S90.02 SOA Technology Concepts (S90-02A) Practice Questions
Prepare for S90.02 with more than an answer.
- Exam fee
- $150 USD
- Level
- Professional
- Valid for
- Lifetime
Domains covered on the exam 6
- Service Implementation Mediums and Fundamentals15%
- Message Exchange Patterns and Service Activities15%
- XML, JSON and Data Format Technologies20%
- REST Services and HTTP Concepts20%
- SOAP, WSDL and WS-* Technologies15%
- Cloud Computing Concepts15%
- 1
Case Study:
Company Background: GlobalRetail Inc. is a large e-commerce company that built its platform a decade ago using a monolithic architecture with a central relational database. The platform is becoming difficult to scale and maintain. New feature deployments are slow and risky. To improve agility and scalability, the leadership team has approved a migration to a microservices architecture hosted in a public cloud.
Current Situation: The first project is to extract the 'Product Catalog' functionality into a new, independent microservice. This service will be consumed by multiple internal clients (e.g., the website front-end, mobile app backend, and inventory system). The existing system exposes this data via an internal, proprietary RPC mechanism.
Requirements:
- The new Product Catalog API must be designed according to modern, industry-standard best practices for web APIs.
- The API must allow clients to discover available actions and navigate between related resources without hardcoding URIs.
- The API contract must be easily understandable by both human developers and automated tools.
- The design must be decoupled from any specific client-side technology.
Problem: Which architectural approach best fulfills all the stated requirements for the new Product Catalog microservice API?
Show answer details
Correct answer: C
This approach directly addresses all requirements. A RESTful API is the modern industry standard (Req 1). HATEOAS specifically fulfills the need for discoverability and navigation without hardcoded URIs (Req 2). Using a standard like JSON Hyper-Application Language (HAL) or Siren makes the API self-descriptive and understandable (Req 3). The uniform interface of REST ensures decoupling from client technology (Req 4). A simple JSON API without hypermedia would violate requirement 2, and SOAP is generally considered a heavier, less agile approach for this type of web API.
- 2
The principle of 'late binding' in service-oriented architecture refers to the practice of deferring the binding of a service consumer to a specific service provider instance until runtime. Which technology is a classic example of a mechanism designed to facilitate late binding?
Show answer details
Correct answer: B
A service registry is the canonical mechanism for achieving late binding. Service providers publish their availability and endpoint information to the registry. At runtime, service consumers query the registry to discover a suitable, available service provider and then bind to it. This decouples the consumer from a hardcoded provider address, allowing for greater flexibility and resilience.
- 3
A developer is troubleshooting a REST API call. The client sends a
PUTrequest to/users/123with a full JSON representation of the user. The expectation is that the user resource on the server will be completely replaced with the new representation. However, they observe that if they make the samePUTrequest multiple times, the user's 'last-updated' timestamp changes with each call. Which fundamental property of the PUT method is being violated by the server's implementation?Show answer details
Correct answer: C
Idempotency means that making the same request multiple times has the same effect as making it once. For a
PUTrequest, this means the state of the resource should be identical after the first call and any subsequent identical calls. By changing the 'last-updated' timestamp on every call, the server is producing a different resource state each time, thus violating idempotency. This is a common implementation error where server-side metadata is updated regardless of whether the actual resource data changed. - 4
Case Study:
Company Background: StartUpHealth is a new company providing a multi-tenant SaaS platform for healthcare clinics. Each clinic (tenant) has its own isolated data, but they all run on a shared cloud infrastructure to keep costs low. The platform's popularity is growing rapidly and unpredictably.
Current Architecture: The application runs on a set of virtual machines in a public cloud. The database is a single, large relational database instance with a
tenant_idcolumn in every table to segregate data. During peak usage hours (e.g., Monday mornings), the entire platform slows down for all tenants because a few large tenants are running resource-intensive reports, causing database contention.Requirements:
- Ensure 'noisy neighbor' problems are eliminated, where one tenant's activity impacts others.
- The architecture must be resilient; a failure impacting one tenant should not affect others.
- The solution must scale cost-effectively to accommodate a growing number of tenants of varying sizes.
Problem: Which cloud architecture and data management strategy would best address StartUpHealth's requirements for tenant isolation, resiliency, and scalability?
Show answer details
Correct answer: C
This approach provides the best balance of isolation and cost-effectiveness. Provisioning a separate database for each tenant (e.g., using a managed database service) completely isolates their data and performance, eliminating the 'noisy neighbor' problem (Req 1 & 2). Using containers (like Docker/Kubernetes) for the application layer allows for efficient, shared compute resources while still isolating application processes. This model scales effectively as new tenants can be provisioned with their own database without impacting others, and resources can be sized according to tenant needs (Req 3).
- 5
An IoT system is designed to receive status updates from thousands of remote sensors. Each sensor sends a small packet of data every minute. The backend system that collects this data is only responsible for receiving and logging the data; it does not send any reply or acknowledgment back to the sensor. This communication style is an example of which fundamental message exchange pattern (MEP)?
sequenceDiagram participant Sensor participant Collector loop Every Minute Sensor->>Collector: Send Status Update endShow answer details
Correct answer: B
This scenario describes the One-Way message exchange pattern. In this pattern, a message is sent from a source to a destination with no expectation of a reply. It is often used for notifications, logging, or 'fire-and-forget' scenarios, which is exactly how the IoT sensors are communicating with the collector service.
- 6
A financial services firm is architecting a new trade processing platform. A key non-functional requirement is that once a trade message is accepted by the system, its successful processing must be guaranteed, even if downstream services are temporarily unavailable. The system should be able to retry processing the message for up to 24 hours. Which WS-* specification is specifically designed to address this requirement?
Show answer details
Correct answer: C
WS-ReliableMessaging is a protocol that enables messages to be delivered reliably between distributed applications in the presence of software component, system, or network failures. It defines mechanisms for guaranteed delivery, duplicate elimination, and message ordering. This directly addresses the requirement for guaranteed processing despite temporary service unavailability. WS-AtomicTransaction deals with distributed transactions, WS-Security handles message-level security, and WS-Policy describes service capabilities and constraints.
- 7
An architect is designing a RESTful API for a document management system. The API needs a mechanism for clients to upload large files. To ensure data integrity, the server must be able to reject an upload if the file's content has been altered in transit. Which combination of HTTP headers should the client and server use to facilitate this content integrity check?
Show answer details
Correct answer: D
The
Content-MD5header (though older) and the more modernDigestheader are specifically designed for end-to-end message integrity checks. The client computes a hash (e.g., MD5 or SHA-256) of the request body and sends it in one of these headers. The server then computes its own hash of the received body and compares it to the value in the header. If they don't match, it indicates data corruption, and the server can reject the request, typically with a400 Bad Requeststatus. ETag is for caching, and the others relate to content negotiation and size. - 8
True or False: In a public cloud environment following the Platform as a Service (PaaS) model, the cloud consumer is responsible for patching the operating system of the application servers.
Show answer details
Correct answer: B
This statement is false. In the PaaS model, the cloud provider manages the underlying infrastructure, including the physical hardware, networking, and the operating system. The cloud consumer is responsible for deploying and managing their applications and data, but not the OS itself. The provider handles OS patching, updates, and maintenance. This abstraction is a key benefit of PaaS.
- 9
A development team is building a set of services that will be consumed by both internal applications and external partners. To ensure a consistent and enforceable data structure for all messages, they are using XML Schema Definition (XSD). Which of the following XSD elements are used to define a reusable, custom data structure containing multiple elements? (Select TWO).
Show answer details
Correct answer: B, D
The
xs:complexTypeelement is the primary mechanism in XSD for defining custom data structures that can contain other elements, attributes, or a combination of both.The
xs:sequenceelement is a compositor used within anxs:complexTypeto specify that the child elements must appear in the defined order. It is a key part of defining the structure. - 10
During a code review, an architect observes that a junior developer used an HTTP GET request to trigger an action that deletes a user's account. This implementation is a severe violation of REST principles. What is the primary characteristic of the GET method that is being violated in this scenario?
Show answer details
Correct answer: C
The primary violation is of the 'safety' property. Safe HTTP methods, like GET and HEAD, are defined as those that do not alter the state of the resource on the server. They are intended for read-only operations. Using GET to perform a destructive action like deleting an account is incorrect and dangerous, as crawlers, proxies, or pre-fetching mechanisms could inadvertently trigger the action. The correct method for deletion would be HTTP DELETE.
