1Z0-1067-25 exam dumps

1Z0-1067-25 practice question 111 of 138

Oracle Cloud Infrastructure 2025 Cloud Ops Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1067-25 Question 111

Single answer

Your organization has created a dedicated compartment named 'Dev' for new application testing, and the DevOps group only needs the ability to create and manage compute instances in that compartment. You want to enforce the principle of least-privilege within Oracle Cloud Infrastructure. Which IAM policy statement meets this requirement most effectively?

  1. A

    Allow group DevOps to manage all-resources in tenancy

  2. B

    Allow group DevOps to read instance-family in compartment Dev

  3. C

    Allow group DevOps to manage instance-family in tenancy

  4. D

    Allow group DevOps to manage instance-family in compartment Dev

Show answer and explanation

Correct answer: D

Explanation

When implementing least-privilege access, you should configure Oracle Cloud Infrastructure IAM policies to allow only the minimal set of actions on the necessary resources. Granting permissions to manage only the instance-family in a specific compartment prevents over-provisioning of privileges. For more information, consult the IAM policy reference documentation in the Oracle Cloud Infrastructure Guides.

  • A. Incorrect.

    Option 1: This statement grants the DevOps group permissions to manage all resources across the entire tenancy, which goes far beyond what is needed for managing compute instances in a single compartment. This violates the principle of least privilege by providing excessive access.

  • B. Incorrect.

    Option 2: This statement only allows the DevOps group to read instance-family in compartment Dev, which does not permit creation or management actions on compute instances. It is insufficient for the team's needs.

  • C. Incorrect.

    Option 3: This statement confines the DevOps group to managing only compute instances but does so across the entire tenancy. This is more than what is necessary when they only need access to the 'Dev' compartment. It also violates the least-privilege principle.

  • D. Correct.

    Option 4: This statement precisely grants the DevOps group the ability to manage the instance-family (compute instances) strictly within the 'Dev' compartment. This aligns with the least-privilege principle by limiting administrative actions to the required scope and resources.

Timed practice exam

Take a 1Z0-1067-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam