1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 295 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 295

Select 2

You have deployed a web application on an OCI compute instance that needs to upload images to an Object Storage bucket residing in a separate compartment. The security policies in your organization require that no credentials are stored in the application code. Which two steps should you take to ensure that the instance can securely access only that specific bucket?

  1. A

    A. Create a dynamic group that includes the instance based on its OCID and write a policy granting that dynamic group access to the Object Storage bucket in the other compartment.

  2. B

    B. Add the compute instance to a local user group and grant that user group the required permissions in the tenancy policy.

  3. C

    C. Store the Object Storage credentials in the web application code to seamlessly authenticate and upload the images.

  4. D

    D. Use instance principals so that your compute instance can authenticate itself automatically, combine it with a policy granting read-write access to the bucket.

Show answer and explanation

Correct answers: A, D

Explanation

To securely grant a compute instance access to specific resources, you should use instance principals combined with dynamic groups and carefully crafted policies. These features allow the instance to authenticate itself without storing credentials in the code, while implementing the principle of least privilege. Refer to Oracle Cloud Infrastructure documentation for detailed instructions on configuring instance principals and dynamic group policies.

  • A. Correct.

    A. CORRECT: Using a dynamic group for the instance and creating a policy that grants access to the required Object Storage bucket is the recommended approach. The policy can reference the specific compartment and resource, ensuring least privilege.

  • B. Incorrect.

    B. INCORRECT: OCI does not support directly adding compute instances to a traditional user group. Groups in OCI Identity and Access Management are for human users or federated identities, not compute resources.

  • C. Incorrect.

    C. INCORRECT: Storing credentials in the application code violates security best practices, as it risks exposing credentials. OCI instead provides secure methods like dynamic groups and instance principals to avoid embedding credentials.

  • D. Correct.

    D. CORRECT: Instance principals allow the compute instance to authenticate and gain limited access based on policies you define, without embedding credentials. In combination with a policy granting access to a specific bucket, this is a secure and practical solution.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam