1Z0-1104-25 OCI 2025 Security Professional Practice Questions
Prepare for 1Z0-1104-25 with more than an answer.
- 1
You are configuring OCI Bastion to provide temporary access to a private database. You want to ensure that the session automatically expires after 30 minutes and restricts access to a specific IP address of the database administrator. Which two parameters must be defined when creating the session? (Select TWO)
Show answer details
Correct answer: B, E
The Client CIDR Block allowlist restricts which source IP address (the admin's computer) can initiate the connection to the Bastion session.
The Session TTL determines the duration (e.g., 30 minutes) before the session expires.
- 2
Which OCI service is primarily responsible for detecting rogue users and identifying potential malicious actors by analyzing audit logs and network telemetry using machine learning?
Show answer details
Correct answer: D
OCI Threat Intelligence aggregates threat data from various sources (Oracle security researchers, open source feeds) to detect malicious activity and rogue users in the tenancy.
- 3
You are managing encryption for a highly regulated banking application. The compliance team requires that the encryption keys be rotated every 90 days. You are using OCI Vault. What happens to the old key version after you rotate to a new key version?
Show answer details
Correct answer: D
When a key is rotated, the old key version is preserved to decrypt data that was encrypted with it. The new key version becomes the primary version used for new encryption operations.
- 4
A global financial institution is designing a Zero Trust architecture on OCI. They require a network security model that decouples security policies from network topology, allowing them to define intent-based policies using attributes rather than IP addresses and ports. Which OCI capability should they implement to meet this specific requirement for 2025 standards?
Show answer details
Correct answer: A
OCI Zero Trust Packet Routing (ZPR) is a new feature (emphasized in the 2025 syllabus) that allows organizations to define security policies based on 'intent' and resource attributes rather than physical network coordinates like IP addresses and ports. It decouples security from network topology.
- 5
You are transitioning your organization's patching strategy from the legacy OS Management Service to the new OCI OS Management Hub. You have several instances in private subnets that do not have direct internet access or a NAT gateway. To enable OS Management Hub to manage these private instances, what component must you configure?
Show answer details
Correct answer: A
In OCI OS Management Hub, a Management Station is a dedicated instance that acts as a mirror for software sources and a proxy for management traffic. It is specifically designed to support instances in private subnets or disconnected environments.
- 6
While troubleshooting a deployment in a compartment associated with an OCI Security Zone, a DevOps engineer receives a '400-InvalidParameter' error when attempting to create a public Compute instance. The Security Zone recipe is set to 'Maximum Security'. What is the most likely cause of this error?
Show answer details
Correct answer: C
Security Zones enforce security best practices. The 'Maximum Security' recipe explicitly denies the creation of compute instances with public IP addresses to prevent internet exposure. This is a policy enforcement error, not an IAM permission error.
