1Z0-1067-25 exam dumps

1Z0-1067-25 practice question 92 of 138

Oracle Cloud Infrastructure 2025 Cloud Ops Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1067-25 Question 92

Select 2

Your organization plans to grant new employees from an external SAML-based Identity Provider (IdP) access to only the development compartment in Oracle Cloud Infrastructure (OCI). As the Cloud Ops Professional, you need to configure a secure, minimal-privilege federation setup so these employees can sign in via single sign-on (SSO) and access specific resources. Which TWO steps are required to achieve this goal?

  1. A

    Create an Identity Provider in OCI that references the metadata from the external SAML IdP.

  2. B

    Create local OCI user accounts for each new employee and assign them to a local group.

  3. C

    Create an OCI group, map the external IdP group to it, and apply a policy granting minimal access to the development compartment.

  4. D

    Configure a dynamic group for federated users based on their email domain, then attach a policy for compartment access.

  5. E

    Enable multi-factor authentication for all federated logins at the external IdP and pass these credentials to OCI.

Show answer and explanation

Correct answers: A, C

Explanation

Federating with an external SAML IdP lets external users sign in without creating separate OCI user accounts for each individual. To properly configure federation, you must first register a SAML Identity Provider in OCI using metadata from your external IdP, then map IdP groups to OCI groups and attach policies to define compartment-level access. According to Oracle� best practices (refer to official IAM documentation), this ensures centralized identity management, minimal overhead in user account creation, and adherence to least-privilege principles for secure resource access.

  • A. Correct.

    Correct. Establishing an Identity Provider in OCI and configuring it with the external SAML IdP metadata is a required step for federation. This tells OCI how to trust and authenticate identities coming from the external SAML provider.

  • B. Incorrect.

    Incorrect. One of the benefits of federation is that you do not have to create and manage individual user accounts in OCI. Instead, users authenticate through the external IdP, and only their federated attributes (like group memberships) are passed to OCI.

  • C. Correct.

    Correct. You must create an ODI (OCI) group and map the external IdP group(s) to this OCI group. Applying an appropriate policy to that OCI group is how you grant the necessary privileges�such as access to the development compartment�while keeping permissions restricted.

  • D. Incorrect.

    Incorrect. Dynamic groups in OCI are most often used for resources (like compute instances) to access other OCI services. They are not intended to manage human federated users or their group memberships, so this step would not be applicable in this scenario.

  • E. Incorrect.

    Incorrect. While enabling multi-factor authentication (MFA) at the IdP is a strong security best practice, it is not a required step to create and assign minimal-privilege access in OCI. Federated authentication can work even if MFA is not configured, although MFA is highly recommended for enhanced security.

Timed practice exam

Take a 1Z0-1067-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam