1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 233 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 233

Select 3

You are the lead architect for a financial services firm that uses Oracle Cloud Infrastructure (OCI) Object Storage to store sensitive customer documents. You also need to allow the marketing department to temporarily upload promotional files to the same bucket, but ensure they cannot access customer data. Which THREE configurations should you implement to fulfill these security and access requirements?

  1. A

    Enable server-side encryption using Oracle-managed keys for all objects in the bucket.

  2. B

    Set the bucket to Public, then rely on IAM tags to restrict operations on sensitive objects.

  3. C

    Create an IAM policy granting marketing employees permission to upload objects only under a specific prefix without read access to other objects.

  4. D

    Keep the bucket private and generate time-bound pre-authenticated requests for marketing employees to upload files.

  5. E

    Give the marketing department the Object Storage Administrator policy across the entire tenancy.

Show answer and explanation

Correct answers: A, C, D

Explanation

In OCI, Object Storage security hinges on correct encryption mechanisms and precise IAM controls. For data at rest, server-side encryption with Oracle-managed keys is a best practice and does not require additional key management from users. Fine-grained IAM policies define who can read, write, or list objects. Leveraging prefixes and compartment-wide (or bucket-specific) policies lets you isolate sensitive data from generic uploads. If you need to grant time-limited access to external teams or departments�like marketing�pre-authenticated requests offer a secure and temporary means of uploading objects without making the entire bucket public. Refer to the official Oracle Cloud Infrastructure documentation on Object Storage Security (docs.oracle.com/en/cloud) for detailed guidance on encryption and policy configuration.

  • A. Correct.

    Correct. Enabling server-side encryption with Oracle-managed keys ensures that all data in the bucket is protected at rest. This is a straightforward way to secure sensitive data without requiring additional configuration by end users.

  • B. Incorrect.

    Incorrect. Making the bucket public grants anyone on the internet access to the bucket unless further restrictions are configured. Relying solely on IAM tags for sensitive data introduces unnecessary risk and potential misconfigurations.

  • C. Correct.

    Correct. By tailoring an IAM policy so that marketing employees can only upload to a specific prefix, you securely separate their uploads from sensitive data. This policy approach also ensures they do not have read access to other objects in the bucket.

  • D. Correct.

    Correct. Pre-authenticated requests (PARs) can be created with an expiration date, providing temporary write access for the marketing department. This keeps the bucket private and still allows controlled, time-bound uploads.

  • E. Incorrect.

    Incorrect. Assigning the Object Storage Administrator policy broadly would give the marketing department unrestricted access to all Object Storage resources in the tenancy, which is excessive and violates the principle of least privilege.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam