1Z0-1067-25 exam dumps

1Z0-1067-25 practice question 98 of 138

Oracle Cloud Infrastructure 2025 Cloud Ops Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1067-25 Question 98

Select 2

You are tasked with improving your tenancy� security posture by ensuring that all newly created block volumes in the 'Prod' compartment are encrypted using customer-managed keys stored in Oracle Cloud Infrastructure (OCI) Vault. In addition, you want to prevent administrators from creating block volumes with Oracle-managed default encryption keys. Which combination of actions should you take to achieve this goal?

  1. A

    Create and assign a security zone to the 'Prod' compartment with a recipe rule enforcing the use of customer-managed keys for block volumes.

  2. B

    Write an IAM policy that denies the creation of block volumes if the request does not specify the custom Vault key.

  3. C

    Use Cloud Guard to detect block volumes encrypted by Oracle-managed keys and automatically disable them on creation.

  4. D

    Implement a dynamic group for provisioning block volumes, assuming it will override default encryption automatically with the custom key.

Show answer and explanation

Correct answers: A, B

Explanation

To enforce a strict security posture for block volumes in OCI, you can combine the Security Zones feature�assigning a security zone recipe to the 'Prod' compartment that mandates the use of customer-managed encryption keys�with an IAM policy that denies creation unless the correct Vault key is specified. This two-pronged approach prevents accidental or intentional creation of block volumes using Oracle-managed default encryption keys, aligning with best practices for securing sensitive data. For reference, see Oracle� documentation on Security Zones (https://docs.oracle.com/en-us/iaas/Content/Security/Reference/securityzone.htm) and IAM Policies with Conditions (https://docs.oracle.com/en-us/iaas/Content/Identity/Tasks/managingcompartments.htm).

  • A. Correct.

    Correct: Security zones in OCI can enforce a set of security policies, including the requirement that block volumes be created with customer-managed encryption keys instead of Oracle-managed keys. By associating the 'Prod' compartment with such a security zone, you ensure that non-compliant operations are blocked.

  • B. Correct.

    Correct: An IAM policy can contain conditions that specifically allow or deny a request based on whether a custom Vault key is used. This helps ensure that block volumes created in the 'Prod' compartment must specify your customer-managed key, effectively blocking attempts to use Oracle-managed default keys.

  • C. Incorrect.

    Incorrect: Cloud Guard can detect and report on non-compliant resources and possibly initiate workflows for remediation. However, it does not directly block or 'automatically disable' block volumes at the moment of creation. It is typically used for monitoring, alerting, and orchestrating corrective actions rather than outright preventing resource creation.

  • D. Incorrect.

    Incorrect: A dynamic group alone does not enforce which encryption key must be used. Dynamic groups are used in IAM policies to define which resources or users have which privileges, but they do not themselves override encryption settings. You still need explicit security zone rules or IAM policy conditions to enforce the custom Vault key requirement.

Timed practice exam

Take a 1Z0-1067-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam