1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 318 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 318

Select 2

Your organization needs to allow only Compute instances in the 'Production' environment, identified by a specific tag, to read from an Object Storage bucket. Additionally, the request must originate from your on-premises network with known public IP addresses. Which two statements describe a correct approach to achieve this using dynamic groups, network sources, and tag-based access control in Oracle Cloud Infrastructure (OCI)? (Choose two)

  1. A

    Create a dynamic group with a matching rule for the 'Production' tag on the Compute instances, define a network source for your organization� public IP addresses, and then write a policy referencing both the dynamic group and network source to allow read access to the bucket.

  2. B

    Define a network source with your on-premises IP ranges and specify that network source in the policy statement along with the resource tag condition, ensuring that only instances with the specified tag and traffic from the approved network can access the bucket.

  3. C

    Create a policy that allows read access to the Object Storage bucket for the dynamic group, but do not include the network source restriction in the same policy since dynamic groups and network sources cannot be combined in a single policy statement.

  4. D

    Define a tag-based access control policy for each individual tagged Compute instance in 'Production,' requiring separate policies for every instance that needs access to the Object Storage bucket.

Show answer and explanation

Correct answers: A, B

Explanation

By using a dynamic group that matches Compute instances with the required tag, defining a network source for your on-premises IP addresses, and creating a policy that references both, you can properly control access to resources. Oracle Cloud Infrastructure (OCI) documentation (see 'Managing Dynamic Groups' and 'Using Network Sources') clarifies that you can combine dynamic group rules and network sources within the same policy condition. Tag-based access control can be applied to multiple resources using a single policy, provided they share the same tag key-value pair, which simplifies and secures your overall resource management.

  • A. Correct.

    Option 1 is correct. You can create a dynamic group that matches Compute instances based on their tag (e.g., 'Production'), define a network source with your approved on-premises IP addresses, and write a policy that includes both the dynamic group and network source condition to allow read access. This is a common and supported approach in OCI.

  • B. Correct.

    Option 2 is correct. Defining a network source using your on-premises CIDR blocks or public IP addresses and including that network source in the policy statement is the proper way to ensure traffic only originates from those addresses. Combining it with tag-based access and dynamic groups fully meets the requirement.

  • C. Incorrect.

    Option 3 is incorrect. OCI does allow combining dynamic group conditions and network source conditions within a single policy statement by using 'where request.networkSource.name = <Network_Source_Name>'. It is a misconception that they cannot be used together.

  • D. Incorrect.

    Option 4 is incorrect. Tag-based access control does not require a separate policy for each individual resource instance. A single tag-based policy referencing a specific tag key or key-value pair can apply to all resources with that same tag.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam