1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 300 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 300

Single answer

Your organization has onboarded a new group of developers who need to provision and manage only Compute instances in a specific compartment, without being able to make changes to networking or billing resources. What is the best way to configure Identity and Access Management (IAM) to meet these requirements while maintaining least privilege in Oracle Cloud Infrastructure?

  1. A

    Create a new group for the developer team, assign each developer to that group, and write a policy granting only the required permissions to the specific compartment

  2. B

    Add the developers to your existing Administrators group so they inherit all current privileges

  3. C

    Use a dynamic group that grants full resource management privileges across all compartments to any user with a specific attribute

  4. D

    Modify the built-in Administrator policy to remove permissions for networking and billing operations

Show answer and explanation

Correct answer: A

Explanation

In Oracle Cloud Infrastructure, the best practice is to utilize groups and policies to grant fine-grained access. By creating a group specifically for developers and writing a policy scoped to a single compartment, you ensure they have the least privilege necessary�only the ability to manage Compute instances. Refer to the OCI IAM documentation (https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/policies.htm) for details on crafting compartment-scoped policies and adhering to the principle of least privilege.

  • A. Correct.

    Correct. This approach ensures developers have precisely the permissions required for managing Compute resources in their designated compartment. By crafting a policy scoped to a single compartment with specific verbs (like manage or use) for Compute, you adhere to the principle of least privilege.

  • B. Incorrect.

    Incorrect. Adding the developers to the Administrators group gives them broad permissions, including tasks that go beyond spinning up Compute instances, violating least privilege guidelines.

  • C. Incorrect.

    Incorrect. Dynamic groups typically apply to resources like instances or services matching certain attributes, not to specific sets of users. Additionally, granting full resource management privileges across all compartments contradicts the requirement of restricting them to a single compartment.

  • D. Incorrect.

    Incorrect. Modifying the default Administrator policy is not a recommended practice, as it might unintentionally restrict necessary global administrative capabilities, and does not address compartment scoping cleanly.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam