1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 270 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 270

Select 2

Your organization is deploying Oracle Cloud Infrastructure (OCI) File Storage for an internal application that handles confidential data. You want to ensure that only specific compute instances can mount the share from a private subnet and that the data remains encrypted at rest. Which two actions should you take to meet these security requirements?

  1. A

    Use a mount target in a private subnet and configure export options to allow access only from the desired subnet or IP addresses.

  2. B

    Store the file system's encryption keys in local ephemeral storage to reduce key management overhead.

  3. C

    Leverage OCI Vault to use your own master encryption keys for data at rest in File Storage.

  4. D

    Deploy the mount target in a public subnet for more flexible network access.

Show answer and explanation

Correct answers: A, C

Explanation

To secure an OCI File Storage resource when dealing with confidential data, best practices include placing the mount target in a private subnet, restricting NFS export access to specific IP addresses or subnets, and encrypting the data at rest with either Oracle-managed or customer-managed keys through OCI Vault. Refer to the official File Storage documentation in the Oracle Cloud Infrastructure Library for details on configuring export options, subnets, and encryption settings.

  • A. Correct.

    Option 1 is correct. Placing your mount target in a private subnet prevents public access, and using export options or Access Control Lists (ACLs) restricts mounts to trusted IP addresses or subnets. This aligns with best practices for securing OCI File Storage.

  • B. Incorrect.

    Option 2 is incorrect. Storing encryption keys in local ephemeral storage is not a recommended or supported method of managing keys in OCI. Keys should be managed through Oracle-managed keys by default or via OCI Vault for customer-managed keys.

  • C. Correct.

    Option 3 is correct. OCI Vault allows you to bring your own master keys to encrypt data at rest, giving you more control over key rotation and security policies. This provides an additional layer of security beyond Oracle-managed keys.

  • D. Incorrect.

    Option 4 is incorrect. Placing the mount target in a public subnet exposes it to the internet and increases the risk of unauthorized access, which goes against the requirement to restrict access to a private subnet.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam