1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 307 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 307

Single answer

Your company has separated environments into three compartments named DevCompartment, StageCompartment, and ProdCompartment. You need to grant the developer group (called DevTeam) the ability to fully manage resources in DevCompartment, read resources in StageCompartment, and have no access to ProdCompartment. Which set of IAM policy statements meets these requirements?

  1. A

    A) Allow group DevTeam to manage all-resources in compartment DevCompartment; Allow group DevTeam to read all-resources in compartment StageCompartment; (No policies for ProdCompartment)

  2. B

    B) Allow group DevTeam to manage instance-family in compartment DevCompartment; Allow group DevTeam to manage all-resources in compartment StageCompartment; Deny group DevTeam to all-resources in compartment ProdCompartment

  3. C

    C) Allow group DevTeam to read all-resources in tenancy; Deny group DevTeam to all-resources in compartment ProdCompartment

  4. D

    D) Allow group DevTeam to manage all-resources in compartment DevCompartment; Allow group DevTeam to manage buckets in compartment StageCompartment; (No policies for ProdCompartment)

Show answer and explanation

Correct answer: A

Explanation

In Oracle Cloud Infrastructure (OCI), if a policy does not explicitly allow access, the default behavior is to deny it. Therefore, granting no access to ProdCompartment is achieved simply by omitting any allow statement for that compartment. For more details on writing IAM policies, refer to the official OCI documentation: https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/policycore.htm

  • A. Correct.

    A) CORRECT � By explicitly allowing 'manage all-resources' in DevCompartment, the DevTeam group can create, update, and delete all resource types there. By allowing 'read all-resources' in StageCompartment, DevTeam can only view resources there. Not specifying any policy for ProdCompartment means DevTeam has no access (OCI IAM policies default to deny if not explicitly allowed). This matches the stated requirement.

  • B. Incorrect.

    B) INCORRECT � This policy allows manage access only to instances in DevCompartment (not all resource types) and manage access to all resource types in StageCompartment, which contradicts the requirement for read-only in StageCompartment. Although it tries to use a deny statement for ProdCompartment, Oracle Cloud Infrastructure policies generally default to deny unless explicitly allowed, so writing a separate deny statement is unnecessary and does not fix the over-granted access in StageCompartment.

  • C. Incorrect.

    C) INCORRECT � This policy allows all DevTeam members to read resources tenancy-wide, which exceeds the read-only requirement specifically intended for StageCompartment and potentially exposes them to resources in other compartments. The deny statement for ProdCompartment is redundant since no explicit allow statement exists for that compartment, but the main issue is the broad read access across the entire tenancy.

  • D. Incorrect.

    D) INCORRECT � This policy gives the DevTeam group management rights in DevCompartment (which aligns with requirements) but also grants manage buckets rights in StageCompartment instead of read access for all resources. This fails the requirement for read-only to all resource types in StageCompartment.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam