Yes that's correct.
Sometimes methods are called by the container like ejbLoad and ejbStore. You can obviously get your own EJBObject at that point, but since no client actually invoked a method there's no client security context to use, so trying to do anything regarding security at that point would cause a runtime error.
While I was studying for the exam, I found that somebody had some very, very helpful notes regarding what was available to beans during its lifecycle. I forget who it was that put it up. I wrote some review in the results forum that you can do a search for (using my member #). It should help you clear up
alot of these issues -- plus, it's a great cram tool right before you walk into the
testing center.
Nathaniel Stodard<br />SCJP, SCJD, SCWCD, SCBCD, SCDJWS, ICAD, ICSD, ICED