1Z0-1067-25 exam dumps

1Z0-1067-25 practice question 110 of 138

Oracle Cloud Infrastructure 2025 Cloud Ops Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1067-25 Question 110

Select 2

Your organization maintains two separate compartments in OCI named 'analytics_compartment' and 'ds_compartment.' The AnalyticsTeam group must have the ability to read objects within the analytics_compartment and manage data science resources within the ds_compartment, but should not be granted any additional privileges. Which two policy statements best align with the principle of least privilege for granting these permissions?

  1. A

    Allow group AnalyticsTeam to read object-family in tenancy

  2. B

    Allow group AnalyticsTeam to read object-family in compartment analytics_compartment

  3. C

    Allow group AnalyticsTeam to manage data-science-family in compartment ds_compartment

  4. D

    Allow group AnalyticsTeam to manage all-resources in compartment ds_compartment

Show answer and explanation

Correct answers: B, C

Explanation

When designing OCI IAM policies, a key best practice is to grant only the necessary level of access to each resource or compartment. By specifying exact actions (such as read for object-family and manage for data-science-family) and limiting those actions to specific compartments, you adhere to the principle of least privilege. Oracle� IAM documentation highlights the importance of using compartment-scoped policies and restricting capabilities to only what is required for a given role.

  • A. Incorrect.

    Option 1: Incorrect. Granting analytical read access at the tenancy level is too broad. It goes against the principle of least privilege by giving the AnalyticsTeam access to read objects in all compartments rather than limiting them to the analytics_compartment only.

  • B. Correct.

    Option 2: Correct. This policy statement restricts read access to only the object-family within the analytics_compartment, satisfying the requirement to grant minimum necessary privileges for analytics tasks.

  • C. Correct.

    Option 3: Correct. This policy statement grants management privileges on data science resources exclusively within the ds_compartment, aligning with the team's need and avoiding broader access to resources in other compartments.

  • D. Incorrect.

    Option 4: Incorrect. Although this policy is limited to ds_compartment, it grants manage privileges on all resources in the compartment, which may exceed what is specifically needed for data science resources only. This fails to uphold the strict principle of least privilege.

Timed practice exam

Take a 1Z0-1067-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam