File APIs for Java Developers
Manipulate DOC, XLS, PPT, PDF and many others from your application.
The moose likes Web Component Certification (SCWCD/OCPJWCD) and the fly likes need help,2 questions Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login

Win a copy of Java Interview Guide this week in the Jobs Discussion forum!
JavaRanch » Java Forums » Certification » Web Component Certification (SCWCD/OCPJWCD)
Bookmark "need help,2 questions" Watch "need help,2 questions" New topic

need help,2 questions

shi lei

Joined: Jan 17, 2006
Posts: 15
-----question :
which of the following can implement security in servlets(select the best answer)?
a. declarative security.
b. programmatic security.
c. both a & b
d. servlet does not provide inbuilt Authentication and Authorization service(JAAS) has to be
used in conjuction with servlets for security.

-----question .
by which of the following means do communicating entities prove to one another that are acting on behalf of
specific identies that are authorized for access ?select one choice.
a. authorization
b. authentication
c. data integrity
d. confidentiality
e. all of above
singh santosh
Ranch Hand

Joined: Jan 13, 2006
Posts: 136
hi ,

According to me these should be the answers :

shi lei

Joined: Jan 17, 2006
Posts: 15
could you explain for me?
Karne Reddy
Ranch Hand

Joined: May 28, 2006
Posts: 35
For first one, i think Programmatic is right choice.

Because declarative security will not work for jsp actions.


singh santosh
Ranch Hand

Joined: Jan 13, 2006
Posts: 136
hi shi,

Ans1) Decrative security means securing throgh the configuration in web.xml and Programatic security menas through the code (servlet ) u write.

Case1: dec security : here we can secure our web app through various decration like for Authentication we have :

<form-login-config> ..</form-login-config>

for Authorization we have :

For programatic security we have got only three method defined:
boolean isUserInRole(String rolename)
String getUserPrinciple()
String getRemoteUser();

So now u can see ,if we have to secure our web-app resources we must have to declare through web.xml that which resources have restircted access and who all in which role can access it.
Whereas in code (Programaticaly ) we can only determine if the resource is restricted or not .and if the user is authentic one.

I agree. Here's the link:
subject: need help,2 questions
It's not a secret anymore!