어로 되어있기는 해도 기본적인 용어는 익숙하니까 덤프외우기가
생각보다 쉬웠네요.^^ 보고 또 보고 해서 크게 어려움없이 S90.20시험패스가능했어요.^^

구매후기

고객님의 이메일 주소는 공개되지 않습니다 *

자격증의 중요성:

ExamPassdump 경쟁율이 심한 IT시대에 인증시험을 패스함으로 IT업계 관련 직종에 종사하고자 하는 분들에게는 아주 큰 가산점이 될수 있고 자신만의 위치를 보장할수 있으며 더욱이는 한층 업된 삶을 누릴수 있을수도 있습니다.

ExamPassdump 제품의 가치:

ExamPassdump에는 IT인증시험의 최신 학습가이드가 있습니다. ExamPassdump의 IT전문가들이 자신만의 경험과 끊임없는 노력으로 최고의 학습자료를 작성해 여러분들이 시험에서 패스하도록 도와드립니다.

무료샘플 받아보기:

관심있는 인증시험과목 덤프의 무료샘플을 원하신다면 덤프구매사이트의 PDF Version Demo 버튼을 클릭하고 메일주소를 입력하시면 바로 다운받아 덤프의 일부분 문제를 체험해 보실수 있습니다.

완벽한 서비스 제공:

ExamPassdump KoreaDumps는 한국어로 온라인상담과 메일상담을 받습니다. 덤프구매후 일년동안 무료 업데이트 서비스를 제공해드리며 구매일로 부터 60일내에 시험에서 떨어지는 경우 덤프비용 전액을 환불해드려 고객님의 부담을 덜어드립니다.

고객님