1Z0-1067-25 exam dumps

1Z0-1067-25 practice question 112 of 138

Oracle Cloud Infrastructure 2025 Cloud Ops Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1067-25 Question 112

Single answer

Your organization has a new compartment named 'ProjectAlpha' in Oracle Cloud Infrastructure (OCI). The ProjectAlpha_Developers group needs to create, update, and terminate compute instances in that compartment without having access to manage networking or other types of resources. Which policy statement best enforces the principle of least privilege in this scenario?

  1. A
    1. Allow group ProjectAlpha_Developers to manage all-resources in compartment ProjectAlpha
  2. B
    1. Allow group ProjectAlpha_Developers to manage instance-family in compartment ProjectAlpha
  3. C
    1. Allow group ProjectAlpha_Developers to inspect all-resources in compartment ProjectAlpha
  4. D
    1. Allow group ProjectAlpha_Developers to manage instance-family in tenancy
Show answer and explanation

Correct answer: B

Explanation

In OCI IAM, �manage instance-family� is the correct verb to grant the necessary permissions to create, update, and delete compute instances while restricting access to other resource types. Granting broader permissions (e.g., manage all-resources) or applying permissions at the tenancy level exposes more than the minimum required, contrary to least-privilege principles. Refer to OCI documentation on writing IAM policies for further guidance on applying these permissions at a granular level.

  • A. Incorrect.

    Option 1 is incorrect because it grants privileges to manage all resources in the compartment, including networking, storage, and other services, which violates least-privilege principles.

  • B. Correct.

    Option 2 is correct. The �manage instance-family� verb in OCI policies allows creation, update, and termination of instances without broader permissions, thus aligning with least-privilege best practices.

  • C. Incorrect.

    Option 3 is incorrect because �inspect� only allows viewing resources without the ability to create or update them. The developers would not be able to create or modify instances with this policy.

  • D. Incorrect.

    Option 4 is incorrect because it applies to the entire tenancy rather than just ProjectAlpha, providing more access than necessary and violating least-privilege guidelines.

Timed practice exam

Take a 1Z0-1067-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam