CAS-002 · Question #43
The database team has suggested deploying a SOA based system across the enterprise. The Chief Information Officer (CIO) has decided to consult the security manager about the risk implications for…
The correct answer is B. Users and services are distributed, often times over the Internet E. SOA abstracts legacy systems as web services, which are often exposed to outside threats. SOA (Service-Oriented Architecture) exposes functionality as interoperable web services (e.g., SOAP or REST), often over the Internet, which introduces two key security concerns: (B) Services and users are distributed across the enterprise and often over the Internet, expanding…
Question
The database team has suggested deploying a SOA based system across the enterprise. The Chief Information Officer (CIO) has decided to consult the security manager about the risk implications for adopting this architecture. Which of the following are concerns that the security manager should present to the CIO concerning the SOA system? (Select TWO).
Options
- AUsers and services are centralized and only available within the enterprise.
- BUsers and services are distributed, often times over the Internet
- CSOA centrally manages legacy systems, and opens the internal network to vulnerabilities.
- DSOA abstracts legacy systems as a virtual device and is susceptible to VMEscape.
- ESOA abstracts legacy systems as web services, which are often exposed to outside threats.
How the community answered
(31 responses)- A16% (5)
- B71% (22)
- C10% (3)
- D3% (1)
Explanation
SOA (Service-Oriented Architecture) exposes functionality as interoperable web services (e.g., SOAP or REST), often over the Internet, which introduces two key security concerns: (B) Services and users are distributed across the enterprise and often over the Internet, expanding the attack surface far beyond the internal network perimeter. (E) Legacy systems are abstracted and exposed as web services, making them accessible to outside threats they were never originally designed to withstand. Option A is incorrect because SOA is inherently distributed, not centralized. Option C incorrectly frames SOA as centralizing legacy systems. Option D confuses SOA with virtualization - VMEscape is a hypervisor vulnerability, completely unrelated to SOA architecture.
Topics
Community Discussion
No community discussion yet for this question.