SOAP fast refresher
The whole of SOAP condensed — no long explanations, just the facts in the order they get asked. Read sections 2, 4, 5 and 8 twice and you've covered most of what a test will ask.
1 · The basics
- SOAP = Simple Object Access Protocol. An XML-only messaging protocol, usually sent over HTTP POST. It can also run over SMTP, TCP or JMS — a common multiple-choice question.
- Contract-first: a WSDL file describes the whole service before anyone calls it.
- Strictly typed, with an XSD schema for every message.
- Built-in standards for enterprise needs — security, reliability, transactions. These are the WS-* standards.
- Where it's used: banks, government, insurance, telecom, payment gateways — the legacy systems this kind of job involves.
2 · The message structure (must know)
<soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/">
<soap:Header> <!-- optional: security token, transaction id -->
<AuthToken>abc123</AuthToken>
</soap:Header>
<soap:Body> <!-- mandatory: the actual request -->
<GetCustomer xmlns="http://tempuri.org/">
<CustomerId>101</CustomerId>
</GetCustomer>
</soap:Body>
</soap:Envelope>
| Element | Required? | Purpose |
|---|---|---|
| Envelope | Yes | Root element; marks the XML as a SOAP message |
| Header | No | Extra information — authentication, routing, transaction data |
| Body | Yes | The request or response data |
| Fault | No (inside Body) | Error details |
Fault elements:
- SOAP 1.1:
faultcode,faultstring,faultactor,detail. - SOAP 1.1 fault codes:
VersionMismatch,MustUnderstand,Client,Server. - SOAP 1.2 renames the last two to
SenderandReceiver.
3 · SOAP 1.1 vs 1.2 (common multiple-choice topic)
| SOAP 1.1 | SOAP 1.2 | |
|---|---|---|
| Content-Type | text/xml | application/soap+xml |
| Action | Separate SOAPAction HTTP header | action parameter inside Content-Type |
| Namespace | schemas.xmlsoap.org/soap/envelope/ | www.w3.org/2003/05/soap-envelope |
| Fault codes | Client / Server | Sender / Receiver |
| WCF binding | basicHttpBinding | wsHttpBinding |
4 · WSDL — the service contract
Web Services Description Language. An XML file, fetched with ?wsdl on the end of the
service URL. 5 parts:
- types — XSD definitions of the data.
- message — the request and response messages.
- portType — the operations, like an interface. Says what the service does.
- binding — the protocol and format, e.g. SOAP 1.1 with document/literal. Says how to call it.
- service / port — the endpoint URL. Says where it is.
What (portType) → How (binding) → Where (service).
Message styles:
- Document/literal (wrapped) — the modern standard, compliant with WS-I Basic Profile.
- RPC/encoded — old and not interoperable.
5 · SOAP in .NET
ASMX (oldest, .NET Framework)
[WebService(Namespace = "http://tempuri.org/")]
public class CustomerService : WebService
{
[WebMethod]
public string GetName(int id) => "Ajay";
}
- Only supports SOAP over HTTP, and is limited.
- Uses XmlSerializer.
WCF (Windows Communication Foundation — the main one)
Address — where the service is (URL) · Binding — how to talk to it (protocol, encoding, security) · Contract — what it offers (the interface).
[ServiceContract]
public interface ICustomerService
{
[OperationContract]
[FaultContract(typeof(ErrorInfo))]
Customer GetCustomer(int id);
}
[DataContract]
public class Customer
{
[DataMember] public int Id { get; set; }
[DataMember] public string Name { get; set; }
}
Bindings — asked frequently:
| Binding | Protocol | Use |
|---|---|---|
basicHttpBinding | SOAP 1.1, HTTP | Works with any client including Java and PHP; the ASMX-compatible one |
wsHttpBinding | SOAP 1.2 with WS-* | Adds security, reliable messaging and transactions |
netTcpBinding | Binary over TCP | Fastest, but only .NET to .NET |
netNamedPipeBinding | Named pipes | Same machine only |
webHttpBinding | REST, not SOAP | A common trick question |
Other WCF points:
- Hosting: IIS, WAS, a Windows Service, or self-hosting with
ServiceHost. - Instance modes:
PerCall(new object per call — the scalable choice),PerSession(the default for session-capable bindings),Single(one object for all callers). - Concurrency:
Single,Multiple,Reentrant. - Errors: throw
FaultException<ErrorInfo>. Don't throw raw exceptions — clients only receive a generic fault unlessincludeExceptionDetailInFaultsis enabled, and that should stay off in production. - Serializers:
DataContractSerializeris WCF's default and requires you to opt in each member with[DataMember].XmlSerializeris used by ASMX and serializes public members.
6 · SOAP in .NET Core / .NET 8 (likely asked — the JD lists both)
- Calling a SOAP service: Visual Studio Connected Services
("WCF Web Service Reference") or the CLI tool
dotnet-svcutil. Either generates a proxy client class from the WSDL.
var client = new CustomerServiceClient();
var customer = await client.GetCustomerAsync(101);
- In .NET Core, generated proxies are async-only. They use the
System.ServiceModel.*NuGet packages. - Hosting a SOAP service: .NET Core has no built-in WCF server. Use CoreWCF (the community port Microsoft supports) or SoapCore.
- Calling without a proxy: send the XML yourself with
HttpClient.
var content = new StringContent(soapXml, Encoding.UTF8, "text/xml");
content.Headers.Add("SOAPAction", "http://tempuri.org/GetCustomer");
var resp = await http.PostAsync(url, content);
7 · Security
- Transport security: HTTPS/SSL protects the connection point to point.
- Message security: WS-Security protects the message itself
end to end, even through intermediaries. It supports:
- UsernameToken (username and password inside the Header)
- X.509 certificates
- XML Signature — guarantees the message wasn't changed
- XML Encryption — keeps it confidential
- Other WS-* standards: WS-Addressing (routing), WS-ReliableMessaging (guaranteed delivery), WS-AtomicTransaction (distributed transactions).
8 · SOAP vs REST (almost guaranteed)
| SOAP | REST | |
|---|---|---|
| Type | Protocol | Architectural style |
| Format | XML only | JSON, XML or anything |
| Contract | WSDL, strict | OpenAPI/Swagger, optional |
| Transport | HTTP, SMTP, TCP, JMS | HTTP only |
| HTTP methods | Nearly always POST | GET, POST, PUT, PATCH, DELETE |
| Caching | Not cacheable (POST) | GET is cacheable |
| Security | WS-Security plus TLS | TLS, OAuth, JWT |
| State | Can be stateful | Stateless |
| Performance | Heavier, verbose | Lighter, faster |
| Best for | Banking, government, transactions, formal contracts | Web and mobile apps, public APIs, microservices |
9 · Quick interview Q&A
| 1 | Is SOAP stateless? By default yes, but it can be stateful using WS-* standards or WCF sessions. |
| 2 | Why is SOAP still used? Formal contracts, WS-Security, reliable messaging and ACID transactions — plus a lot of legacy government and bank systems. |
| 3 | What does "Add Service Reference" do? Reads the WSDL and generates a proxy client class plus data classes. |
| 4 | What is mustUnderstand? A header attribute. If set to 1 and the receiver can't process that header, it must return a fault. |
| 5 | How do you test a SOAP service? SoapUI, the WCF Test Client, or Postman (POST with raw XML, the right Content-Type and a SOAPAction header). |
| 6 | What HTTP status does a SOAP fault return? 500 for a server fault. Some implementations return 400 for client errors. |
| 7 | Can SOAP return JSON? No — SOAP is XML only. A WCF service can expose REST/JSON through webHttpBinding, but that endpoint is no longer SOAP. |
| 8 | What is WS-I Basic Profile? Interoperability rules for SOAP, such as using document/literal. They make .NET and Java services work together. |
| 9 | What is MTOM? A way to send large binary attachments efficiently, instead of base64 inside the XML. |
| 10 | How do you expose a legacy SOAP service to a React app? See below — this is the scenario question. |
Build a .NET Core REST API as a facade:
- It calls the SOAP service through the generated proxy.
- It maps the XML data to JSON DTOs.
- It adds caching, retries (Polly) and JWT authentication.
- React then only ever talks to REST.
10 · Common multiple-choice traps
- Mandatory elements are Envelope and Body; Header is optional.
- WSDL is written in XML, and its data types are defined in XSD.
webHttpBindingis REST, not SOAP.basicHttpBindingis SOAP 1.1;wsHttpBindingis SOAP 1.2.- The Fault element goes inside the Body.
- UDDI is the old registry for discovering web services — dead now, but still appears in theory questions.
Read sections 2, 4, 5 and 8 twice. Say the ABC of WCF and the 5 parts of WSDL out loud. Rehearse Q10, the REST facade — it shows you understand both the old and the new systems.
Want the longer version with worked examples and traps? Start at Module 01, or use the cheat sheet for one-line recall of all 32 questions.