Quick recap · Cheat sheet ☷ Flashcards
Quick recap

All 32 questions, one line each

Filter to one category, collapse what you already know, and print the rest. Click any question to open the full explanation.


The 14 things to be sure of

If you remember nothing else, remember these.

1SOAP is a protocol with a strict contract; REST is an architectural style. That's the whole difference in one line.
2Envelope → optional Header (security, routing) → mandatory Body. Errors go in a <Fault> inside the Body.
3A SOAP fault still returns HTTP 500 — the status code tells you nothing; read the fault.
41.1 vs 1.2: different namespace, application/soap+xml instead of text/xml, and Code/Reason instead of faultcode/faultstring.
5WSDL = types · message · portType · binding · service. The client needs the binding and the service address.
6SOAP is not encrypted by itself. You get privacy from HTTPS (transport) or WS-Security (message).
7Transport security protects point to point; message security survives intermediaries. That's when you need WS-Security.
8Interop problems are nearly always namespaces, SOAPAction, or a missing security header — in that order.
9WCF's ABC: Address (where), Binding (how), Contract (what).
10basicHttpBinding = interop · wsHttpBinding = WS-* features · netTcpBinding = fast, .NET-to-.NET only · webHttpBinding = REST, not SOAP.
11Throw FaultException<T>, never a raw .NET exception — a plain exception leaks nothing useful and faults the channel.
12A faulted proxy must be Abort()ed and recreated. Reusing it throws CommunicationObjectFaultedException.
13.NET Core can consume SOAP (dotnet-svcutil, async-only proxies, binding configured in code) but cannot host WCF — use CoreWCF or SoapCore.
14The modern answer to any legacy-SOAP question: wrap it in a .NET Core REST facade with DTOs, caching, Polly and JWT, so the frontend only sees JSON.

Debugging order that actually works

1Can you fetch ?wsdl at all? → network, TLS, auth.
2Does SoapUI succeed with its generated request? → the service is fine; it's your client.
3Diff SoapUI's envelope against yours → namespace, SOAPAction, headers.
4Log the full request and response envelopes, not just the exception message.

Words that signal seniority

contract-first · interoperability · WS-I Basic Profile · document/literal · message vs transport security · typed fault · faulted channel · facade · anti-corruption layer · legacy seam · MTOM · binding · trade-off

How to answer, whatever they ask

What it is → why it matters → what you'd do in practice, then tie it to something you've actually built. If you don't know, say so and say how you'd find out.