1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 232 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 232

Single answer

A financial services company wants to store highly sensitive transaction records in an OCI Object Storage bucket. They need to ensure that the data is always encrypted at rest, and the security team must directly control and manage the encryption keys. Which approach should they implement to meet these requirements?

  1. A

    Rely on OCI� default server-side encryption using Oracle-managed keys without any additional configuration

  2. B

    Implement client-side encryption using a custom, on-premises key management system and upload the encrypted data to Object Storage

  3. C

    Create a Customer-Managed Key (CMK) in OCI Vault and configure the Object Storage bucket to use that key for encryption

  4. D

    Enable a Pre-Authenticated Request (PAR) for the bucket and rely on HTTPS to encrypt data in transit

Show answer and explanation

Correct answer: C

Explanation

In OCI, Object Storage buckets are encrypted at rest by default using Oracle-managed keys (server-side encryption). However, some organizations require direct control over encryption keys for compliance or regulatory purposes. In such cases, configuring a bucket to use a Customer-Managed Key (CMK) in OCI Vault allows the security team to manage, rotate, and revoke keys as needed. For more details, refer to the 'Using Customer-Managed Keys with Object Storage' section in the Oracle Cloud Infrastructure documentation.

  • A. Incorrect.

    Option A is incorrect because relying solely on Oracle-managed keys does not allow the security team to control key rotation or ownership. Although it encrypts data at rest by default, it does not meet the requirement for direct key control.

  • B. Incorrect.

    Option B is incorrect because while client-side encryption can protect data, it adds complexity with key management living outside OCI. The question specifically asks for a solution within OCI that the security team can manage directly. A custom on-prem solution doesn�t leverage OCI� built-in capabilities for easy rotation and auditing.

  • C. Correct.

    Option C is correct. By creating a private key in OCI Vault and assigning it as a customer-managed key for the Object Storage bucket, the security team gains full control over key management, including rotation and access policies. This satisfies both the encryption at rest requirement and the direct key ownership requirement.

  • D. Incorrect.

    Option D is incorrect because using a PAR only helps secure temporary public access and ensures data travels over HTTPS. It does not address key ownership and management for encryption at rest.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam