Fast refresher
Everything, in bullet points

SOAP fast refresher

The whole of SOAP condensed — no long explanations, just the facts in the order they get asked. Read sections 2, 4, 5 and 8 twice and you've covered most of what a test will ask.

1 · The basics

  • SOAP = Simple Object Access Protocol. An XML-only messaging protocol, usually sent over HTTP POST. It can also run over SMTP, TCP or JMS — a common multiple-choice question.
  • Contract-first: a WSDL file describes the whole service before anyone calls it.
  • Strictly typed, with an XSD schema for every message.
  • Built-in standards for enterprise needs — security, reliability, transactions. These are the WS-* standards.
  • Where it's used: banks, government, insurance, telecom, payment gateways — the legacy systems this kind of job involves.

2 · The message structure (must know)

<soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/">
  <soap:Header>          <!-- optional: security token, transaction id -->
    <AuthToken>abc123</AuthToken>
  </soap:Header>
  <soap:Body>            <!-- mandatory: the actual request -->
    <GetCustomer xmlns="http://tempuri.org/">
      <CustomerId>101</CustomerId>
    </GetCustomer>
  </soap:Body>
</soap:Envelope>
ElementRequired?Purpose
EnvelopeYesRoot element; marks the XML as a SOAP message
HeaderNoExtra information — authentication, routing, transaction data
BodyYesThe request or response data
FaultNo (inside Body)Error details

Fault elements:

  • SOAP 1.1: faultcode, faultstring, faultactor, detail.
  • SOAP 1.1 fault codes: VersionMismatch, MustUnderstand, Client, Server.
  • SOAP 1.2 renames the last two to Sender and Receiver.

3 · SOAP 1.1 vs 1.2 (common multiple-choice topic)

SOAP 1.1SOAP 1.2
Content-Typetext/xmlapplication/soap+xml
ActionSeparate SOAPAction HTTP headeraction parameter inside Content-Type
Namespaceschemas.xmlsoap.org/soap/envelope/www.w3.org/2003/05/soap-envelope
Fault codesClient / ServerSender / Receiver
WCF bindingbasicHttpBindingwsHttpBinding

4 · WSDL — the service contract

Web Services Description Language. An XML file, fetched with ?wsdl on the end of the service URL. 5 parts:

  1. types — XSD definitions of the data.
  2. message — the request and response messages.
  3. portType — the operations, like an interface. Says what the service does.
  4. binding — the protocol and format, e.g. SOAP 1.1 with document/literal. Says how to call it.
  5. service / port — the endpoint URL. Says where it is.
Memory trick

What (portType) → How (binding) → Where (service).

Message styles:

  • Document/literal (wrapped) — the modern standard, compliant with WS-I Basic Profile.
  • RPC/encoded — old and not interoperable.

5 · SOAP in .NET

ASMX (oldest, .NET Framework)

[WebService(Namespace = "http://tempuri.org/")]
public class CustomerService : WebService
{
    [WebMethod]
    public string GetName(int id) => "Ajay";
}
  • Only supports SOAP over HTTP, and is limited.
  • Uses XmlSerializer.

WCF (Windows Communication Foundation — the main one)

The "ABC" of an endpoint — always asked

Address — where the service is (URL) · Binding — how to talk to it (protocol, encoding, security) · Contract — what it offers (the interface).

[ServiceContract]
public interface ICustomerService
{
    [OperationContract]
    [FaultContract(typeof(ErrorInfo))]
    Customer GetCustomer(int id);
}

[DataContract]
public class Customer
{
    [DataMember] public int Id { get; set; }
    [DataMember] public string Name { get; set; }
}

Bindings — asked frequently:

BindingProtocolUse
basicHttpBindingSOAP 1.1, HTTPWorks with any client including Java and PHP; the ASMX-compatible one
wsHttpBindingSOAP 1.2 with WS-*Adds security, reliable messaging and transactions
netTcpBindingBinary over TCPFastest, but only .NET to .NET
netNamedPipeBindingNamed pipesSame machine only
webHttpBindingREST, not SOAPA common trick question

Other WCF points:

  • Hosting: IIS, WAS, a Windows Service, or self-hosting with ServiceHost.
  • Instance modes: PerCall (new object per call — the scalable choice), PerSession (the default for session-capable bindings), Single (one object for all callers).
  • Concurrency: Single, Multiple, Reentrant.
  • Errors: throw FaultException<ErrorInfo>. Don't throw raw exceptions — clients only receive a generic fault unless includeExceptionDetailInFaults is enabled, and that should stay off in production.
  • Serializers: DataContractSerializer is WCF's default and requires you to opt in each member with [DataMember]. XmlSerializer is used by ASMX and serializes public members.

6 · SOAP in .NET Core / .NET 8 (likely asked — the JD lists both)

  • Calling a SOAP service: Visual Studio Connected Services ("WCF Web Service Reference") or the CLI tool dotnet-svcutil. Either generates a proxy client class from the WSDL.
var client = new CustomerServiceClient();
var customer = await client.GetCustomerAsync(101);
  • In .NET Core, generated proxies are async-only. They use the System.ServiceModel.* NuGet packages.
  • Hosting a SOAP service: .NET Core has no built-in WCF server. Use CoreWCF (the community port Microsoft supports) or SoapCore.
  • Calling without a proxy: send the XML yourself with HttpClient.
var content = new StringContent(soapXml, Encoding.UTF8, "text/xml");
content.Headers.Add("SOAPAction", "http://tempuri.org/GetCustomer");
var resp = await http.PostAsync(url, content);

7 · Security

  • Transport security: HTTPS/SSL protects the connection point to point.
  • Message security: WS-Security protects the message itself end to end, even through intermediaries. It supports:
    • UsernameToken (username and password inside the Header)
    • X.509 certificates
    • XML Signature — guarantees the message wasn't changed
    • XML Encryption — keeps it confidential
  • Other WS-* standards: WS-Addressing (routing), WS-ReliableMessaging (guaranteed delivery), WS-AtomicTransaction (distributed transactions).

8 · SOAP vs REST (almost guaranteed)

SOAPREST
TypeProtocolArchitectural style
FormatXML onlyJSON, XML or anything
ContractWSDL, strictOpenAPI/Swagger, optional
TransportHTTP, SMTP, TCP, JMSHTTP only
HTTP methodsNearly always POSTGET, POST, PUT, PATCH, DELETE
CachingNot cacheable (POST)GET is cacheable
SecurityWS-Security plus TLSTLS, OAuth, JWT
StateCan be statefulStateless
PerformanceHeavier, verboseLighter, faster
Best forBanking, government, transactions, formal contractsWeb and mobile apps, public APIs, microservices

9 · Quick interview Q&A

1Is SOAP stateless? By default yes, but it can be stateful using WS-* standards or WCF sessions.
2Why is SOAP still used? Formal contracts, WS-Security, reliable messaging and ACID transactions — plus a lot of legacy government and bank systems.
3What does "Add Service Reference" do? Reads the WSDL and generates a proxy client class plus data classes.
4What is mustUnderstand? A header attribute. If set to 1 and the receiver can't process that header, it must return a fault.
5How do you test a SOAP service? SoapUI, the WCF Test Client, or Postman (POST with raw XML, the right Content-Type and a SOAPAction header).
6What HTTP status does a SOAP fault return? 500 for a server fault. Some implementations return 400 for client errors.
7Can SOAP return JSON? No — SOAP is XML only. A WCF service can expose REST/JSON through webHttpBinding, but that endpoint is no longer SOAP.
8What is WS-I Basic Profile? Interoperability rules for SOAP, such as using document/literal. They make .NET and Java services work together.
9What is MTOM? A way to send large binary attachments efficiently, instead of base64 inside the XML.
10How do you expose a legacy SOAP service to a React app? See below — this is the scenario question.
Q10 in full — the answer that fits this job

Build a .NET Core REST API as a facade:

  • It calls the SOAP service through the generated proxy.
  • It maps the XML data to JSON DTOs.
  • It adds caching, retries (Polly) and JWT authentication.
  • React then only ever talks to REST.

10 · Common multiple-choice traps

⚠ The six that catch people
  • Mandatory elements are Envelope and Body; Header is optional.
  • WSDL is written in XML, and its data types are defined in XSD.
  • webHttpBinding is REST, not SOAP.
  • basicHttpBinding is SOAP 1.1; wsHttpBinding is SOAP 1.2.
  • The Fault element goes inside the Body.
  • UDDI is the old registry for discovering web services — dead now, but still appears in theory questions.

If you only have 30 minutes

Read sections 2, 4, 5 and 8 twice. Say the ABC of WCF and the 5 parts of WSDL out loud. Rehearse Q10, the REST facade — it shows you understand both the old and the new systems.

Want the longer version with worked examples and traps? Start at Module 01, or use the cheat sheet for one-line recall of all 32 questions.