1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 303 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 303

Select 3

Your company has created a new IAM domain called 'R&D-Domain' in Oracle Cloud Infrastructure (OCI) to isolate resources for a research and development project. You have also created an 'R&D-Compartment' in that domain. You need to ensure that only a specific group of new R&D users can provision and manage compute resources in the 'R&D-Compartment,' without granting them access to other compartments. Which three steps must you perform to accomplish this requirement?

  1. A

    Create the 'R&D-Compartment' within the 'R&D-Domain' to isolate project resources.

  2. B

    Define a new group in the 'R&D-Domain' and add all R&D users to that group.

  3. C

    Create a policy in the root (primary) domain to manage compute resources in the 'R&D-Compartment.'

  4. D

    Create a policy in the 'R&D-Domain' granting this group the 'manage compute-family' permission on the 'R&D-Compartment.'

  5. E

    Move the 'R&D-Domain' under a different domain that already has administrator privileges.

Show answer and explanation

Correct answers: A, B, D

Explanation

To properly secure resources with Oracle Cloud Infrastructure IAM, you must create compartments to organize your resources and apply policies at the compartment or domain level. In this scenario, creating the 'R&D-Compartment' inside the 'R&D-Domain' and defining a local group with policies that grant the necessary permissions isolates R&D resources while granting users the ability to provision and manage compute resources. For more details, refer to Oracle� IAM documentation on managing IAM domains, compartments, users, and policies.

  • A. Correct.

    Correct: Creating the 'R&D-Compartment' in the 'R&D-Domain' is essential to isolate the R&D project� resources and help with fine-grained access control. Compartments are logical containers for organizing and controlling access to resources.

  • B. Correct.

    Correct: You must create a local group within the newly created 'R&D-Domain' and add all R&D users to it. Group membership is required for applying policies that regulate what these users can do in a specific compartment.

  • C. Incorrect.

    Incorrect: While creating a policy in the root domain (the primary IAM domain) can be valid for broad access, it does not help isolate permissions strictly within the new 'R&D-Domain' for this R&D group. You typically create policies in the same domain or the root compartment if you want cross-domain access, but here you only need local access within 'R&D-Domain.'

  • D. Correct.

    Correct: To let the group manage compute resources in the 'R&D-Compartment,' you need to create a policy within the scope of the 'R&D-Domain' granting them 'manage compute-family' (or the proper verbs such as 'use,' 'inspect,' etc. depending on needs). This policy restricts the group� access to only the 'R&D-Compartment' in the 'R&D-Domain.'

  • E. Incorrect.

    Incorrect: Moving the 'R&D-Domain' under another domain that has broader administrator privileges could inadvertently grant the R&D users permissions beyond their specific R&D compartment, violating the principle of least privilege.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam