SOA S90.20 dumps - in .pdf

S90.20 pdf
  • Exam Code: S90.20
  • Exam Name: SOA Security Lab
  • Updated: Oct 04, 2026
  • Q & A: 30 Questions and Answers
  • PDF Price: $49.99

SOA S90.20 Value Pack
(Frequently Bought Together)

S90.20 Online Test Engine

Online Test Engine supports Windows / Mac / Android / iOS, etc., because it is the software based on WEB browser.

  • Exam Code: S90.20
  • Exam Name: SOA Security Lab
  • Updated: Oct 04, 2026
  • Q & A: 30 Questions and Answers
  • PDF Version + PC Test Engine + Online Test Engine
  • Value Pack Total: $99.98  $69.99
  • Save 50%

SOA S90.20 dumps - Testing Engine

S90.20 Testing Engine
  • Exam Code: S90.20
  • Exam Name: SOA Security Lab
  • Updated: Oct 04, 2026
  • Q & A: 30 Questions and Answers
  • Software Price: $49.99
  • Testing Engine

About SOA S90.20 Instant Exam Download

Every S90.20 syllabus topic looks manageable on paper — until the exam rephrases it. Training with ITExamDownload's SOA Security Lab practice questions teaches you the exam's dialect, not just its vocabulary.

SOA S90.20 Exam Overview:

Certification Vendor:Arcitura Education
Exam Name:SOA Security Lab
Exam Number:S90.20
Related Certifications:Certified Microservice Professional
Certified SOA Professional
Exam Format:Design challenges, Lab-based, Diagramming, Written responses, Scenario-driven, Manual evaluation
Passing Score:70% or 700/1000
Available Languages:English
Exam Price:$249 USD
Real Exam Qty:3–5 practical lab tasks
Exam Duration:180–240
Certificate Validity Period:3 years
Recommended Training:Security for Microservices & SOA Course
SOACP Module 19: Advanced SOA Security
Exam Registration:Pearson VUE Arcitura Testing
Arcitura Official Exam Registration
Sample Questions:Instant Download S90.20 Exam
Exam Way:Online proctored via Arcitura digital platform or on-site at authorized workshops
Pre Condition:Recommended: S90.18 Fundamental SOA Security and S90.19 Advanced SOA Security; hands-on experience with SOA/microservices security
Official Syllabus URL:https://www.arcitura.com/soacp-gen-1/exams/exam-s90-20-soa-security-lab/

SOA S90.20 Exam Syllabus Topics:

SectionWeightObjectives
Topic 1: SOA Security Architecture & Patterns25%- Trusted subsystems and security gateways
- Policy-based access control and XACML
- Identity propagation across service chains
- Secure service composition and orchestration
Topic 2: Threat Mitigation & Risk Management25%- Threat modeling and vulnerability assessment
- Countermeasures for injection, DoS, replay attacks
- Security governance and compliance
- Confidentiality, integrity, non-repudiation controls
Topic 3: Secure Service Interactions30%- Message-level security (WS-Security, XML Encryption, XML Signature)
- Security token management (SAML, JWT, OAuth)
- Transport security (TLS/SSL)
- Secure service discovery and registry
Topic 4: Infrastructure & Advanced Security20%- Securing API gateways and service meshes
- Applying advanced SOA security patterns
- Security monitoring and incident response

S90.20 Exam FAQ: SOA Candidates' Top Questions

At its core, the S90.20 exam is SOA's gatekeeper for the Certified SOA Security Specialist / Certified Service Security Specialist certification — a Specialist-level credential. It examines how well you apply the SOA Security Lab objectives to realistic scenarios, which is why hands-on candidates tend to outperform pure memorizers. The credential also links into a wider path covering Certified SOA Professional, Certified Microservice Professional, so it works as both a standalone achievement and a stepping stone. In a market where certificates increasingly signal ability, passing S90.20 is a concrete, verifiable upgrade to your professional profile.

The SOA Security Lab exam draws its questions from 4 domains, starting with Infrastructure & Advanced Security (20%), Threat Mitigation & Risk Management (25%), and SOA Security Architecture & Patterns (25%). Smart candidates read weightings as a resource map: heavy domains get the deepest practice, light domains get efficient review. You'll find the complete domain list in the exam topics section above — let it drive your schedule.

The SOA Security Lab exam fits 3–5 practical lab tasks questions into 180–240. Convert that into a pace before exam day: total minutes divided by question count gives you a per-item budget, and the discipline to flag-and-return when something overruns it. Practicing under a live timer — the ITExamDownload test engines run one on every session — turns that discipline into reflex, so the clock works for you instead of against you.

The SOA Security Lab exam requires 70% or 700/1000 to pass, and SOA charges $249 USD per attempt — full price, every time, including retakes. That pricing structure rewards preparation: run timed self-assessments with ITExamDownload practice questions, and only book your seat once your scores clear the bar consistently across multiple sessions. One well-prepared attempt is dramatically cheaper than two hopeful ones.

Officially, the SOA Security Lab exam uses these formats: Lab-based, Scenario-driven, Design challenges, Written responses, Diagramming, Manual evaluation. Formats shape strategy — long scenario stems reward reading the final question sentence first, while multi-select items punish partial knowledge. The fix is exposure: ITExamDownload's 30 practice questions rehearse you in every listed format until the mechanics are second nature and only the content demands your attention.

SOA currently delivers the S90.20 exam in English. Select whichever language lets you parse questions fastest under time pressure — borderline scores are often decided by reading speed, not knowledge. If English is your choice, daily sessions with ITExamDownload's English S90.20 practice questions build exactly the vocabulary the exam uses.

The credential earned through the SOA Security Lab exam remains valid for 3 years. Note the expiry date the day you pass and start researching recertification options well in advance — planned renewals are routine, last-minute ones are stressful. Because recertification rules belong to SOA and change over time, verify the current policy on the official certification page as your renewal window approaches.

The content is identical — 30 expert-verified questions — so choose by lifestyle:

  • PDF version — printable, expert-prepared, instantly downloadable, readable anywhere. Includes 365 days of free updates; a free demo is available.
  • Desktop Test Engine — Windows software simulating the real exam environment, two practice modes, works offline, installs on unlimited computers.
  • Online Test Engine — opens in any browser on Windows, Mac, Android, or iOS, with test history and performance review. Once loaded, your material stays accessible even when you go offline.

Commuters and travelers usually live in the online engine; desk-bound studiers prefer the desktop version; annotators swear by the PDF.

There is. Many SOA Security Lab candidates are first-time test-takers, so ITExamDownload provides a free PDF demo containing real sample questions and answers — enough to judge the style, depth, and fit for your study habits. There's no single "perfect" study tool for everyone, only the one that suits you; download the demo and decide with evidence. Purchases then include 365 days of free updates, with renewal at 50% off afterward.

Our staff checks for SOA Security Lab changes every day. When the exam evolves, the question bank is updated and the latest version reaches you through your member zone — free for 365 days after payment. We also welcome rational customer suggestions and fold them into revisions. Watch the New Releases section or the ITExamDownload newsletter, re-check 3-4 days before your exam, and if a product ever expires, repurchase it at 50% off to restart the service.

Quality first, customer foremost: our support team answers whenever and wherever you need help — before purchase, during study, or after the exam. On the security side, transactions are protected by McAfee security services, your personal information is never shared with third parties, and you can leave our mailing list anytime. You're buying material and a support relationship, not just a file.

Delivery: your SOA Security Lab practice questions are downloadable instantly and emailed within one minute of payment — if 2 hours pass, check spam and contact support. Installs are unlimited. Refund: the 100% Money Back Guarantee applies if you take the corresponding exam within 60 days of purchase and don't pass — submit a scanned enrollment slip and your official Score Report PDF within 2 days after the exam, and the full refund is processed within 7 days. Not eligible: attempts made within 3 days of purchase, exams never actually taken, free items, and expired orders; candidate and payer names must match. Alternative: exchange for two free exam products of equal value and keep your update service.

Everything Included with Your SOA Security Lab Purchase at ITExamDownload

One purchase covers preparation, delivery, updates, and support. Evaluate the free demo first; when you buy, your S90.20 material is emailed within one minute of payment (contact support if 2 hours pass) and installs on unlimited computers. McAfee security services protect every transaction, your information is never shared with third parties, and our team answers questions whenever you have them.

  • Update service: 365 days of free updates checked daily by our staff; expired products repurchase at a 50% discount from your member zone.
  • 100% Money Back Guarantee: take the corresponding exam within 60 days of purchase, and if you don't pass, submit your enrollment slip and official Score Report within 2 days after the exam for a full refund processed within 7 days — or exchange for two free products of equal value.

Join the growing number of candidates preparing smarter: download the free S90.20 demo, and let ITExamDownload's 30 practice questions carry your SOA Security Lab preparation from first look to passing score.

SOA Security Lab Sample Questions:

Question #1

Service Consumer A sends a request to Service A (1). Service A replies with an acknowledgement message (2) and then processes the request and sends a request message to Service B (3). This message contains confidential financial data. Service B sends three different request messages together with its security credentials to Services C.
D.
and E (4, 5, 6). Upon successful authentication, Services C.
D. and E store the data from the message in separate databases (7.8, 9). Services B.
C.D, and E belong to Service Inventory A, which further belongs to Organization B.
Service Consumer A and Service A belong to Organization A.

Organization B decides to create a new service inventory (Service Inventory B) for services that handle confidential data. Access to these services is restricted by allocating Service Inventory B its own private network. Access to this private network is further restricted by a dedicated firewall. Services C, D and E are moved into Service Inventory B, and as a result. Service B can no longer directly access these services.
How can this architecture be changed to allow Service B to access Services C, D and E in a manner that does not jeopardize the security of Service Inventory B while also having a minimal impact on the service composition's performance?

  • A. The Brokered Authentication pattern is applied by extending the firewall functionality with a single sign-on mechanism. Because the firewall already restricts accesses to Service Inventory B, adding authentication logic to the firewall optimizes the performance of the overall security architecture. Service B needs to be authenticated by the authentication broker only once in order to get a security token that can be used to access Services C, D, and E.
    This eliminates the need for Service B to authenticate several times during the same service composition.
  • B. The Service Perimeter Guard pattern is applied together with the Message Screening pattern. A new perimeter service is created specifically for Service Inventory B.
    This service filters all messages before they reach the firewall and further evaluates the IP address of the messages to verify the identity of the message originators. If the originator is successfully authenticated, then the perimeter guard checks the request message for potentially malicious content. If the request message does not contain malicious content, it is sent through the firewall to proceed to Services C, D, and E for further processing.
  • C. The Service Perimeter Guard pattern is applied together with the Brokered Authentication pattern. A new perimeter service is created to intercept all request messages sent to services inside the private network (inside Service Inventory B), before they reach the firewall. The perimeter service also acts as the authentication broker that authenticates request messages sent to Services C, D, and E by evaluating the accompanying security credentials and issuing a security token to be used by Service B when accessing Services C, D, and E.
  • D. The Data Confidentiality pattern is applied together with the Direct Authentication pattern. A new utility service is created to validate request messages sent to Service Inventory B.
    Service B must encrypt the message content using the utility service's public key and attach its own digital certificate to the request message. This message is first evaluated by the firewall to filter out requests from disallowed sources and can then be forwarded to the utility service, which then verifies the identity of the message originator (using a digital certificate) and decrypts the request message contents. If the originator is authorized to access Services C, D, and E, the appropriate request messages are sent to these services.
Reveal Solution  Discussion  0

Correct Answer: C  🗳️

Question #2

Service Consumer A submits a request message with security credentials to Service A (1).
The identity store that Service A needs to use in order to authenticate the security credentials can only be accessed via a legacy system that resides in a different service inventory. Therefore, to authenticate Service Consumer A, Service A must first forward the security credentials to the legacy system (2). The legacy system then returns the requested identity to Service A (3). Service A authenticates Service Consumer A against the identity received from the legacy system. If the authentication is successful, Service A retrieves the requested data from Database A (4), and returns the data in a response message sent back to Service Consumer A (5).
Service A belongs to Service Inventory A which further belongs to Security Domain A and the legacy system belongs to Service Inventory B which further belongs to Security Domain
B. (The legacy system is encapsulated by other services within Service Inventory B, which are not shown in the diagram.) These two security domains trust each other.
Communication between Service A and the legacy system is kept confidential using transport-layer security.

No intermediary service agents currently exist between the two service inventories.
However, it has been announced that due to the introduction of new systems, some intermediary service agents may be implemented in the near future. Additionally, the legacy system has been scheduled for retirement and will be replaced by a new identity management system that will provide a new identity store. Because the new identity store will need to serve many different systems, there are concerns that it could become a performance bottleneck. As a result, services (including Service A and other services in Security Domains A and B) will not be allowed to directly access the new identity store.
Which of the following statements describes a solution that can accommodate the requirements of the new identity store, the authentication requirements of Service A, and can further ensure that message exchanges between Security Domains A and B remain confidential after intermediary service agents are introduced?

  • A. Apply the Trusted Subsystem pattern to implement a utility service abstracting the new identity management system. Service A forwards Service Consumer As credentials to the utility service to verify Service Consumer As identity. The utility service authenticates the request originating from Service A.
    After successful authentication, the utility service uses its own credentials to retrieve the requested identity, and then send the identity to Service A, Therefore, effectively reducing the processing need of the identity management system.
    The current transport-layer security can still be used, in order to secure the communication between Service A and the new utility service, as it more efficient than the message-layer security.
  • B. Replicate the identity database used by the new identity management system. Because the Security Domains A and B trust each other, protection of the identity store is guaranteed. Use Service Agents to monitor changes to the identity database used by the new identity management system and to update the replica. This would satisfy the security needs of Service A, would eliminate the need to request services from Service Inventory B, and ensure that current identity information is available for Service A.
    Because Service A would not need to access services across different trust domains, the current transport- layer security is sufficient.
  • C. Apply the Trusted Subsystem pattern by abstracting away the new identity management system using a utility service that authenticates the request from Service A and then uses its own credentials to retrieve the requested identity from the new identity management system. For the utility service to authenticate Service As request, it needs to be provisioned with a new identity database that contains identities for all authorized service consumers of the new utility service. In order to secure the communication between Service A and the new utility service, use message-layer security as it provides security over multiple hops considering the need to secure the message in case an intermediary is introduced in future.
  • D. Apply the Brokered Authentication pattern to establish an authentication broker. Instead of Service A directly authenticating Service Consumer A, Service Consumer A submits a request message with security credentials to the authentication broker, which authenticates Service Consumer A against the new identity store and then issues a SAML token to Service Consumer A that it can use for message exchanges with other services, if necessary. In order to secure cross-service inventory message exchanges, the Data Confidentiality pattern is applied to establish message-layer security.
Reveal Solution  Discussion  0

Correct Answer: D  🗳️

Question #3

Service Consumer A sends a request message to Service A (1), after which Service A sends a request message to Service B (2). Service B forwards the message to have its contents calculated by Service C (3). After receiving the results of the calculations via a response message from Service C (4), Service B then requests additional data by sending a request message to Service D (5). Service D retrieves the necessary data from Database A (6), formats it into an XML document, and sends the response message containing the XML-formatted data to Service B (7). Service B appends this XML document with the calculation results received from Service C, and then records the entire contents of the XML document into Database B (8). Finally, Service B sends a response message to Service A (9) and Service A sends a response message to Service Consumer A (10).
Services A, B and D are agnostic services that belong to Organization A and are also being reused in other service compositions. Service C is a publicly accessible calculation service that resides outside of the organizational boundary. Database A is a shared database used by other systems within Organization A and Database B is dedicated to exclusive access by Service B.

Recently, Service D received request messages containing improperly formatted database retrieval requests. All of these request messages contained data that originated from Service C.
There is a strong suspicion that an attacker from outside of the organization has been attempting to carry out SOL injection attacks. Furthermore, it has been decided that each service that writes data to a database must keep a separate log file that records a timestamp of each database record change. Because of a data privacy disclosure requirement used by Organization A, the service contracts of these services need to indicate that this logging activity may occur.
How can the service composition architecture be improved to avoid SQL injection attacks originating from Service C - and - how can the data privacy disclosure requirement be fulfilled?

  • A. Apply the Data Origin Authentication pattern to authenticate data received from Service C.
    Service C digitally signs any data sent in response messages to Service B.
    Service B can then verify that the data has not been modified during transit and that it originated from Service C.
    Secondly, update the service contracts for Services B and D with an ignorable WS-Policy assertion that communicates the possibility of the logging activity. The service contracts for Services B and D are updated with an optional WS-Policy assertion that provides service consumers with the option of complying to the logging requirements.
  • B. Apply the Service Perimeter Guard pattern together with the Message Screening pattern in order to establish a perimeter service with message screening logic. Position the perimeter service between Service C and Service B.
    The message screening logic rejects or filters out potentially harmful content in messages sent from Service C, prior to being forwarded to Service B.
    Secondly, update the service contracts for Services B and D with an optional WS-Policy assertion that provides service consumers with the option of complying to the logging requirements.
  • C. Apply the Data Origin Authentication pattern to authenticate data received from Service C.
    Service C digitally signs any data sent in response messages to Service B.
    Service B can then verify that the data has not been modified during transit and that it originated from Service C.
    Secondly, update the service contracts for Services B and D with an ignorable WS-Policy assertion that communicates the possibility of the logging activity.
  • D. Apply the Message Screening pattern in order to establish a service agent with message screening logic. Position the service agent between Service C and Service B.
    The service agent's message screening logic can reject or filter out potentially harmful content in messages sent from Service C, before being processed by Service B.
    Secondly, update the service contracts for Services B and D with an ignorable WS-Policy assertion that communicates the possibility of the logging activity.
Reveal Solution  Discussion  0

Correct Answer: D  🗳️

What Clients Say About Us

The soft version of S90.20 study materials are compatible with Windows system.

Lance Lance       4 star  

I get S90.20 PDF, Jeff get C90.01, we both pass the examination casually. Yes, it is very helpful. I find a lot of valid questions. Oh ha best choose! will tell my friends to buy! Thanks again.

Joyce Joyce       5 star  

I wanted to write some words of gratitude about ITExamDownload.

Bertram Bertram       5 star  

I passed S90.20 only because of S90.20 exam dump. They gave me hope and guide at the right time. I trust it. Thank! I made the right decision.

Ian Ian       5 star  

I love you guys! I have successfully passed the S90.20 exam with your excellent exam braindumps. Glad to share with you!

Woodrow Woodrow       4 star  

Last time i was using another exam materials for my preparation and passed, this time i used the S90.20 test engine and passed as well. This is the advantages of using test engine from ITExamDownload, you can pass for sure with 100% success guarantee.

Tony Tony       4.5 star  

Thanks for the great S90.20 study materials.

Valentine Valentine       4 star  

I passed the two exams.

Herman Herman       5 star  

I hate to fail and i am lucky to find this website to pass the S90.20 exam just in one go!

Lydia Lydia       4 star  

I used your S90.20 exams for practice and to identify my weak areas.

Harley Harley       4 star  

If you are worried about your S90.20 certification exam, I suggest that you can use the exam dumps on ITExamDownload. They are truly high-effective!

Elroy Elroy       5 star  

I used your updated S90.20 study materials and passed my exam easily.

Salome Salome       5 star  

Thanks a lot to ITExamDownload. You gave me the best products to pass S90.20 exams. You did changed my life!

Joyce Joyce       4.5 star  

I used and i can say confidently these S90.20 exam dumps are valid. Passed it with ease! Thanks!

Tyler Tyler       4.5 star  

I have cleared this exam.I have got your S90.20

Sally Sally       4.5 star  

The S90.20 exam questions are trully valid, i used only them and was practicing with them at home. I passed with a high score. Perfect!

Barton Barton       4.5 star  

I found the S90.20 practice test is so helpful that you can pass the exam in a short time. I only studied the questions in my spare time and passed the exam with 93% score!

Valerie Valerie       4.5 star  

Come across ITExamDownload and try S90.20 the material,now the result is success, thank you!
Passed my S90.20 exam with a high score.

Scott Scott       5 star  

Something unbelieveable! The dumps is totally same with the S90.20 real test. Pass exam easily

Marvin Marvin       5 star  

Best pdf practise questions at ITExamDownload for S90.20 certification exam. Studied from other dumps but I wasn't satisfied with the preparation. I studied with the material at ITExamDownload and got 96% marks. Thank you so much.

Murphy Murphy       5 star  

The S90.20 dump does an excellent job of covering all required objectives. I used the dump only and get a good score! All my thinks!

Stan Stan       4 star  

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Security & Privacy

We respect customer privacy. We use McAfee's security service to provide you with utmost security for your personal information & peace of mind.

365 Days Free Updates

Free update is available within 365 days after your purchase. After 365 days, you will get 50% discounts for updating.

Money Back Guarantee

Full refund if you fail the corresponding exam in 60 days after purchasing. And Free get any another product.

Instant Download

After Payment, our system will send you the products you purchase in mailbox in a minute after payment. If not received within 2 hours, please contact us.

Our Clients