1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 316 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 316

Single answer

Your organization requires that only on-premises IP addresses manage OCI Compute instances tagged with Department=Finance. You have created a dynamic group that includes resources with the tag key Department and value Finance, and a Network Source called FinanceNetworkSource defining the on-prem IP range. Which policy statement approach correctly ensures that only your on-prem IP addresses can manage these Finance-tagged instances?

  1. A

    Create a policy for the dynamic group that includes a condition referencing the FinanceNetworkSource, allowing management of finance-tagged resources.

  2. B

    Create a policy granting the dynamic group the manage verb on the tenancy without specifying any network source condition.

  3. C

    Use a local user group with a policy referencing the FinanceNetworkSource and include all Department=Finance resources.

  4. D

    Restrict the dynamic group to the compartment level alone without specifying any tag or network source in the policy.

Show answer and explanation

Correct answer: A

Explanation

In Oracle Cloud Infrastructure, you can combine dynamic groups, network sources, and tag conditions in IAM policies to achieve fine-grained access control. By referencing both the dynamic group (to target only resources tagged with Department=Finance) and the network source (to restrict requests to specific IP ranges), you ensure secure, tag-based and location-based access. For more information, see the OCI documentation on Tag-Based Access Control, Dynamic Groups, and Network Sources.

  • A. Correct.

    Correct. You must create a policy referencing both the dynamic group and the Network Source in the policy condition. The condition ensures that only requests originating from the IP range defined in FinanceNetworkSource can manage resources that match the dynamic group tag criteria (Department=Finance).

  • B. Incorrect.

    Incorrect. Allowing dynamic-group access to manage the tenancy without referencing the network source would permit requests from any IP address, violating the requirement to restrict access solely to on-prem addresses.

  • C. Incorrect.

    Incorrect. A local user group is not required for restricting resource access by IP address ranges tied to dynamic groups. Dynamic groups are based on resource metadata (e.g., tags), whereas user groups are for IAM principals. Mixing these would not achieve the stated objective of limiting instance management by IP range.

  • D. Incorrect.

    Incorrect. Limiting the policy to a compartment alone does not restrict IP addresses or enforce the Department=Finance tag. This would expose all resources in the compartment to any network source, failing the requirement.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam