1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 231 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 231

Single answer

Your organization needs to store confidential project data in an Oracle Cloud Infrastructure (OCI) Object Storage bucket. The security team requires that (1) only a specific IAM group of internal engineers can read or write objects in that bucket, (2) data must be encrypted at rest with minimal operational overhead, and (3) external vendors should occasionally be given temporary access to specific objects. Which strategy best meets these requirements?

  1. A

    Create a private bucket, use an IAM policy to allow only the engineer group to access it, rely on default OCI-managed server-side encryption, and use pre-authenticated requests for external vendors.

  2. B

    Create a public bucket and rely on object ACLs to restrict read/write operations, enable OCI's server-side encryption, and share objects through a public URL for vendors.

  3. C

    Use client-side encryption exclusively and allow access to the bucket for all employees, but disable pre-authenticated requests to manage external sharing.

  4. D

    Set up a bucket-level access list (ACL) allowing read/write for the engineer group, disable server-side encryption to minimize overhead, and require each vendor to create their own IAM user.

Show answer and explanation

Correct answer: A

Explanation

In OCI Object Storage, securing sensitive data involves making the bucket private, granting proper IAM policies to specific groups, and leveraging server-side encryption with Oracle-managed keys. This setup meets encryption-at-rest requirements and streamlines administration. When external partners briefly need to download or upload objects, pre-authenticated requests are a lightweight, secure approach. Refer to the official OCI documentation on Object Storage security, IAM policies, and pre-authenticated requests for best practices.

  • A. Correct.

    Option 1 is correct. By making the bucket private, you ensure it is not openly accessible. Using an IAM policy to explicitly allow only the engineer group maintains proper internal access control. OCI automatically encrypts all objects at rest with OCI-managed keys by default, satisfying the minimal operational overhead requirement. Pre-authenticated requests allow granting time-limited access to external vendors without creating new IAM users.

  • B. Incorrect.

    Option 2 is incorrect. A public bucket is visible to everyone on the internet, which violates the requirement of restricting access to only specific engineers. Object ACLs alone are not recommended as the primary security mechanism in OCI, especially for highly confidential data.

  • C. Incorrect.

    Option 3 is incorrect. While client-side encryption can add security, it increases operational overhead and does not leverage OCI-managed server-side encryption. Also, allowing bucket access for all employees does not satisfy the requirement of limiting access to a specific engineer group.

  • D. Incorrect.

    Option 4 is incorrect. OCI recommends using IAM policies rather than bucket ACLs for robust control. Disabling server-side encryption undermines security requirements. Requiring each vendor to create their own IAM user for occasional access is unnecessarily complex and not the best practice when pre-authenticated requests are available.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam