A SOA certification unlocks career development that stays locked without it. The SOA Advanced SOA Security exam is the key, and the 83 practice questions at ActualPDF are cut to fit it.
SOA S90.19 Exam Overview:
| Certification Vendor: | Arcitura Education |
|---|---|
| Exam Name: | Advanced SOA Security |
| Exam Number: | S90.19 |
| Exam Format: | Scenario-Based, Multiple Choice |
| Certificate Validity Period: | 3 years |
| Exam Duration: | 90 minutes |
| Related Certifications: | S90.18 Fundamental SOA Security Certified SOA Architect Certified SOA Security Specialist S90.20 SOA Security Lab |
| Real Exam Qty: | 40-70 |
| Available Languages: | English |
| Passing Score: | 70% |
| Exam Price: | $250 - $395 USD |
| Recommended Training: | Arcitura Official S90.19 Course |
| Exam Registration: | Pearson VUE Registration Arcitura Official Exam Page |
| Sample Questions: | DOWNLOAD DEMO |
| Exam Way: | Online proctored or onsite at Pearson VUE test centers |
| Pre Condition: | Recommended prior knowledge: S90.01, S90.02, S90.03, S90.08, S90.18 or equivalent experience; no mandatory prerequisite exam |
| Official Syllabus URL: | https://www.arcitura.com/soacp-gen-1/exams/exam-s90-19-advanced-soa-security/ |
SOA S90.19 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Message & Transport Security | 25% | - REST security and HTTP-based protection mechanisms - WS-Security, XML Encryption, XML Signature - Transport-level security (TLS/SSL) |
| Topic 2: Identity, Authentication & Federation | 25% | - Security tokens: SAML, JWT, STS - WS-Trust, WS-Secure Conversation, federation and trust brokering - Identity propagation and delegation |
| Topic 3: Security Policies & Governance | 15% | - Audit, logging, and security monitoring - Security governance and compliance - Design and enforcement of security policies |
| Topic 4: Secure Design & Architecture | 15% | - Gateway and intermediary security - Securing service composition, orchestration, and cloud-based services - SOA security patterns and best practices |
| Topic 5: SOA Security Fundamentals & Threats | 20% | - Advanced SOA security principles and concepts - Threat modeling and risk assessment in SOA environments - Common security vulnerabilities and attack vectors |
SOA S90.19 Exam: What Candidates Want to Know
SOA Advanced SOA Security is an official Arcitura Education certification exam, registered under the code S90.19. Passing it awards the SOA Certified Professional (SOACP) certification, a credential at the Professional / Advanced level. It also connects to Certified SOA Security Specialist, Certified SOA Architect, S90.18 Fundamental SOA Security, S90.20 SOA Security Lab. The exam is demanding by design, and that difficulty is precisely what makes the credential meaningful for career development.
The SOA Advanced SOA Security exam presents 40-70 questions within 90 minutes. That is a brisk pace, and the candidates who handle it best are the ones who rehearsed it. Use the ActualPDF engine for full timed simulations, practice flagging and returning, and arrive on exam day with a pacing strategy already proven.
Passing SOA Advanced SOA Security takes 70%, and official registration costs $250 - $395 USD. Retakes bill the full $250 - $395 USD again, so preparation is the least expensive insurance available. Let your ActualPDF practice scores guide the timing: book when you clear the requirement consistently, not occasionally.
Recommended prior knowledge: S90.01, S90.02, S90.03, S90.08, S90.18 or equivalent experience; no mandatory prerequisite exam
Policies get revised, so confirm the current requirements before you register on the official exam page.
SOA Advanced SOA Security registration is handled through the official channels below.
For scheduling purposes: the exam is delivered Online proctored or onsite at Pearson VUE test centers.
Yes, Arcitura Education recommends the following training for SOA Advanced SOA Security candidates.
Complement any training with the 83 practice questions in the ActualPDF S90.19 package, because repeated application is what turns course knowledge into a passing score.
Yes. ActualPDF offers a free demo of the SOA Advanced SOA Security questions, so you can verify the quality personally before purchasing. Your purchase then includes a one-year service warranty: updates are free for 365 days, and after expiry you can extend the update service at a 50% discount.
Your money is protected by a 100% money-back guarantee with defined conditions. Take the SOA Advanced SOA Security exam within 60 days of purchase; if you fail, you may claim a full refund, provided the exam matches your product. Attempts within 3 days of purchase are ineligible, as are downloaded-but-unused products, free materials, and expired orders; the candidate name must match the payer name. Submit a scanned enrollment slip and the official Score Report PDF within 2 days of the exam, and claims are processed within 7 days. You may instead wait for the update version or change to other exam material: exchange for two other exam products of equal value, free, with your original purchase keeping its update service.
Delivery is instant: files unlock for download at payment and are emailed within one minute. If nothing arrives within 2 hours, check spam and contact customer service, online 7/24 even on official holidays. Installation is unlimited across your computers.
SOA Advanced SOA Security is organized into 5 official domains. The most heavily weighted are Security Policies & Governance (15%), SOA Security Fundamentals & Threats (20%), and Secure Design & Architecture (15%). The full breakdown appears above on this page; study the weightings and your preparation priorities set themselves.
SOA Advanced SOA Security Sample Questions:
Service A contains reporting logic that collects statistical data from different sources in order to produce a report document. One of the sources is a Web service that exists outside of the organizational boundary. Some of Service A's service consumers are encountering slow response times and periods of unavailability when invoking Service A.
While investigating the cause, it has been discovered that some of the messages received from the external Web service contain excessive data and links to files (that are not XML schemas or policies). What can be done to address this issue?
- A. correlate request and response messages across different services
- B. define cardinality in message schemas
- C. use precompiled XPath expressions
- D. avoid downloading XML schemas at runtime
Correct Answer: B,D 🗳️
Service A's logic has been implemented using managed code. An attacker sends an XML bomb to Service A.
As a result, Service A's memory consumption started increasing at an alarming rate and then decreased back to normal. The service was not affected by this attack and quickly recovered. Which of the following attacks were potentially avoided?
- A. Buffer overrun attack
- B. XML parser attack
- C. Denial of service
- D. Insufficient authorization attack
Correct Answer: B,C 🗳️
When considering the ESB as providing intermediary logic, which of the following types of subject confirmation methods relate to its access control issues?
- A. Sender-vouches
- B. Issuer-vouches
- C. Holder-of-key
- D. None of the above.
Correct Answer: A 🗳️
The application of the Data Origin Authentication pattern and the Data Confidentiality pattern do not help mitigate the risk of malicious intermediary attacks.
- A. True
- B. False
Correct Answer: B 🗳️
The service contract for Service A uses an XML schema that does not specify the maximum length for the CustomerAddress XML element. A service consumer sends a message that contains a very long string of characters inside the CustomerAddress XML element. This can be an indication of what types of attacks?
- A. Buffer overrun attack
- B. XML parser attack
- C. XPath injection attack
- D. Insufficient authorization attack
Correct Answer: A,B 🗳️
PDF Version Demo


