Prasenjit Sarkar
By Prasenjit SarkarLast verified: 2026-09-06
OracleCybersecurityPROFESSIONAL

Oracle Cloud Infrastructure 2025 Security Professional Certification: Complete Guide 2026

1Z0-1104-25

The Oracle Cloud Infrastructure 2025 Security Professional certification validates expertise in designing, implementing, and managing secure cloud infrastructure solutions on OCI, including identity management, network security, data protection, and compliance.

Exam Details

Exam Code1Z0-1104-25
Duration90 min
Questions55
Passing Score68%
Exam Cost$245
Validity3 years
Avg. Salary$135,000/yr

Free Exam Dumps

1Z0-1104-25 practice questions

174 free questions with verified answers and an explanation for every option. A sample from each bank is below; every question has its own page.

1Z0-1104-25 exam dumps (174 questions)

All 1Z0-1104-25 questions

1Z0-1104-25 Question 1

Select 3

Your organization is migrating its financial application to Oracle Cloud Infrastructure (OCI) and has created separate compartments for development, testing, and production. As the security engineer, you want to ensure compliance with OCI� shared responsibility model. Which of the following tasks do you need to handle as the customer to maintain a secure environment?

  1. A

    Managing security lists and network security group rules for compute subnets

  2. B

    Applying operating system patches and updates on your compute instances

  3. C

    Overseeing physical security controls at OCI� data centers

  4. D

    Enforcing compartment-based IAM policies to restrict user access

  5. E

    Relying on automatic block volume encryption at rest provided by OCI, requiring no further action

Show answer and explanation

Correct answers: A, B, D

Explanation

In OCI� shared responsibility model, Oracle secures the underlying cloud infrastructure (e.g., physical servers, facilities, and hypervisors), while customers remain responsible for tasks such as configuring access controls, applying patches, and managing IAM policies in their tenancies. For more details, refer to the OCI documentation on 'Security in OCI' and the 'Shared Security Model' guidelines.

  • A. Correct.

    Managing security lists and network security group rules is the customer� responsibility, as you must configure network-based access controls to prevent unauthorized traffic to your instances. This is part of the �security in the cloud� under OCI� shared responsibility model.

  • B. Correct.

    Applying operating system patches and updates on your compute instances is a key customer responsibility, since Oracle manages the underlying infrastructure but not the guest OS. You control how frequently and when your servers are patched.

  • C. Incorrect.

    Overseeing physical security controls at OCI� data centers is Oracle� responsibility. Oracle manages data center physical security such as surveillance, access control, and facility hardening under the �security of the cloud� portion.

  • D. Correct.

    Enforcing compartment-based IAM policies is the customer� responsibility. Configuring appropriate IAM policies ensures the right users or groups have sufficient, but not excessive, privileges in each compartment.

  • E. Incorrect.

    While OCI automatically encrypts block volumes at rest, as a customer you do not need to take extra steps to enable this feature by default. However, creation and rotation of your own customer-managed keys (if you choose to go beyond default encryption) is an additional optional responsibility.

1Z0-1104-25 Question 2

Select 2

Your organization has discovered that certain Object Storage buckets in OCI are publicly accessible and some network security rules are overly permissive. The security team wants a solution that continuously detects misconfigurations and can automatically remediate them. Which TWO OCI services can you combine to achieve both real-time visibility and automated corrective actions for these security issues?

  1. A

    Cloud Guard

  2. B

    Data Safe

  3. C

    Security Zones

  4. D

    Vault

  5. E

    Vulnerability Scanning Service

Show answer and explanation

Correct answers: A, C

Explanation

Cloud Guard provides continuous security monitoring and automated remediation via responder rules, making it an excellent choice for detecting and resolving issues like publicly exposed buckets or permissive network rules. Security Zones enforce secure configurations from the start, blocking high-risk actions in designated compartments. Together, these two services address real-time detection, enforcement, and auto-remediation of misconfigurations. Refer to Oracle� Cloud Guard and Security Zones documentation for best practices and configuration details.

  • A. Correct.

    Cloud Guard is correct because it monitors resources continuously for security risks and can automate remediation through responder rules, making it ideal for detecting and fixing exposed buckets or permissive security rules.

  • B. Incorrect.

    Data Safe is incorrect because it primarily focuses on database security features like user assessment, data discovery, and activity auditing. It does not provide the continuous infrastructure misconfiguration detection and automated remediation you need for Object Storage buckets or network security configurations.

  • C. Correct.

    Security Zones is correct because it enforces security best practices from the outset. If a compartment is designated as a Security Zone, OCI prevents many misconfigurations (such as creating a public bucket) from ever happening. Used together with Cloud Guard, you get both enforcement and real-time detection/remediation.

  • D. Incorrect.

    Vault is incorrect because it provides centralized key management and supports data encryption, but it does not continuously monitor or remediate misconfigurations in OCI resources.

  • E. Incorrect.

    Vulnerability Scanning Service is incorrect because it focuses on scanning compute instances and load balancers for known vulnerabilities and open ports, rather than misconfigured Object Storage buckets or overly permissive network rules.

1Z0-1104-25 Question 3

Select 2

Your organization is migrating critical workloads to Oracle Cloud Infrastructure (OCI). You have been tasked with setting up the initial security configuration to align with the principle of least privilege. Which two actions should you prioritize to ensure that users only have access to the resources they need and to reduce the overall attack surface?

  1. A

    Create a single compartment for all resources and assign broad administrative privileges to administrators for easier maintenance

  2. B

    Organize resources into multiple compartments based on different functional or environment-specific requirements

  3. C

    Define and apply IAM policies that grant each user group only the permissions necessary to perform their tasks

  4. D

    Enable all advanced security features like Web Application Firewall (WAF) and Bastion by default, regardless of the environment� actual requirements

Show answer and explanation

Correct answers: B, C

Explanation

Implementing compartments and defining targeted IAM policies from the outset aligns with OCI best practices for least privilege. By segmenting resources and granting minimal but sufficient permissions, you reduce the potential blast radius of any security breach. Oracle� documentation emphasizes compartmentalization and precise policy management to maintain strong oversight of resource access while avoiding unnecessary privileges.

  • A. Incorrect.

    Incorrect. Consolidating all resources into a single compartment and assigning broad privileges contradicts the principle of least privilege. This approach increases the risk of unauthorized access if an administrator account is compromised, as it potentially grants them control over all resources.

  • B. Correct.

    Correct. Configuring separate compartments for different functional or environment-specific groups (e.g., Production, Development, Finance) is a best practice. Compartments help segment resources, allowing security boundaries to be properly enforced through policies.

  • C. Correct.

    Correct. IAM policies control who can access which resources and how. By granting only the necessary privileges to each group, you reduce the risk of accidental or malicious activity on resources outside a team� scope.

  • D. Incorrect.

    Incorrect. While enabling security features like WAF or Bastion when appropriate is important, turning them on indiscriminately without evaluating specific requirements can lead to unnecessary costs and complexity. Not all environments require every advanced security feature by default.

Exam Content

Exam Domains & Topics

Master these 4 domains to pass your exam

1

Identity and Access Management

25%
2

Network Security

25%
3

Data Protection and Encryption

25%
4

Security Monitoring and Compliance

25%

Who Should Take This Exam?

  • Security professionals with cloud infrastructure experience
  • Cloud architects focusing on security implementation
  • IT professionals managing OCI security operations
  • System administrators transitioning to cloud security roles
  • Security engineers seeking OCI-specific expertise

Study Timeline

10-14 weeks

Recommended duration

01

Foundation · Weeks 1-2

Review exam objectives & core concepts

02

Deep Dive · Weeks 3-6

Study each domain with hands-on labs

03

Practice & Review · Weeks 7-8

Take practice exams & target weak areas

View Full Study Plan

Study Guide

1Z0-1104-25 Study Plan

The Oracle Cloud Infrastructure 2025 Security Professional certification (1Z0-1104-25) validates your expertise in implementing and managing security solutions within OCI. This professional-level certification demonstrates advanced knowledge of identity management, network security, data protection, and compliance monitoring in cloud environments. It is highly valued for roles in cloud security architecture, security engineering, and compliance management.

  1. Week 1-2

    Foundation and IAM Mastery

    Build strong foundation in OCI fundamentals and master identity and access management

    • Complete OCI security architecture overview
    • Master IAM policy syntax and conditions
    • Understand federation and MFA implementation
    • Configure users, groups, and compartments
    • Practice writing complex IAM policies
  2. Week 3-4

    Network Security Deep Dive

    Master network security components and design secure network architectures

    • Design secure VCN architectures
    • Configure security lists and NSGs
    • Implement security zones
    • Set up WAF and DDoS protection
    • Configure VPN and private connectivity
    • Analyze network flows and logs
  3. Week 5-6

    Data Protection and Encryption

    Master encryption mechanisms and data protection strategies

    • Configure OCI Vault and key management
    • Implement encryption across services
    • Manage customer-managed encryption keys
    • Set up secrets management and rotation
    • Configure certificate management
    • Understand data residency requirements
  4. Week 7-8

    Security Monitoring and Compliance

    Master security monitoring tools and compliance frameworks

    • Configure and manage Cloud Guard
    • Set up vulnerability scanning
    • Implement comprehensive logging strategy
    • Create security alerts and notifications
    • Understand compliance frameworks
    • Practice incident response scenarios
  5. Week 9-10

    Integration and Advanced Scenarios

    Practice complex scenarios integrating all security domains

    • Design end-to-end secure architectures
    • Implement defense-in-depth strategies
    • Practice troubleshooting security issues
    • Review all exam domains comprehensively
    • Complete practice exams
    • Identify and strengthen weak areas
  6. Week 11-12

    Final Review and Exam Preparation

    Intensive review and practice testing

    • Complete multiple full-length practice exams
    • Review incorrect answers thoroughly
    • Create summary notes for quick review
    • Practice time management strategies
    • Review all key concepts and services
    • Mentally prepare for exam day

Study tips

Hands-On Practice

  • Create an OCI free tier account immediately and practice every concept
  • Build real security scenarios: configure Cloud Guard, set up WAF rules, implement encryption
  • Practice writing IAM policies from scratch without looking at documentation
  • Set up a test compartment structure and implement security zones
  • Break things intentionally to understand error messages and troubleshooting

IAM Policy Mastery

  • Create a policy syntax reference sheet with conditions and variables
  • Practice 20-30 different policy scenarios covering all resource types
  • Understand the evaluation logic: explicit deny > explicit allow > implicit deny
  • Master dynamic groups and when to use them versus regular groups
  • Test federation configurations with multiple identity providers

Network Security Focus

  • Draw network diagrams for different security scenarios before implementing
  • Understand the differences between security lists (stateful/stateless) and NSGs
  • Practice designing DMZ architectures and multi-tier applications
  • Configure WAF protection rules and understand different rule types
  • Test network path analyzer to understand traffic flows

Cloud Guard Expertise

  • Enable Cloud Guard and observe all default detector recipes
  • Create custom detector and responder recipes for specific scenarios
  • Understand the difference between problems, targets, and detectors
  • Practice configuring automated responses to security findings
  • Review real security findings and practice remediation procedures

Documentation Strategy

  • Bookmark key documentation pages for quick reference during study
  • Read the 'Security Best Practices' documentation cover to cover
  • Study the CLI commands for security services as exam may test automation
  • Review release notes for new security features introduced in 2024-2025
  • Create your own quick reference guide summarizing each domain

Exam-Specific Preparation

  • The exam tests depth not breadth - know services thoroughly, not superficially
  • Focus on 'why' not just 'how' - understand use cases and best practices
  • Pay attention to scenario-based questions requiring security design decisions
  • Review compliance requirements (PCI-DSS, HIPAA) and how OCI addresses them
  • Understand service limits and quotas that might impact security implementations
  • Know the differences between Oracle-managed and customer-managed controls

Time Management

  • With 55 questions in 90 minutes, you have about 98 seconds per question
  • Practice with timed mock exams to build speed and accuracy
  • Flag difficult questions and return to them after completing easier ones
  • Don't spend more than 2 minutes on any single question initially
  • Save 10-15 minutes at the end to review flagged questions

Exam day checklist

  • Arrive 15 minutes early for online proctoring setup or testing center check-in
  • Have a government-issued ID ready for verification
  • Ensure your testing environment is quiet, clean, and free from prohibited materials
  • Read each question carefully - Oracle exams often have subtle wording nuances
  • Watch for keywords like 'most secure', 'least effort', 'cost-effective', 'best practice'
  • Eliminate obviously wrong answers first in multiple-choice questions
  • Don't change answers unless you're certain - your first instinct is usually correct
  • If unsure, think about which answer aligns with security best practices
  • Remember that you need 68% (38 out of 55 questions) to pass - stay calm
  • Use the mark/flag feature for questions you want to review
  • Don't leave any questions unanswered - there's no penalty for guessing
  • Take a deep breath before starting and maintain confidence throughout

Career

Career Opportunities

Roles and salary potential for Oracle Cloud Infrastructure 2025 Security Professional certified professionals

Related Job Titles

Cloud Security EngineerOCI Security ArchitectCloud Infrastructure Security SpecialistSecurity Operations Engineer

$135,000

Average Annual Salary

Prerequisites

Oracle Cloud Infrastructure 2025 Architect Associate certification recommended 6-12 months of hands-on experience with OCI security services Understanding of cloud security principles and best practices Knowledge of identity and access management concepts Familiarity with network security and encryption technologies

FAQ

Oracle Cloud Infrastructure 2025 Security Professional FAQs

Common questions about the 1Z0-1104-25 certification exam

The OCI 2025 Security Professional certification validates your ability to design, implement, and manage comprehensive security solutions in Oracle Cloud Infrastructure. It demonstrates expertise in identity and access management, network security, data protection, encryption, and security monitoring across OCI environments.

The exam is considered moderately difficult and requires professional-level expertise. It contains 55 questions to be completed in 90 minutes and tests both theoretical knowledge and practical application of OCI security services. Candidates should have hands-on experience with OCI security implementations and thorough understanding of security best practices.

Professionals with the Oracle Cloud Infrastructure Security Professional certification typically earn between $115,000 and $155,000 annually, with an average of $135,000. Salaries vary based on location, experience level, and additional certifications. This certification is particularly valuable as organizations increasingly prioritize cloud security expertise.

While not mandatory, Oracle recommends having the OCI 2025 Architect Associate certification and 6-12 months of hands-on experience with OCI security services before attempting this professional-level exam. This foundation ensures you understand core OCI concepts before diving into advanced security topics.

The Oracle Cloud Infrastructure 2025 Security Professional certification is valid for 3 years from the date you pass the exam. After 3 years, you'll need to recertify by passing the current version of the exam to maintain your certified status and stay current with evolving OCI security features.

About the Oracle Cloud Infrastructure 2025 Security Professional Certification

The Oracle Cloud Infrastructure 2025 Security Professional (1Z0-1104-25) is a professional-level certification offered by Oracle. This certification validates your expertise in cybersecurity and is recognized globally by employers seeking qualified professionals. The exam consists of 55 questions to be completed in 90 minutes, with a passing score of 68%. The exam fee is $245, and the certification is valid for 3 years.

Why Get Oracle Cloud Infrastructure 2025 Security Professional Certified?

  • Career Advancement: Certified professionals earn an average of $135,000 per year. Oracle-certified professionals are among the most sought-after in the cybersecurity industry.
  • Industry Recognition: Oracle certifications are respected worldwide by employers, demonstrating verified competency in cybersecurity technologies and practices.
  • Skill Validation: The Oracle Cloud Infrastructure 2025 Security Professional exam rigorously tests your knowledge across 4 domains, ensuring you have the practical skills employers demand.

Oracle Cloud Infrastructure 2025 Security Professional Exam Format & Details

The 1Z0-1104-25 exam is designed to test both theoretical knowledge and practical application. Candidates are given 90 minutes to complete the exam, which contains approximately 55 questions. A score of 68% is required to pass. As a professional-level exam, it requires significant hands-on experience and deep technical knowledge. Prerequisites include: Oracle Cloud Infrastructure 2025 Architect Associate certification recommended 6-12 months of hands-on experience with OCI security services Understanding of cloud security principles and best practices Knowledge of identity and access management concepts Familiarity with network security and encryption technologies.

Exam Domains & Topics

The Oracle Cloud Infrastructure 2025 Security Professional exam covers 4 key domains. Understanding the weight of each domain helps you allocate your study time effectively:

  • Identity and Access Management (25% of exam)
  • Network Security (25% of exam)
  • Data Protection and Encryption (25% of exam)
  • Security Monitoring and Compliance (25% of exam)

Who Should Take the Oracle Cloud Infrastructure 2025 Security Professional Exam?

This certification is designed for professionals in the following roles:

  • Security professionals with cloud infrastructure experience
  • Cloud architects focusing on security implementation
  • IT professionals managing OCI security operations
  • System administrators transitioning to cloud security roles
  • Security engineers seeking OCI-specific expertise

Career Opportunities & Salary

Earning the Oracle Cloud Infrastructure 2025 Security Professional certification opens doors to roles such as Cloud Security Engineer, OCI Security Architect, Cloud Infrastructure Security Specialist, Security Operations Engineer. Certified professionals earn an average salary of $135,000 per year, reflecting the high demand for cybersecurity skills in today's job market.

Recertification & Renewal

The Oracle Cloud Infrastructure 2025 Security Professional certification is valid for 3 years. To maintain your credential, you will need to meet Oracle's renewal requirements before your certification expires. This may include earning continuing education credits, passing a recertification exam, or earning a higher-level certification.

Exam Registration & Cost

The 1Z0-1104-25 exam costs $245. You can register through Oracle's official website or an authorized testing center. Most candidates choose between in-person testing at a Pearson VUE or PSI center and online proctored exams taken from home. Be sure to review the exam policies, including identification requirements and prohibited items, before your test date.

How to Prepare for 1Z0-1104-25

We recommend 10-14 weeks of dedicated study time to prepare for the Oracle Cloud Infrastructure 2025 Security Professional exam. Start by reviewing the official exam objectives, then work through each domain systematically. Regular practice with exam-style questions is essential for building confidence and identifying weak areas. Combine reading with hands-on practice to develop both theoretical knowledge and practical skills.

HydraNode publishes 174 free 1Z0-1104-25 practice questions with answers and explanations, plus a timed practice exam drawn from the same bank. Every question is written to the published objectives, so what you practise matches the format and difficulty of the actual 1Z0-1104-25 exam.