A financial services company is modernizing its legacy SOA, which is built around a central Enterprise Service Bus (ESB) for orchestration, transformation, and routing of SOAP/XML messages between monolithic applications. The new architecture will introduce RESTful microservices running in containers. A key requirement is to expose a subset of both new and legacy services to external mobile applications via a secure, managed API. The company wants to improve agility and reduce the bottleneck caused by the central ESB team. Which architectural approach provides the most effective long-term solution for managing both internal service-to-service communication and external API exposure?
Answer and explanation
Correct answer: B
This is the optimal approach for a hybrid environment. An API Gateway at the edge is specifically designed for managing external traffic, providing security (rate limiting, auth), and exposing a clean API facade. Retaining the ESB for its powerful internal orchestration and transformation capabilities for legacy systems leverages existing investments and avoids a risky 'big bang' migration. This layered approach separates concerns effectively.
Question 2
Multiple answers
A development team is decomposing a monolithic order processing system into microservices. They have created an Order service and a Shipment service. When a new order is successfully processed, the Order service needs to trigger the creation of a shipment. The lead architect has mandated that the system must be resilient to transient failures of the Shipment service and that the Order service should not be blocked or fail if the Shipment service is temporarily unavailable. Which two design patterns should be implemented to meet these requirements? (Select TWO)
Answer and explanation
Correct answers: A, C
The Transactional Outbox pattern ensures that the event to trigger the shipment is reliably saved in the same transaction as the order creation. A separate process then reads from this outbox table and publishes the event to a message broker. This guarantees that the event will eventually be sent, even if the message broker is down at the time of order creation, achieving reliable asynchronous communication.
Using a Publish/Subscribe (Pub/Sub) messaging system decouples the Order service from the Shipment service. The Order service simply publishes an OrderCreated event to a topic. The Shipment service subscribes to this topic and processes the event when it is available. This asynchronous model prevents the Order service from being blocked if the Shipment service is down.
Question 3
An architect is designing a security model for a microservices-based application deployed in Kubernetes. The requirements are to enforce strong identity for every service, encrypt all service-to-service (east-west) traffic, and apply fine-grained access policies specifying which services can communicate with each other. Manual configuration of certificates for each service is not feasible due to the dynamic nature of the environment. Which technology is best suited to meet all these requirements?
Answer and explanation
Correct answer: C
A service mesh (like Istio or Linkerd) is specifically designed to handle these concerns. It provides each service with a strong, verifiable identity (e.g., via SPIFFE/SPIRE), automatically enforces mutual TLS (mTLS) for all traffic within the mesh without application code changes, and allows for the definition of declarative, fine-grained authorization policies. This comprehensively addresses all stated requirements in a scalable, automated manner.
Question 4
Case Study:
A large e-commerce company, ShopSphere, is re-architecting its monolithic backend into a cloud-native microservices platform on Kubernetes to handle massive seasonal traffic spikes. The current system suffers from tight coupling, making independent deployments impossible and scaling inefficient.
Current Architecture & Problems:
A single, large Java application handles Products, Inventory, Orders, and Payments.
All teams deploy on a fixed, quarterly schedule.
The entire application must be scaled horizontally, even if only the Payments module is under heavy load.
A failure in the Inventory component can bring down the entire checkout process.
Business & Technical Requirements:
Independent Deployability: The Product, Inventory, Order, and Payment services must be developed, tested, and deployed independently.
Elastic Scalability: Each service must scale independently based on its specific load.
High Availability: The failure of a non-critical service (e.g., a recommendation engine) must not impact the core user journey of placing an order.
Data Consistency: An order should only be confirmed if payment is successful and inventory is successfully reserved. This cross-service transaction must be managed reliably.
Observability: A unified view of logs, metrics, and traces is required for troubleshooting distributed transactions.
Which of the following proposed architectures best satisfies all of ShopSphere's requirements?
Answer and explanation
Correct answer: B
This architecture correctly addresses all requirements. Independent CI/CD pipelines and databases enable independent deployability. The Saga pattern with event-driven choreography provides a resilient way to manage data consistency across services without tight coupling. A service mesh provides observability (tracing, metrics) out-of-the-box. The Bulkhead pattern is a key resilience strategy that prevents cascading failures, directly addressing the high availability requirement. This is the most comprehensive and modern approach.
Question 5
True or False: In a contract-first approach to service design, the WSDL or OpenAPI specification is generated automatically from the service implementation code.
Answer and explanation
Correct answer: B
This statement describes a code-first (or implementation-first) approach. In a contract-first approach, the service contract (WSDL or OpenAPI specification) is defined first, as a technology-neutral agreement. The service implementation code is then written to conform to this pre-defined contract.
Question 6
A DevOps team is building a CI/CD pipeline for a microservice. A key goal is to ensure that any code change passes a series of automated quality gates before it can be deployed to production. The pipeline must support rapid feedback to developers and prevent buggy code from reaching users. The following diagram shows a proposed pipeline structure. Which stage is missing that is critical for enabling a zero-downtime deployment strategy and immediate rollback capability?
flowchart LR
A[Commit Code] --> B{Build & Unit Test}
B --> C{Static Code Analysis}
C --> D[Integration Test]
D --> E[Deploy to Staging]
E --> F{User Acceptance Test}
F --> G[Deploy to Production]
Answer and explanation
Correct answer: C
The diagram shows a direct 'Deploy to Production' step. To achieve zero-downtime and fast rollback, a progressive deployment strategy is needed. A canary deployment would release the new version to a small subset of users first, while a blue-green deployment would deploy the new version to a parallel production environment. Both allow for validation in a live environment before a full cutover and provide an immediate rollback path by simply redirecting traffic back to the old version. This stage is essential for mitigating deployment risk.
Question 7
When designing a new, agnostic utility service for currency conversion, an architect must decide on a versioning strategy. The service will be used by many independent consumer applications across the enterprise. The primary goal is to allow the service to evolve without breaking existing consumers. Which versioning approach best supports this goal?
Answer and explanation
Correct answer: B
URI versioning is a common and clear method for supporting multiple, potentially breaking, versions of a service concurrently. This allows existing consumers to continue using the older, stable version (v1) while new consumers can adopt the new version (v2). It gives consumers control over their migration timeline, preventing the service evolution from breaking them and thus achieving the primary goal.
Question 8
A cloud architect is deciding between using a container orchestration platform like Kubernetes or a Serverless/FaaS platform like AWS Lambda for a new event-processing service. The service will process uploaded images to extract metadata. The workload is expected to be very spiky, with long idle periods followed by sudden bursts of thousands of concurrent requests. Cost optimization for idle time is a major priority. Which platform is the better choice and why?
Answer and explanation
Correct answer: B
Serverless (FaaS) platforms are ideal for spiky, event-driven workloads. The key benefits that match the requirements are the 'scale-to-zero' capability, which means no resources are consumed and no costs are incurred during idle periods, and the automatic, massive scaling in response to event bursts. This directly addresses the cost optimization and scalability requirements more effectively than a Kubernetes cluster, which would require a minimum number of nodes to be running continuously.
Question 9
Multiple answers
An operations team is struggling to troubleshoot performance issues in a distributed microservices environment. When a user reports a slow API call, it's difficult to identify which downstream service is the bottleneck because logs from each service are stored in separate files on different virtual machines. What combination of practices is essential for establishing effective observability in this environment? (Select ALL that apply)
Answer and explanation
Correct answers: A, B, D
Aggregating logs from all services into a single, searchable platform (like the ELK stack or Splunk) is the first step to being able to analyze behavior across the entire system.
This is crucial for understanding the path of a request as it travels through multiple services. By propagating a unique correlation ID, tracing tools (like Jaeger or Zipkin) can visualize the entire call graph and pinpoint latency in specific downstream services.
Collecting time-series metrics (like request latency, error rates, resource utilization) from each service and visualizing them in dashboards (using tools like Prometheus and Grafana) allows the team to spot anomalies and correlate performance degradation with system events.
Question 10
A team is designing a service that aggregates data from two other services, Service A (product details) and Service B (inventory levels), to provide a complete view for a web storefront. Service A has a 99.5% availability SLA, and Service B has a 99.0% availability SLA. Assuming the services fail independently, what is the maximum theoretical availability of the new aggregator service if it relies on synchronous calls to both services to fulfill a single request?
Answer and explanation
Correct answer: C
When services are composed synchronously, their availabilities are multiplied to calculate the composite availability. The aggregator service is only available if BOTH Service A AND Service B are available. Therefore, the composite availability is calculated as: 0.995 * 0.990 = 0.98505, or 98.505%. This demonstrates how synchronous dependencies in a service composition decrease overall availability.