Securing Services (17%)
Configure secure Bindings
This objective may include but is not limited to: transport, message, mixed mode
http://msdn.microsoft.com/en-us/library/ms731172(v=VS.100).aspx
Configure message security
This objective may include but is not limited to: specifying protection levels on different message parts
http://msdn.microsoft.com/en-us/library/ms789036.aspx
Implement Authentication
- Implement Authentication.This objective may include but is not limited to: Microsoft ASP.NET Membership Provider, Custom Provider, Windows Integrated Security, certificates (X.509), Federated Authentication endpoint identity; configuring client credentials; Custom ValidatorThis objective does not include: Geneva Framework
- Implement Authorization.This objective may include but is not limited to: role based, claim based; configuring role providers for endpoints; principal permission attributeThis objective does not include: rights-management authorization such as Active Directory Rights Management Services (AD RMS)
- Implement Impersonation.This objective may include but is not limited to: configuration and code; configuring WCF-specific Internet Information Services (IIS) impersonation properties; configuring impersonation options; operation-based and service-based
- Implement security auditing.This objective may include but is not limited to: using serviceSecurityAudit behavior, service auditing, audit log
0 comentarios: