S90.09 SOA Design & Architecture Lab (S90-09A) Practice Questions
Prepare for S90.09 with more than an answer.
- Exam fee
- $399 USD
- Level
- Professional
- Valid for
- Lifetime
Domains covered on the exam 6
- Service-Oriented Design Fundamentals15%
- Microservices and Domain-Driven Design20%
- Cloud and Container Technologies20%
- DevOps and Automation15%
- Integration and Messaging15%
- Security and Governance15%
- 1
A global logistics firm is architecting a multi-region SOA deployment. To comply with data sovereignty regulations like GDPR, customer data originating in the European Union must be processed and stored exclusively on servers within the EU. The current architecture uses a central API Gateway that routes traffic to services deployed across regions in the US, EU, and APAC. What is the most effective and maintainable design to enforce this data residency policy?
Show answer details
Correct answer: B
The most effective place to enforce cross-cutting concerns like policy-based routing is at a centralized ingress point, such as an API Gateway or service mesh ingress. This approach centralizes the governance logic, making it easier to manage, audit, and update without requiring changes to the underlying business services. Embedding logic in each service violates the principle of separation of concerns and leads to duplicated, hard-to-maintain code. Using separate gateways introduces management overhead, and relying on client-side logic is unreliable and not enforceable.
- 2
During a monolith-to-microservices migration, a development team finds that the new 'Orders' and 'Shipping' microservices both require access to customer address data. To move quickly, they configured both services to read from the same 'customers' table in the legacy database. This has resulted in a 'distributed monolith' where changes to the customer table schema require coordinated deployments of both services. Which Domain-Driven Design (DDD) pattern should be implemented to decouple these services while the legacy database is still in use?
Show answer details
Correct answer: C
An Anti-Corruption Layer (ACL) is the ideal pattern for this scenario. A new 'Customer' microservice would be created to own the customer data and expose it through a well-defined API. The 'Orders' and 'Shipping' services would then interact with this new service via the ACL, which translates the new API model to their internal domain models. This isolates them from the legacy database schema, breaking the direct dependency and allowing them to be deployed independently. A Shared Kernel would formalize the tight coupling, which is the problem. Published Language is about communication, not breaking structural coupling. An Aggregate is a concept within a bounded context, not an integration pattern.
- 3
A public utility company's microservice architecture experiences frequent cascading failures. A performance degradation in a low-level 'Billing-Data' service often causes timeouts in the mid-tier 'Invoice-Generation' service, which in turn causes 500 errors in the top-level 'Customer-Portal' API. The operations team struggles to identify the original source of the problem quickly. Which TWO of the following observability practices are most critical for enabling rapid root cause analysis in this distributed system? (Select TWO)
Show answer details
Correct answer: A, D
Distributed tracing is essential for understanding the entire lifecycle of a request as it travels through multiple services. It allows operators to visualize the call graph, identify which specific service call is introducing latency or failing, and pinpoint the origin of a cascading failure. Centralized logging helps correlate events across services once a problem area is identified.
Centralized logging, when combined with correlation IDs passed between service calls, allows the operations team to assemble a complete, ordered log of all activities related to a single user request. This is crucial for understanding the context of an error and seeing events from different services in one place. Without it, debugging involves manually checking logs on multiple systems.
- 4
True or False: The principle of Service Reusability dictates that a service should always be designed to be as generic as possible, even if it adds significant complexity to the initial implementation and contract.
Show answer details
Correct answer: B
This statement is false. While Service Reusability is a key goal, it is a trade-off. Overly generic services can become complex, difficult to maintain, and hard to understand (often called 'gold-plating'). The principle suggests designing for reuse where practical and valuable, but not at the expense of all other design considerations like simplicity, performance, and fitness for purpose. Effective SOA involves finding the right balance between specific, single-purpose services and broadly reusable, agnostic services.
- 5
Case Study: MediCare Solutions Modernization
MediCare Solutions, a regional healthcare provider, is modernizing its monolithic Patient Management System (PMS). The current system, built on a traditional 3-tier architecture with a large Oracle database, struggles with scalability during peak hours and makes it difficult to integrate with modern, third-party lab and pharmacy systems that use RESTful APIs.
Business & Technical Requirements:
- Compliance: The new system must be strictly HIPAA compliant, ensuring all Patient Health Information (PHI) is encrypted at rest and in transit, with granular access controls.
- Integration: It must integrate in near real-time with external partner APIs for lab results and e-prescriptions. These integrations must be reliable and resilient to partner downtime.
- Scalability & Availability: The system must be highly available (99.99%) and scale independently. The patient appointment scheduling feature, for example, sees massive spikes in traffic, while the patient history module has steady, predictable usage.
- Agility: Different development teams must be able to work on and deploy features like 'Appointments', 'Patient Records', and 'Billing' independently to increase development velocity.
Constraints:
- The existing Oracle database contains decades of patient data and cannot be replaced in the short term. The new architecture must coexist with it.
- The in-house operations team has strong experience with virtualization but is new to containerization and cloud-native tools.
Which of the following architectural proposals BEST meets all of MediCare Solutions' requirements and constraints?
graph TD subgraph "Proposed Architecture" API_GW[API Gateway] subgraph "Microservices (Kubernetes)" ApptSvc[Appointments Service] --> ApptDB[(Appt DB)] PatientSvc[Patient Records Service] BillingSvc[Billing Service] --> BillingDB[(Billing DB)] end subgraph "Integration Layer" IntegrationSvc[Integration Service] MsgBroker[Message Broker] end LegacyDB[(Legacy Oracle DB)] end API_GW --> ApptSvc API_GW --> PatientSvc API_GW --> BillingSvc PatientSvc -->|ACL| LegacyDB ApptSvc --> MsgBroker BillingSvc --> MsgBroker IntegrationSvc --> MsgBroker IntegrationSvc PartnerAPIs[External Partner APIs]Show answer details
Correct answer: A
This approach correctly addresses all requirements. The Strangler Fig pattern allows for gradual migration while coexisting with the legacy database. Microservices on Kubernetes address the independent scalability and team agility requirements. An API Gateway centralizes security. An ACL is the correct pattern to interface with the legacy DB without tight coupling. A message broker provides the required resilience for external integrations. Finally, encryption and mTLS (managed by a service mesh) satisfy the strict HIPAA compliance needs. The other options have critical flaws, such as using direct synchronous calls for external APIs (violating resilience), keeping a shared database (failing to achieve decoupling), or a 'lift-and-shift' which doesn't solve the core architectural problems.
- 6
A financial services company is modernizing its legacy SOA, which is built around a central Enterprise Service Bus (ESB) for orchestration, transformation, and routing of SOAP/XML messages between monolithic applications. The new architecture will introduce RESTful microservices running in containers. A key requirement is to expose a subset of both new and legacy services to external mobile applications via a secure, managed API. The company wants to improve agility and reduce the bottleneck caused by the central ESB team. Which architectural approach provides the most effective long-term solution for managing both internal service-to-service communication and external API exposure?
Show answer details
Correct answer: B
This is the optimal approach for a hybrid environment. An API Gateway at the edge is specifically designed for managing external traffic, providing security (rate limiting, auth), and exposing a clean API facade. Retaining the ESB for its powerful internal orchestration and transformation capabilities for legacy systems leverages existing investments and avoids a risky 'big bang' migration. This layered approach separates concerns effectively.
- 7
A development team is decomposing a monolithic order processing system into microservices. They have created an
Orderservice and aShipmentservice. When a new order is successfully processed, theOrderservice needs to trigger the creation of a shipment. The lead architect has mandated that the system must be resilient to transient failures of theShipmentservice and that theOrderservice should not be blocked or fail if theShipmentservice is temporarily unavailable. Which two design patterns should be implemented to meet these requirements? (Select TWO)Show answer details
Correct answer: A, C
The Transactional Outbox pattern ensures that the event to trigger the shipment is reliably saved in the same transaction as the order creation. A separate process then reads from this outbox table and publishes the event to a message broker. This guarantees that the event will eventually be sent, even if the message broker is down at the time of order creation, achieving reliable asynchronous communication.
Using a Publish/Subscribe (Pub/Sub) messaging system decouples the
Orderservice from theShipmentservice. TheOrderservice simply publishes anOrderCreatedevent to a topic. TheShipmentservice subscribes to this topic and processes the event when it is available. This asynchronous model prevents theOrderservice from being blocked if theShipmentservice is down. - 8
An architect is designing a security model for a microservices-based application deployed in Kubernetes. The requirements are to enforce strong identity for every service, encrypt all service-to-service (east-west) traffic, and apply fine-grained access policies specifying which services can communicate with each other. Manual configuration of certificates for each service is not feasible due to the dynamic nature of the environment. Which technology is best suited to meet all these requirements?
Show answer details
Correct answer: C
A service mesh (like Istio or Linkerd) is specifically designed to handle these concerns. It provides each service with a strong, verifiable identity (e.g., via SPIFFE/SPIRE), automatically enforces mutual TLS (mTLS) for all traffic within the mesh without application code changes, and allows for the definition of declarative, fine-grained authorization policies. This comprehensively addresses all stated requirements in a scalable, automated manner.
- 9
Case Study:
A large e-commerce company,
ShopSphere, is re-architecting its monolithic backend into a cloud-native microservices platform on Kubernetes to handle massive seasonal traffic spikes. The current system suffers from tight coupling, making independent deployments impossible and scaling inefficient.Current Architecture & Problems:
- A single, large Java application handles Products, Inventory, Orders, and Payments.
- All teams deploy on a fixed, quarterly schedule.
- The entire application must be scaled horizontally, even if only the Payments module is under heavy load.
- A failure in the Inventory component can bring down the entire checkout process.
Business & Technical Requirements:
- Independent Deployability: The Product, Inventory, Order, and Payment services must be developed, tested, and deployed independently.
- Elastic Scalability: Each service must scale independently based on its specific load.
- High Availability: The failure of a non-critical service (e.g., a recommendation engine) must not impact the core user journey of placing an order.
- Data Consistency: An order should only be confirmed if payment is successful and inventory is successfully reserved. This cross-service transaction must be managed reliably.
- Observability: A unified view of logs, metrics, and traces is required for troubleshooting distributed transactions.
Which of the following proposed architectures best satisfies all of ShopSphere's requirements?
Show answer details
Correct answer: B
This architecture correctly addresses all requirements. Independent CI/CD pipelines and databases enable independent deployability. The Saga pattern with event-driven choreography provides a resilient way to manage data consistency across services without tight coupling. A service mesh provides observability (tracing, metrics) out-of-the-box. The Bulkhead pattern is a key resilience strategy that prevents cascading failures, directly addressing the high availability requirement. This is the most comprehensive and modern approach.
- 10
True or False: In a contract-first approach to service design, the WSDL or OpenAPI specification is generated automatically from the service implementation code.
Show answer details
Correct answer: B
This statement describes a code-first (or implementation-first) approach. In a contract-first approach, the service contract (WSDL or OpenAPI specification) is defined first, as a technology-neutral agreement. The service implementation code is then written to conform to this pre-defined contract.
