Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Oracle 1z0-1104-25 Dumps

Page: 1 / 4
Total 36 questions

Oracle Cloud Infrastructure 2025 Security Professional Questions and Answers

Question 1

Task 3: Create a Master Encryption Key

Note: OCI Vault to store the key required by this task is created in the root compartment as PBI_Vault_SP

Create an RSA Master Encryption Key (MEK), where:

Key name: PBT-CERT-MEK-01-

For example, if your username is 99008677-lab.user01, then the MEK name should be PBT-CERT-MEK-01990086771abuser01

Ensure you eliminate special characters from the user name.

Key shape: 4096 bits

Enter the OCID of the Master Encryption Key created in the provided text box:

Options:

Question 2

Challenge 2 -Task 1

In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.

As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.

Review the architecture diagram, which outlines the resoures you'll need to address the requirement:

as

Preconfigured

To complete this requirement, you are provided with the following:

Access to an OCI tenancy, an assigned compartment, and OCI credentials

Required IAM policies

Task3: Create and configure a Virtual Cloud Network and Private Subnet

Createand configure virtual cloud Network (VCN) named IAD SP-PBT-VCN-01, with an internet Gateway and configure appropriate route rules to allow external connectivity.

Enter the OCID of the created VCN in the text box below.

Options:

Question 3

Task 7: Verify the OCI Certificate with Load Balancer

Verify HTTPS connection to the load balancer by running the following command in Cloud Shell

curl -k

Enter the following URL in the web browser:

If prompted with a certificate error, accept the risk and continue.

Verify web page content by ensuring the text, "You are visiting Web Server 1" from the index.html file is displayed in the browser

Options:

Question 4

Challenge 2 -Task 1

In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.

As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.

Review the architecture diagram, which outlines the resoures you'll need to address the requirement:

as

Preconfigured

To complete this requirement, you are provided with the following:

Access to an OCI tenancy, an assigned compartment, and OCI credentials

Required IAM policies

Task 2: Create a Security Zone

Create a security Zone named IAD_SAP-PBT-CSZ-01 in your assigned compartement and associate it with the Custom Security Zone Recipe (IAD-SAP-PBT-CSP-01) created in the previous task.

Enter the OCID of the created Security zone in the box below.

as

Options:

Question 5

Task 5: Create a Certificate

Create a certificate, where:

Certificate name: PBT-CERT-01-

For example, if your username is 99008677-lab.user01, then the certificate name should be PBT-CERT-01990086771abuser01

Ensure you eliminate special characters from the user name.

Common name: PBT-CERT-OCICERT-01

Certificate Authority: PBT-CERT-CA-01 (created in the previous task)

Options:

Question 6

Your organization needs to implement strong password policies for users in OCI.

Which of the following statements is TRUE about password policies in OCI IAM?

Options:

A.

Custom password policies allow for granular control over password complexity.

B.

The default password policy cannot be modified.

C.

Only one password policy can be applied to all users in a domain.

D.

Simple password policies are suitable for production environments.

Question 7

A company has implemented OCI IAM policies with multiple levels of compartments. A policy attached to a parent compartment grants "manage virtual-network-family" permissions. A policy attached to a child compartment grants "use virtual-network-family" permissions.

as

According to OCI IAM policy inheritance, how does the OCI IAM policy engine resolve the permissions for a user attempting to perform an operation that requires 'manage' permissions in the child compartment?

Options:

A.

The operation is denied due to conflicting policies.

B.

The policy in the parent compartment takes precedence, and the user is granted "manage" permissions.

C.

The policy in the child compartment takes precedence, and the user is granted "use" permissions only.

Question 8

"Your company is in the process of migrating its sensitive data to Oracle Cloud Infrastructure (OCI) and is prioritizing the strongest possible security measures. Encryption is a key part of this strategy, but you are particularly concerned about the physical security of the hardware where your encryption keys will be stored.

Which characteristic of OCI Key Management Service (KMS) helps ensure the physical security of your encryption keys?

Options:

A.

Granular customer control over key access permissions

B.

Centralized key management for simplified administration

C.

Seamless integration with other OCI services for streamlined workflows

D.

Utilization of FIPS 140-2 validated Hardware Security Modules (HSMs)"

Question 9

An E-commerce company running on Oracle Cloud Infrastructure (OCI) wants to prevent accidental misconfigurations that could expose sensitive data. They need an OCI service that can enforce predefined security rules when creating or modifying cloud resources.

Which OCI service should they use?

Options:

A.

OCI Web Application Firewall (WAF)

B.

OCI Identity and Access Management (IAM)

C.

OCI Security Zone

D.

OCI Certificates

Question 10

Based on the provided diagram, you have a group of critical compute instances in a private subnet that require vulnerability using the Oracle Cloud Infrastructure(OCI) Vulnerability Scanning Service (VSS).

as

"What additional configuration is required to enable VSS to scan instances in the private subnet

Options:

A.

VSS cannot scan private instances. You need to move them to a public subnet for vulnerability scanning.

B.

Configure a service gateway in the VCN and a route rule to direct traffic for the VSS service through the gateway.

C.

No additional configuration is needed. VSS can access private instances by default.

D.

Use an OCI Bastion session to establish connectivity and forward scan results from the private instances."

Page: 1 / 4
Total 36 questions