1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 291 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 291

Select 2

Your team just created a DevOps group in Oracle Cloud Infrastructure (OCI). They need to provision and manage compute instances in the 'DevCompartment' while having only read access to the networking resources within the same compartment. Which two IAM policy statements would meet these requirements?

  1. A

    Allow group DevOps to manage instance-family in compartment DevCompartment

  2. B

    Allow group DevOps to manage all-resources in compartment DevCompartment

  3. C

    Allow group DevOps to read virtual-network-family in compartment DevCompartment

  4. D

    Allow group DevOps to use virtual-network-family in compartment DevCompartment

Show answer and explanation

Correct answers: A, C

Explanation

To meet the scenario requirements, you must allow the DevOps group to manage only the compute resource set (referred to as �instance-family�) and grant them read-only permissions on the networking resource set (�virtual-network-family�). Policy statements are very specific in OCI IAM: �manage� allows full control (create, update, delete) for that resource type, while �read� restricts privileges to viewing details only. Refer to Oracle Cloud Infrastructure Identity and Access Management documentation for more on policy statements and their scopes: https://docs.oracle.com/en-us/iaas/Content/Identity/Reference/policyreference.htm

  • A. Correct.

    Correct. �manage instance-family� gives the DevOps group the permissions to create, update, and delete compute instances (and related functions) within DevCompartment. It specifically targets compute resources, which aligns with the requirement to spin up compute instances.

  • B. Incorrect.

    Incorrect. �manage all-resources� grants full control over all resource types in the compartment, including networking. This is broader than required, going against the need for read-only access to networking resources.

  • C. Correct.

    Correct. �read virtual-network-family� restricts the group� networking access to read-only operations. This satisfies the requirement for limited visibility without the ability to modify or create networking components.

  • D. Incorrect.

    Incorrect. �use virtual-network-family� grants more privileges than read, allowing actions such as attaching and detaching resources from the network. This exceeds the read-only requirement.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam