S90.19 (official code S90.19A) is Arcitura Education's Advanced SOA Security exam. It is one of six exams required for the Certified SOA Security Specialist credential in Arcitura's Gen 1 SOA Certified Professional (SOACP) program. It covers advanced security for service-oriented solutions, infrastructure, middleware and cloud-based services, including token issuance, WS-Trust, SAML federation, REST/HTTP security and security governance. TroyTec offers 83 practice questions and answers in PDF and Online Test Engine formats.
The S90.19 exam is the second of three security exams in Arcitura's SOA Security Specialist track. It follows S90.18 (Fundamental SOA Security) and comes before S90.20 (SOA Security Lab).
S90.18 covers the core controls. S90.19 moves into complex, real-world scenarios. You'll be asked where a security token should be issued and validated, how trust extends across organizational boundaries, and how message-level security holds up in multi-service compositions.
Passing S90.19 shows that you can find and fix security weaknesses in service-oriented designs before deployment. That skill is valued by solution architects, security architects and integration engineers who work with web services, REST APIs and hybrid cloud services.
Exam Code : S90.19 (official: S90.19A)
Exam Name : Advanced SOA Security
Vendor : Arcitura Education Inc.
Certification : Certified SOA Security Specialist (SOACP Gen 1)
Course Module : Module 19: Advanced SOA Security
Delivery : Pearson VUE test centers, Pearson VUE OnVUE online proctoring, Arcitura Direct Online Proctoring, or on-site during instructor-led workshops
Retake Policy : 24-hour wait after the 1st fail, 14 days after the 2nd, max 5 attempts in 12 months.
All six exams below must be passed to earn the certification:
S90.01A : Fundamental SOA & Service-Oriented Computing - SOA foundations
S90.02A : SOA Technology Concepts - Service technologies
S90.03A : SOA Design & Architecture - Architecture & design principles
S90.18A : Fundamental SOA Security - Core security controls & patterns
S90.19A : Advanced SOA Security - Advanced security architecture (this exam)
S90.20A : SOA Security Lab - Hands-on security problem-solving
Arcitura describes Module 19 as covering technical and complex security topics for contemporary service-oriented solutions, infrastructure, middleware and cloud-based service technology. The module outline is organized around these topic areas:
Security Policy Design & Governance - Defining, enforcing and governing security policies across service inventories
Security Token Structures & Issuance - Token types, issuance flows, validation points
Security Patterns for Internal Service Architectures - Applying patterns inside individual service architectures
Authentication Sessions & Secure Conversations - Session-based authentication, WS-SecureConversation
SOA Security Threats - Identifying and preparing for attacks on service-oriented solutions
WS-Trust & WS-SecureConversation with SAML - Security token services, SAML assertions, trust exchange
Cloud-Based Service Security Risks - Risks in cloud-hosted services and service compositions
Federation & Trust Brokering : Cross-domain identity and brokered trust
REST Security Controls & Design : Securing RESTful services
HTTP Security Mechanisms : HTTP-level authentication and transport security
SOA and solution architects who design security into service inventories
Security architects who are responsible for web service and API security
Integration and middleware engineers who work with ESBs, API gateways and service compositions
Candidates who have passed S90.18 and are continuing toward the SOA Security Specialist certification
Refresh the fundamentals. Review your S90.18 material first. S90.19 assumes you already know core security controls and patterns.
Study one topic area at a time. Work through the topic table above and focus on token flows, trust relationships and federation.
Practice scenario reasoning. The questions test judgment ("where should this token be validated?") rather than definitions.
Use the PDF for learning and the Test Engine for timing. Study with the PDF, then run timed sessions until you score consistently.
Review every wrong answer. Revisit the matching topic before retesting.
Plan for S90.20. The SOA Security Lab builds directly on what S90.19 covers.
S90.19A belongs to Arcitura's Gen 1 SOACP program. Arcitura's current Service Technology School offers a newer Service Security Specialist Certification Exam, which covers security for both microservices and SOA.
S90.19 (S90.19A) is Arcitura Education's Advanced SOA Security exam. It is the fifth of six exams required for the Certified SOA Security Specialist certification in the Gen 1 SOACP program.
Security policy design and governance, token structures and issuance, authentication sessions and secure conversations, WS-Trust and SAML, federation and trust brokering, cloud-based service security risks, REST security and HTTP security mechanisms.
S90.18 covers fundamental SOA security controls and patterns. S90.19 applies them to advanced scenarios such as cross-domain trust, token issuance, federation and cloud-hosted service compositions.
Arcitura exams can be taken at Pearson VUE testing centers, through Pearson VUE OnVUE online proctoring, through Arcitura Direct Online Proctoring, or on-site during an instructor-led workshop.
You must wait 24 hours after a first failure and 14 days after a second. Arcitura allows a maximum of five attempts in 12 months, and each retake needs a new voucher.
S90.01A, S90.02A, S90.03A, S90.18A, S90.19A and S90.20A.
Study anywhere with our portable PDF question bank
Simulate real exam conditions with our online engine
Everything you need to know about the S90.19 Advanced SOA Security Exam certification
Showing 5 of 20 FAQs
3,680 Students Downloaded this exam
Updated September 05, 2026
Stay current with frequently updated content
We're confident in our materials' quality