S90.18 (official code S90.18A) is Arcitura Education's Fundamental SOA Security exam. It is the first of three security exams in the Certified SOA Security Specialist track, part of Arcitura's Gen 1 SOA Certified Professional (SOACP) program. It tests core security terminology, security mechanisms, service interaction security patterns, WS-Security and REST security standards, SAML, and service-orientation security considerations. TroyTec offers 98 practice questions and answers in PDF and Online Test Engine formats.
The S90.18 exam validates your understanding of the essential techniques, patterns and industry technologies used to build security controls and security architectures for service-oriented solutions. It corresponds to Arcitura SOACP Module 18.
S90.18 is the foundation of the SOA security path. You'll need to understand how services authenticate each other, how message data stays confidential as it passes through intermediaries, and which standards (WS-Security, SAML, HTTP-based controls) apply in each situation. Everything in S90.19 Advanced SOA Security and the S90.20 SOA Security Lab builds on this knowledge.
Exam Code : S90.18 (official: S90.18A)
Exam Name : Fundamental SOA Security
Vendor : Arcitura Education Inc.
Certification : Certified SOA Security Specialist (SOACP Gen 1)
Course Module : Module 18: Fundamental Security for Services, Microservices & SOA
unable to make a table please write content difference
S90.18 and S90.19 are both part of Arcitura's Certified SOA Security Specialist track, but they test different levels of knowledge. S90.18 builds the foundation, and S90.19 applies it to advanced, real-world security scenarios.
S90.18 Fundamental SOA Security is the entry point to the security track. It checks whether you understand the core concepts, mechanisms and patterns used to secure service-oriented solutions. S90.19 Advanced SOA Security assumes you already know these fundamentals and tests whether you can apply them to complex architectures.
S90.18 covers security terminology, basic security mechanisms such as encryption and digital signatures, and service interaction security patterns like Direct Authentication, Brokered Authentication, Data Confidentiality and Data Origin Authentication. S90.19 moves into security policy design and governance, security token issuance, federation and trust brokering, and the security risks of cloud-based services and service compositions.
In S90.18, you learn what WS-Security, SAML and REST security controls do and when to use each one. S90.19 goes deeper into WS-Trust, WS-SecureConversation, SAML-based federation and HTTP security mechanisms, with a focus on how trust and identity move across services and organizations.
S90.18 questions mainly test whether you can identify the right concept, pattern or standard for a given problem. S90.19 questions are more scenario-based. For example, you may need to decide where a security token should be issued and validated, or how to maintain trust between separate security domains.
S90.18 is the fourth of six exams in the Certified SOA Security Specialist path, and S90.19 is the fifth. Taking them in order is recommended, because S90.19 builds directly on S90.18. After both, candidates move on to S90.20, the SOA Security Lab.
TroyTec's S90.18 bundle includes 98 practice questions and answers. The S90.19 bundle includes 83. Both come in PDF and Online Test Engine formats.
Start with S90.18 if you are new to service security or want a solid grounding in the core patterns and standards. Move to S90.19 once you're comfortable with those fundamentals and ready to handle advanced, multi-service security scenarios.
These topic areas follow the official lesson structure of Arcitura's Module 18:
Fundamental Security Terminology & Concepts : Confidentiality, integrity, authentication, authorization, threats and vulnerabilities
Fundamental Security Mechanisms : Encryption, hashing, digital signatures, certificates and identity mechanisms
Service Interaction Security Patterns : Direct Authentication, Brokered Authentication, Data Confidentiality, Data Origin Authentication
Web Service Security Standards : WS-Security and related XML security technologies
REST Service Security Standards : Securing RESTful services and HTTP-based interactions
Security Assertion Markup Language (SAML) : SAML assertions and how they carry identity between services
SOA & Service-Orientation Security Considerations : How service-orientation principles (reuse, composition, loose coupling) affect security design
SOA and solution architects who need a solid grounding in service security
Developers and integration engineers who build web services or REST APIs
Security professionals moving into service-oriented or API security
SOACP candidates who have completed S90.01–S90.03 and are starting the security track
Learn the vocabulary first. Arcitura exams rely on precise terminology, so build a one-page glossary of security terms and patterns.
Match each pattern to its problem. Know when to use Direct Authentication vs. Brokered Authentication, and Data Confidentiality vs. Data Origin Authentication.
Separate the standards. Be clear on what WS-Security, SAML and HTTP/REST security each handle.
Study with the PDF, then test with the engine. Run timed sessions until you score consistently.
Review every missed question against its topic area before retesting.
Move straight into S90.19 while the fundamentals are fresh.
S90.18 (S90.18A) is Arcitura Education's Fundamental SOA Security exam. It is the fourth of six exams required for the Certified SOA Security Specialist certification in the Gen 1 SOACP program.
Arcitura Education Inc., a vendor-neutral IT training and certification provider.
Security terminology and concepts, security mechanisms, service interaction security patterns, WS-Security, REST service security, SAML and service-orientation security considerations.
S90.18 covers foundational security concepts, patterns and standards. S90.19 applies them to advanced scenarios such as token issuance, federation, trust brokering and cloud-based service security.
At Pearson VUE testing centers, through Pearson VUE OnVUE online proctoring, through Arcitura Direct Online Proctoring, or on-site during an instructor-led workshop.
You must wait 24 hours after a first failure and 14 days after a second. Arcitura allows a maximum of five attempts in 12 months, and each retake requires a new voucher.
Study anywhere with our portable PDF question bank
Simulate real exam conditions with our online engine
Everything you need to know about the Fundamental SOA Security Exam certification
Showing 5 of 20 FAQs
3,678 Students Downloaded this exam
Updated September 04, 2026
Stay current with frequently updated content
We're confident in our materials' quality