1Z0-1067-25 exam dumps

1Z0-1067-25 practice question 94 of 138

Oracle Cloud Infrastructure 2025 Cloud Ops Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1067-25 Question 94

Select 2

You have a new analytics team that needs to programmatically read and write objects to a production Object Storage bucket. The production environment mandates minimal manual credentials, so you want to avoid generating and distributing long-lived user credentials whenever possible. The team plans to run these data operations on a compute instance within the same VCN. Which TWO configuration steps should you perform to ensure secure access to Object Storage following OCI best practices?

  1. A

    Create an OCI user for each team member and generate an Object Storage token for each user.

  2. B

    Create a dynamic group referencing the compute instance� OCID, then write an IAM policy allowing that dynamic group to manage objects in the production compartment.

  3. C

    Assign the Storage_Administrator role at the tenancy level to all members of the analytics team.

  4. D

    Configure an Instance Principal on the compute instance, then use the instance principal token to access the Object Storage bucket.

Show answer and explanation

Correct answers: B, D

Explanation

Following OCI best practices for identity and security involves giving the least amount of privilege necessary while minimizing long-lived credentials. Dynamic groups allow policies to be written for specific instances or groups of instances, and Instance Principals enable secure, credential-less access from a compute resource to OCI services. Reference the OCI documentation on Dynamic Groups and Instance Principals for detailed guidance on securely configuring access (https://docs.oracle.com/en-us/iaas/Content/Identity/Tasks/managingdynamicgroups.htm and https://docs.oracle.com/en-us/iaas/Content/Identity/Tasks/managingcredentials.htm).

  • A. Incorrect.

    Option 1 is incorrect. Creating individual OCI users and generating Object Storage tokens increases credential exposure and management overhead. This approach does not align with the requirement to minimize manual credentials.

  • B. Correct.

    Option 2 is correct. Dynamic groups allow you to target resources (like compute instances) based on their OCID, then create an IAM policy granting only the permissions needed to manage objects in the production compartment. This follows least-privilege best practices and avoids manual credentials.

  • C. Incorrect.

    Option 3 is incorrect. Assigning a broad Storage_Administrator role at the tenancy level is overly permissive and violates the principle of least privilege, as it gives the team access to all Object Storage resources across the tenancy.

  • D. Correct.

    Option 4 is correct. Configuring an Instance Principal lets the compute instance authenticate directly with OCI services without storing traditional user credentials. The instance principal token can then be used to securely access the Object Storage bucket.

Timed practice exam

Take a 1Z0-1067-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam