1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 306 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 306

Select 2

Your organization is onboarding a new partner team and wants to isolate their user management from the rest of your tenancy in Oracle Cloud Infrastructure (OCI). You create a new IAM domain called 'PartnerDomain' to host these partner users. You also plan to place all partner resources in a dedicated compartment named 'PartnerCompartment.' The partner administrators should have full control over the resources in this new compartment, without affecting any other resources. Which two actions must you take to achieve these requirements? (Choose two.)

  1. A
    1. Create the 'PartnerAdmins' group in 'PartnerDomain' and add partner user accounts to that group in the same domain.
  2. B
    1. Create a policy in the root compartment that allows the 'PartnerAdmins' group to manage all-resources in the 'PartnerCompartment'.
  3. C
    1. Create a policy in 'PartnerDomain' that allows the 'PartnerAdmins' group to manage all-resources in your tenancy� root compartment.
  4. D
    1. Create a dynamic group for partner user accounts and assign the 'PartnerCompartment' to that dynamic group.
Show answer and explanation

Correct answers: A, B

Explanation

In OCI, you manage identity by creating or using an existing domain, then creating users and groups within that domain. To control access to compartments, you must write policies at the tenancy (root compartment) level. Here, you isolate partner users in the PartnerDomain, form a group (PartnerAdmins), and then create a tenancy-level policy granting that group the rights to manage the PartnerCompartment. This design follows OCI best practices for compartment isolation and least privilege. For more details, refer to the Oracle Cloud Infrastructure Identity and Access Management documentation.

  • A. Correct.

    Option 1: CORRECT. In OCI, users and their groups must reside within the same domain. Here, you're creating a dedicated domain (PartnerDomain) and a group (PartnerAdmins) for partner users. Adding the partner user accounts to PartnerAdmins in the same domain is required to manage identities in an isolated domain.

  • B. Correct.

    Option 2: CORRECT. To grant PartnerAdmins full control over resources only in PartnerCompartment, you must create a tenancy-level (root compartment) policy. For example: 'Allow group PartnerAdmins to manage all-resources in compartment PartnerCompartment.' This ensures least privilege by targeting just that compartment.

  • C. Incorrect.

    Option 3: INCORRECT. Granting PartnerAdmins the ability to manage all-resources in the root compartment would allow them to manage resources outside the PartnerCompartment, violating the isolation requirement.

  • D. Incorrect.

    Option 4: INCORRECT. Dynamic groups are typically used to grant permissions based on resource metadata (like instance IDs, etc.), not for granting user identities compartment access. Partner user accounts need to be grouped under PartnerAdmins with a proper policy, rather than a dynamic group.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam