1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 265 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 265

Select 2

You are configuring an Oracle Cloud Infrastructure (OCI) File Storage system to store highly confidential research data. The system must be accessible only by a specific group of compute instances in a private subnet, and all data should be encrypted with a customer-managed key to meet strict compliance requirements. Which two actions should you take to fulfill these needs?

  1. A

    Deploy the File Storage system in a public subnet so it� accessible to all compute instances in your VCN.

  2. B

    Create an export with a restricted NFS export option allowing only the private subnet's CIDR block.

  3. C

    Use a Vault-based customer-managed key in OCI Key Management for file system encryption.

  4. D

    Mount the file system to a public IP address for easier remote access and management.

  5. E

    Use only default Oracle-managed keys, since customer-managed keys are not supported by File Storage.

Show answer and explanation

Correct answers: B, C

Explanation

To secure confidential data in File Storage, you should first limit NFS export access to authorized subnets only, which prevents unauthorized hosts from connecting. Additionally, using a Vault-based customer-managed key is key to fulfilling compliance requirements for encryption at rest. Refer to OCI documentation on File Storage and Key Management for details on configuring export options (using Access Control Lists or restricting CIDR blocks) and setting up customer-managed keys in Vault.

  • A. Incorrect.

    Option 1: INCORRECT. Deploying the file system in a public subnet goes against the goal of restricting access to specific private instances. Storing confidential data in a public subnet increases the risk of unauthorized access.

  • B. Correct.

    Option 2: CORRECT. Restricting the NFS export to the private subnet's CIDR block ensures that only the compute instances within that subnet can mount and read/write data.

  • C. Correct.

    Option 3: CORRECT. Attaching a Vault-based customer-managed key to the File Storage service guarantees data at rest is protected using a key you control, fulfilling the compliance requirement for customer-managed encryption.

  • D. Incorrect.

    Option 4: INCORRECT. Mounting the file system to a public IP address defeats the purpose of having a private subnet restriction, as it could allow external access.

  • E. Incorrect.

    Option 5: INCORRECT. OCI File Storage does support customer-managed keys, so relying on Oracle-managed keys alone does not meet the specific policy requirement for using a customer-managed key.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam