OracleProfessional level1Z0-1104-25

1Z0-1104-25 exam dumps: 174 free OCI 2025 Security Professional practice questions

Free 1Z0-1104-25 practice questions for the Oracle Cloud Infrastructure 2025 Security Professional exam, with the correct answer and a full explanation for every option. Read the first 10 below, browse all 174 by number, or take a timed practice exam.

Question bank last updated May 2025

Free 1Z0-1104-25 practice questions

Questions 1 to 10 of 174

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

1Z0-1104-25 Question 1

Select 3

Your organization is migrating its financial application to Oracle Cloud Infrastructure (OCI) and has created separate compartments for development, testing, and production. As the security engineer, you want to ensure compliance with OCI� shared responsibility model. Which of the following tasks do you need to handle as the customer to maintain a secure environment?

  1. A

    Managing security lists and network security group rules for compute subnets

  2. B

    Applying operating system patches and updates on your compute instances

  3. C

    Overseeing physical security controls at OCI� data centers

  4. D

    Enforcing compartment-based IAM policies to restrict user access

  5. E

    Relying on automatic block volume encryption at rest provided by OCI, requiring no further action

Show answer and explanation

Correct answers: A, B, D

Explanation

In OCI� shared responsibility model, Oracle secures the underlying cloud infrastructure (e.g., physical servers, facilities, and hypervisors), while customers remain responsible for tasks such as configuring access controls, applying patches, and managing IAM policies in their tenancies. For more details, refer to the OCI documentation on 'Security in OCI' and the 'Shared Security Model' guidelines.

  • A. Correct.

    Managing security lists and network security group rules is the customer� responsibility, as you must configure network-based access controls to prevent unauthorized traffic to your instances. This is part of the �security in the cloud� under OCI� shared responsibility model.

  • B. Correct.

    Applying operating system patches and updates on your compute instances is a key customer responsibility, since Oracle manages the underlying infrastructure but not the guest OS. You control how frequently and when your servers are patched.

  • C. Incorrect.

    Overseeing physical security controls at OCI� data centers is Oracle� responsibility. Oracle manages data center physical security such as surveillance, access control, and facility hardening under the �security of the cloud� portion.

  • D. Correct.

    Enforcing compartment-based IAM policies is the customer� responsibility. Configuring appropriate IAM policies ensures the right users or groups have sufficient, but not excessive, privileges in each compartment.

  • E. Incorrect.

    While OCI automatically encrypts block volumes at rest, as a customer you do not need to take extra steps to enable this feature by default. However, creation and rotation of your own customer-managed keys (if you choose to go beyond default encryption) is an additional optional responsibility.

1Z0-1104-25 Question 2

Select 2

Your organization has discovered that certain Object Storage buckets in OCI are publicly accessible and some network security rules are overly permissive. The security team wants a solution that continuously detects misconfigurations and can automatically remediate them. Which TWO OCI services can you combine to achieve both real-time visibility and automated corrective actions for these security issues?

  1. A

    Cloud Guard

  2. B

    Data Safe

  3. C

    Security Zones

  4. D

    Vault

  5. E

    Vulnerability Scanning Service

Show answer and explanation

Correct answers: A, C

Explanation

Cloud Guard provides continuous security monitoring and automated remediation via responder rules, making it an excellent choice for detecting and resolving issues like publicly exposed buckets or permissive network rules. Security Zones enforce secure configurations from the start, blocking high-risk actions in designated compartments. Together, these two services address real-time detection, enforcement, and auto-remediation of misconfigurations. Refer to Oracle� Cloud Guard and Security Zones documentation for best practices and configuration details.

  • A. Correct.

    Cloud Guard is correct because it monitors resources continuously for security risks and can automate remediation through responder rules, making it ideal for detecting and fixing exposed buckets or permissive security rules.

  • B. Incorrect.

    Data Safe is incorrect because it primarily focuses on database security features like user assessment, data discovery, and activity auditing. It does not provide the continuous infrastructure misconfiguration detection and automated remediation you need for Object Storage buckets or network security configurations.

  • C. Correct.

    Security Zones is correct because it enforces security best practices from the outset. If a compartment is designated as a Security Zone, OCI prevents many misconfigurations (such as creating a public bucket) from ever happening. Used together with Cloud Guard, you get both enforcement and real-time detection/remediation.

  • D. Incorrect.

    Vault is incorrect because it provides centralized key management and supports data encryption, but it does not continuously monitor or remediate misconfigurations in OCI resources.

  • E. Incorrect.

    Vulnerability Scanning Service is incorrect because it focuses on scanning compute instances and load balancers for known vulnerabilities and open ports, rather than misconfigured Object Storage buckets or overly permissive network rules.

1Z0-1104-25 Question 3

Select 2

Your organization is migrating critical workloads to Oracle Cloud Infrastructure (OCI). You have been tasked with setting up the initial security configuration to align with the principle of least privilege. Which two actions should you prioritize to ensure that users only have access to the resources they need and to reduce the overall attack surface?

  1. A

    Create a single compartment for all resources and assign broad administrative privileges to administrators for easier maintenance

  2. B

    Organize resources into multiple compartments based on different functional or environment-specific requirements

  3. C

    Define and apply IAM policies that grant each user group only the permissions necessary to perform their tasks

  4. D

    Enable all advanced security features like Web Application Firewall (WAF) and Bastion by default, regardless of the environment� actual requirements

Show answer and explanation

Correct answers: B, C

Explanation

Implementing compartments and defining targeted IAM policies from the outset aligns with OCI best practices for least privilege. By segmenting resources and granting minimal but sufficient permissions, you reduce the potential blast radius of any security breach. Oracle� documentation emphasizes compartmentalization and precise policy management to maintain strong oversight of resource access while avoiding unnecessary privileges.

  • A. Incorrect.

    Incorrect. Consolidating all resources into a single compartment and assigning broad privileges contradicts the principle of least privilege. This approach increases the risk of unauthorized access if an administrator account is compromised, as it potentially grants them control over all resources.

  • B. Correct.

    Correct. Configuring separate compartments for different functional or environment-specific groups (e.g., Production, Development, Finance) is a best practice. Compartments help segment resources, allowing security boundaries to be properly enforced through policies.

  • C. Correct.

    Correct. IAM policies control who can access which resources and how. By granting only the necessary privileges to each group, you reduce the risk of accidental or malicious activity on resources outside a team� scope.

  • D. Incorrect.

    Incorrect. While enabling security features like WAF or Bastion when appropriate is important, turning them on indiscriminately without evaluating specific requirements can lead to unnecessary costs and complexity. Not all environments require every advanced security feature by default.

1Z0-1104-25 Question 4

Select 2

An organization discovers that a developer inadvertently has broad access to resources across multiple OCI compartments. To adhere to the principle of least privilege and properly isolate sensitive workloads, which two actions should the security administrator take going forward?

  1. A

    Create and maintain separate compartments for each environment or team to isolate resources

  2. B

    Grant tenancy-wide policy permissions to all resources for faster development

  3. C

    Restrict IAM policies to ensure only the required groups or roles can access each compartment

  4. D

    Use Oracle Cloud Infrastructure Logging to track and block all access attempts

Show answer and explanation

Correct answers: A, C

Explanation

In OCI, maintaining separate compartments and using narrowly scoped IAM policies are fundamental steps in implementing least privilege. Compartments logically group resources, while policies specify precisely who can access them. Refer to Oracle documentation on 'OCI Compartments and IAM Policies Best Practices' for more guidance on defining appropriate access boundaries.

  • A. Correct.

    Correct. Compartmentalizing resources according to environment or team helps maintain strict boundaries and enforces the principle of least privilege by minimizing unnecessary access.

  • B. Incorrect.

    Incorrect. Tenancy-wide policy permissions are too broad and contradict least-privilege principles. It allows access beyond what is required for specific tasks.

  • C. Correct.

    Correct. Granular IAM policies that grant privileges only to the necessary compartments and resources ensure that users cannot access data or services beyond their role requirements.

  • D. Incorrect.

    Incorrect. Logging provides detailed records of system events and user actions, but it does not inherently block or limit access. It is primarily used for auditing and troubleshooting, not for controlling resource isolation.

1Z0-1104-25 Question 5

Single answer

You have created multiple compartments to isolate resources for different teams in your OCI tenancy. You want to grant a new developer permission to create and manage Compute resources only in the 'Development' compartment while restricting them to read-only access to logs in a separate 'Logging' compartment. Which solution best enforces the principle of least privilege in this scenario?

  1. A

    Create a single group for all developers and grant it full administrative access to every compartment.

  2. B

    Place the developer in a dedicated group and write an IAM policy that allows 'manage' on Compute in the Development compartment and 'read' on logs in the Logging compartment.

  3. C

    Add the developer directly to the Administrators group, granting them global administrative privileges across all resources.

  4. D

    Create a dynamic group based on the developer's user credentials and grant that group full permissions on the Development and Logging compartments.

Show answer and explanation

Correct answer: B

Explanation

In OCI, best practices recommend using the principle of least privilege by assigning narrowly scoped policies to groups. By creating a group specifically for the developer and writing an IAM policy with compartment-scoped permissions, you ensure they can only perform the required actions (manage Compute in Development, read logs in Logging). Reference: Oracle Cloud Infrastructure Documentation � Identity and Access Management Best Practices.

  • A. Incorrect.

    Incorrect. Granting full administrative access to every compartment violates least privilege and unnecessarily broadens access.

  • B. Correct.

    Correct. Creating a dedicated group and applying an IAM policy that grants only the necessary permissions to specific compartments aligns with the principle of least privilege.

  • C. Incorrect.

    Incorrect. Adding a user to the Administrators group gives universal permissions, which exceeds minimal required privileges and poses security risks.

  • D. Incorrect.

    Incorrect. While dynamic groups can be used to grant access based on conditions, giving full permissions to both compartments also violates the principle of least privilege.

1Z0-1104-25 Question 6

Single answer

Your organization recently migrated its on-premises finance, HR, and marketing systems to Oracle Cloud Infrastructure (OCI). Each department wants to maintain control over its own resources without interfering with one another. As a Security Professional, you need to design the best logical isolation strategy from the start. Which approach should you recommend first to achieve this requirement?

  1. A

    Assign each department to an entirely separate Identity Domain and rely on cross-domain trust for collaboration.

  2. B

    Create separate compartments for each department and apply relevant IAM policies to those compartments.

  3. C

    Use a single compartment but rely on detailed Object Storage bucket policies to limit inter-departmental access.

  4. D

    Grant each department member the Administrator role so they can manage only their own resources.

Show answer and explanation

Correct answer: B

Explanation

OCI recommends using compartments as the primary mechanism to separate and manage resources logically. By placing each department� resources in its own compartment and applying least-privilege IAM policies, you align with Oracle� best practices for secure deployment. Refer to the Oracle Cloud Infrastructure documentation on 'Managing Compartments' and 'Identity and Access Management' for more details on creating a scalable and secure multi-compartment design.

  • A. Incorrect.

    Option 1: Assigning each department to its own Identity Domain can work in certain scenarios, but it is typically more complex to manage and not necessary for simple departmental isolation. Compartments are the recommended first layer of resource isolation in OCI.

  • B. Correct.

    Option 2: Creating separate compartments for each department and applying IAM policies to those compartments is the fundamental best practice for logical isolation in OCI. This ensures each department controls access to its resources without cross-department conflicts. (Correct)

  • C. Incorrect.

    Option 3: Using a single compartment and relying on Object Storage bucket policies alone does not provide broad resource isolation. While bucket policies can limit storage access, they don�t address overall compartment-level security and governance needs.

  • D. Incorrect.

    Option 4: Granting everyone Administrator privileges for self-management contradicts the least-privilege principle and could easily lead to misconfigurations or security breaches. Roles should be scoped to specific resources and tasks instead.

1Z0-1104-25 Question 7

Single answer

Your financial services company is migrating a critical HR application to an Oracle Cloud Infrastructure (OCI) Compute instance. You need to ensure the environment meets strict regulatory requirements for data security, patches, and access controls. According to the OCI Shared Security Responsibility model, which statement best reflects your responsibilities versus Oracle� responsibilities?

  1. A

    A) Oracle handles all aspects of data security, including operating system patching and encryption within the guest operating system.

  2. B

    B) Your team is responsible for configuring and maintaining the guest operating system, applying application-level patches, and managing data encryption, while Oracle secures the underlying physical and virtual infrastructure.

  3. C

    C) Oracle covers application-level security controls and user access management, and your team only needs to manage network firewall and traffic filtering rules.

  4. D

    D) You are only required to manage authentication for users logging into OCI. Oracle implements all other security controls, including encryption and compliance.

Show answer and explanation

Correct answer: B

Explanation

The OCI Shared Security Responsibility model clearly divides duties: Oracle secures the underlying infrastructure (hardware, network, hypervisor, and physical data centers), while the customer is accountable for the security of their own instances, operating systems, application software, and data. For more details, refer to Oracle� official documentation on Shared Security Responsibility, which outlines the boundaries between Oracle� responsibilities and those of the customer (e.g., OS-level patching, encryption management, and application configuration).

  • A. Incorrect.

    Option A: Incorrect. While Oracle manages security of the underlying physical infrastructure and cloud services, customers must still patch and secure the operating system and configure encryption within their own instances. It is a misconception to assume Oracle covers all aspects of data security.

  • B. Correct.

    Option B: Correct. Under the Shared Security Responsibility model, Oracle is responsible for the physical data centers, network, and hypervisor layers, while customers are responsible for what runs on top of those layers, including guest OS patching, application security, and data protection controls.

  • C. Incorrect.

    Option C: Incorrect. Customers manage not only network firewall rules but also operating system security and application patches. Oracle does not assume responsibility for application-level security in the customer� environment.

  • D. Incorrect.

    Option D: Incorrect. This suggests that the customer has almost no responsibilities beyond authentication, which is not accurate. Customers also handle OS-level patching, data encryption, and compliance tasks within their tenant� scope.

1Z0-1104-25 Question 8

Select 2

Your healthcare organization is migrating a patient management system to Oracle Cloud Infrastructure (OCI). As part of the shared security responsibility model, which responsibilities specifically fall under your organization� role to ensure the environment remains protected?

  1. A

    Setting up and maintaining physical security controls at Oracle� data centers

  2. B

    Controlling and managing IAM policies for users and groups in your OCI tenancy

  3. C

    Deploying security patches to the underlying hypervisor that hosts your instances

  4. D

    Implementing and maintaining OS-level patches and configurations within your compute instances

Show answer and explanation

Correct answers: B, D

Explanation

In OCI� shared security responsibility model, Oracle secures the underlying infrastructure�including physical data centers, hardware, and the hypervisor. Customers are responsible for securing their applications, data, OS patches, and IAM policies. For details, refer to Oracle documentation on the Shared Security Responsibility Model and best practices for infrastructure security in OCI.

  • A. Incorrect.

    Option 1: Incorrect. Physical security of OCI data centers is Oracle� responsibility. They manage locks, surveillance, and restricted access at the data center level.

  • B. Correct.

    Option 2: Correct. You are responsible for configuring and enforcing Identity and Access Management (IAM) policies for your resources, ensuring correct privilege assignments and secure authentication methods.

  • C. Incorrect.

    Option 3: Incorrect. Oracle is responsible for applying patches to the underlying hypervisor and virtualization layers. As a customer, you only manage responsibilities starting at the operating system level and above (for IaaS).

  • D. Correct.

    Option 4: Correct. Managing and regularly updating OS patches, antivirus software, and other configurations within your instances is part of the customer� responsibilities in OCI.

1Z0-1104-25 Question 9

Select 2

Your organization is migrating a mission-critical workload to an OCI Compute instance. The leadership team is uncertain about who is responsible for operating system patching, data encryption at rest, security of the physical infrastructure, and user access management. According to the OCI Shared Security Responsibility model, which two tasks are typically the customer� responsibility in this scenario?

  1. A

    Patching the operating system on the compute instance

  2. B

    Securing the physical hardware in the OCI data center

  3. C

    Managing user access and credentials

  4. D

    Maintaining the underlying virtualization layer

Show answer and explanation

Correct answers: A, C

Explanation

Under OCI� Shared Security Responsibility model, Oracle secures the underlying infrastructure (data centers, hardware, network, and virtualization). Customers are responsible for securing their workloads, including operating system patches, IAM components, data configurations, and application-level security. Refer to OCI documentation at https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm for more details.

  • A. Correct.

    Correct. In an IaaS model on OCI, customers are responsible for maintaining and patching the operating system on their compute instances.

  • B. Incorrect.

    Incorrect. Oracle is responsible for securing the physical hardware, including data centers and network infrastructure.

  • C. Correct.

    Correct. Managing users, permissions, and credentials is the customer� responsibility, including creating and managing IAM policies, groups, and roles.

  • D. Incorrect.

    Incorrect. Oracle manages the underlying virtualization layer that supports compute instances.

1Z0-1104-25 Question 10

Single answer

Your e-commerce company is deploying a customer-facing application on Oracle Cloud Infrastructure (OCI). During a security review, your team is uncertain about which security tasks they must handle versus those that Oracle handles. Under the OCI Shared Security Responsibility model, which of the following tasks is the customer responsible for?

  1. A

    Ensuring physical security at the OCI data centers

  2. B

    Managing and rotating user credentials within the OCI environment

  3. C

    Maintaining and updating OCI� underlying hypervisor layer

  4. D

    Providing uninterrupted power and network infrastructure at OCI facilities

Show answer and explanation

Correct answer: B

Explanation

In the OCI Shared Security Responsibility model, Oracle is responsible for the infrastructure, including the physical data center security, underlying network, and hypervisor. Customers, however, are responsible for securing their own workloads, data, and the configurations within their OCI tenancy. This includes managing user credentials, applying OS and application-level patches, and enforcing strong identity and access management policies. Refer to the official Oracle Cloud Infrastructure Security documentation (https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm) for detailed guidance on each party� responsibilities.

  • A. Incorrect.

    Incorrect. Oracle manages physical security at its data centers, including entry controls and on-premises security. Customers generally have no control or responsibilities in this area.

  • B. Correct.

    Correct. Under the shared responsibility model, customers must manage credentials, implement strong password policies, and perform periodic key rotations or secret management for their users in the OCI environment.

  • C. Incorrect.

    Incorrect. Oracle manages and patches the underlying hypervisor for its compute infrastructure. Customers do not maintain or update the hypervisor or other infrastructure layers.

  • D. Incorrect.

    Incorrect. Oracle is responsible for the physical infrastructure, power, and network connectivity at its data centers. Customers do not handle these aspects.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

What the 1Z0-1104-25 exam covers

Official Oracle Cloud Infrastructure 2025 Security Professional exam domains and weightings.

  • Identity and Access Management

    25% of exam

  • Network Security

    25% of exam

  • Data Protection and Encryption

    25% of exam

  • Security Monitoring and Compliance

    25% of exam

All 174 1Z0-1104-25 practice questions

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them.

  1. 1.Your organization is migrating its financial application to Oracle Cloud Infrastructure (OCI) and has created...
  2. 2.Your organization has discovered that certain Object Storage buckets in OCI are publicly accessible and some...
  3. 3.Your organization is migrating critical workloads to Oracle Cloud Infrastructure (OCI). You have been tasked...
  4. 4.An organization discovers that a developer inadvertently has broad access to resources across multiple OCI...
  5. 5.You have created multiple compartments to isolate resources for different teams in your OCI tenancy. You want...
  6. 6.Your organization recently migrated its on-premises finance, HR, and marketing systems to Oracle Cloud...
  7. 7.Your financial services company is migrating a critical HR application to an Oracle Cloud Infrastructure...
  8. 8.Your healthcare organization is migrating a patient management system to Oracle Cloud Infrastructure (OCI)....
  9. 9.Your organization is migrating a mission-critical workload to an OCI Compute instance. The leadership team is...
  10. 10.Your e-commerce company is deploying a customer-facing application on Oracle Cloud Infrastructure (OCI)....
  11. 11.Your organization is migrating a business-critical HR application to Oracle Cloud Infrastructure (OCI). The...
  12. 12.A retail company is migrating its on-premises e-commerce platform to Oracle Cloud Infrastructure (OCI). As...
  13. 13.A financial services company is designing a multi-tier application in Oracle Cloud Infrastructure (OCI). They...
  14. 14.You are designing a multi-tier application on Oracle Cloud Infrastructure (OCI) that processes sensitive...
  15. 15.Your organization is deploying a new set of microservices in Oracle Cloud Infrastructure (OCI) that handle...
  16. 16.Your team has deployed an e-commerce application on Oracle Cloud Infrastructure (OCI) that stores sensitive...
  17. 17.Your team is deploying a multi-tier web application in Oracle Cloud Infrastructure (OCI) that processes...
  18. 18.Your organization is migrating an internal HR application to Oracle Cloud Infrastructure (OCI). This...
  19. 19.You are a security architect at a financial services firm planning to store daily transaction logs in an OCI...
  20. 20.You are deploying a microservices-based application in Oracle Cloud Infrastructure (OCI) with a public-facing...
  21. 21.You are deploying a new application on Oracle Container Engine for Kubernetes (OKE) that needs to retrieve...
  22. 22.You are deploying an e-commerce application on Oracle Cloud Infrastructure (OCI) with the front-end web...
  23. 23.An organization is deploying a sensitive HR application on Oracle Cloud Infrastructure (OCI). They need to...
  24. 24.You are responsible for securing a new web application that processes sensitive data in Oracle Cloud...
  25. 25.You are the security engineer for an enterprise that uses Oracle Cloud Infrastructure (OCI). The company has...
  26. 26.Your organization has brought in a third-party consultant for two weeks to optimize the existing Database...
  27. 27.Your organization has an existing AdminGroup that is granted broad permissions via the policy: 'Allow group...
  28. 28.Your organization uses Oracle Cloud Infrastructure (OCI) to separate Dev, Test, and Production workloads into...
  29. 29.You are the lead security administrator for a company using Oracle Cloud Infrastructure (OCI). You need to...
  30. 30.Your company wants to grant the FinanceTeam group the ability to view all cost-related data across the...
  31. 31.Your organization has created a group called 'Operations' in Oracle Cloud Infrastructure (OCI) and assigned...
  32. 32.Your organization has deployed a microservice on Oracle Container Engine for Kubernetes (OKE) to process...
  33. 33.Your organization has created a new group called 'DataScientists' in Oracle Cloud Infrastructure (OCI). This...
  34. 34.You are an OCI Security Administrator for a company with separate compartments for Marketing, Finance, and...
  35. 35.Your organization has recently set up a SAML-based federation with Oracle Cloud Infrastructure (OCI) so...
  36. 36.Your company has two groups in Oracle Cloud Infrastructure (OCI): 'Finance' and 'Dev'. The Finance team needs...
  37. 37.Your organization has decided to create a new domain called 'SalesDomain' to separate sales users from other...
  38. 38.Your organization has recently acquired a new subsidiary. Leadership has decided to create a separate IAM...
  39. 39.Your organization has created a new IAM domain (named 'BUAcquired') in Oracle Cloud Infrastructure to isolate...
  40. 40.Your organization has acquired a new subsidiary and wants to provision a dedicated IAM domain for them in...
  41. 41.Your organization has created a new IAM domain named FinanceDomain in Oracle Cloud Infrastructure (OCI) to...
  42. 42.Your organization has acquired a new business unit that requires strict resource isolation. You have decided...
  43. 43.You have been asked to create a policy for a new group named AppTeamComputeAdmins. They need to provision and...
  44. 44.Your organization uses Oracle Cloud Infrastructure (OCI) for multiple projects. The 'AppTeam' group needs...
  45. 45.Your organization has created a new group called 'DevGroup' in Oracle Cloud Infrastructure (OCI) that needs...
  46. 46.You have a new project that requires the 'ReportCreators' IAM group to access objects in an Object Storage...
  47. 47.Your organization manages two OCI compartments: 'Development' for testing and 'Production' for live...
  48. 48.A compliance team at your organization needs to review all audit logs across all compartments in Oracle Cloud...
  49. 49.Your organization wants to ensure that only compute instances tagged with Department=Finance can read objects...
  50. 50.You have an OCI Vault and want to allow compute instances with the tag Department=DevOps to read secrets, but...
  51. 51.You want to grant access to the Object Storage API only to your compute instances that carry the tag...
  52. 52.Your organization hosts a CI/CD pipeline on Oracle Cloud Infrastructure (OCI) and wants to ensure that only...
  53. 53.Your company wants to restrict administrative actions on OCI Compute instances to those labeled with a...
  54. 54.Your organization wants only compute instances tagged with Department=Finance to access a particular Object...
  55. 55.You are a Security Administrator at a company that requires multi-factor authentication (MFA) for all members...
  56. 56.Your organization requires mandatory multi-factor authentication (MFA) for all OCI console sign-ins....
  57. 57.You are the security administrator for a large enterprise using Oracle Cloud Infrastructure (OCI). Your...
  58. 58.Your security team wants to enforce multi-factor authentication (MFA) on all administrator console logins in...
  59. 59.Your organization requires that all users must provide Multi-factor Authentication (MFA) when signing in from...
  60. 60.You work at a company that has mandated multi-factor authentication (MFA) for all users. In addition, the...
  61. 61.Your retail organization hosts a critical e-commerce website on Oracle Cloud Infrastructure (OCI) using a...
  62. 62.You are managing an e-commerce application deployed on Oracle Cloud Infrastructure (OCI). The front end is...
  63. 63.Your organization hosts a mission-critical web application on Oracle Cloud Infrastructure behind a public...
  64. 64.Your organization hosts a three-tier e-commerce application on Oracle Cloud Infrastructure (OCI). The web...
  65. 65.You are designing a multi-tier e-commerce application on Oracle Cloud Infrastructure (OCI). The web-tier is...
  66. 66.You have deployed a three-tier application in Oracle Cloud Infrastructure (OCI) with a public-facing...
  67. 67.You are responsible for a three-tier web application deployed to Oracle Cloud Infrastructure (OCI). The...
  68. 68.You have set up a new OCI environment with a public subnet hosting an Internet-facing Load Balancer (LB) and...
  69. 69.An organization is deploying a new e-commerce system in Oracle Cloud Infrastructure. The environment includes...
  70. 70.Your organization hosts a multi-tier application in Oracle Cloud Infrastructure (OCI) with a public subnet...
  71. 71.Your organization is deploying a microservices-based application within a single VCN. The front-end services...
  72. 72.You have deployed a multi-tier web application on Oracle Cloud Infrastructure (OCI) with a public subnet...
  73. 73.Your organization is deploying a multi-tier application in Oracle Cloud Infrastructure (OCI) across two...
  74. 74.Your organization hosts a mission-critical web application on Oracle Cloud Infrastructure across two...
  75. 75.Your organization hosts a business-critical e-commerce application across two Availability Domains (AD1 and...
  76. 76.Your company is deploying a business-critical web application in the Phoenix region on Oracle Cloud...
  77. 77.Your company has deployed a critical e-commerce application in Oracle Cloud Infrastructure (OCI) and wants to...
  78. 78.A retail company has deployed their e-commerce platform on Oracle Cloud Infrastructure (OCI), distributing...
  79. 79.Your organization uses an OCI Load Balancer fronting a web application, with an SSL certificate managed...
  80. 80.You manage a production application behind an OCI Load Balancer that uses a certificate from the Oracle Cloud...
  81. 81.Your organization has obtained a third-party CA-signed certificate and wants to store it in the OCI...
  82. 82.Your organization has renewed its SSL/TLS certificate from a trusted Certificate Authority (CA) for a...
  83. 83.Your organization has a microservices-based application running behind an OCI Load Balancer, and you want to...
  84. 84.You are managing an e-commerce application behind an OCI Load Balancer that uses a TLS certificate stored in...
  85. 85.Your team recently created an Oracle Cloud Infrastructure (OCI) Web Application Firewall (WAF) policy for a...
  86. 86.Your security team has noticed an increase in malicious traffic targeting a public web application hosted...
  87. 87.You are configuring an Oracle Cloud Infrastructure (OCI) Web Application Firewall (WAF) to protect a...
  88. 88.Your organization has configured an Oracle Cloud Infrastructure Web Application Firewall (WAF) policy with...
  89. 89.You manage an online store hosted in Oracle Cloud Infrastructure (OCI) behind a public load balancer. You...
  90. 90.Your e-commerce application runs behind an OCI public load balancer, and you recently created a new WAF...
  91. 91.Your organization runs a mission-critical application on Linux-based virtual machine (VM) instances in Oracle...
  92. 92.You manage an e-commerce platform running Linux-based workloads on multiple Oracle Cloud Infrastructure (OCI)...
  93. 93.You manage a multi-tier application running on Oracle Linux compute instances in Oracle Cloud Infrastructure...
  94. 94.You are responsible for securing a fleet of frequently launched and terminated Linux compute instances in...
  95. 95.You are managing a set of Linux-based instances that handle sensitive financial data in Oracle Cloud...
  96. 96.You are a security engineer with 200 Linux compute instances spread across multiple compartments in Oracle...
  97. 97.Your team needs temporary SSH access to a private compute instance for troubleshooting a production issue....
  98. 98.Your finance department has engaged a third-party auditor who needs short-lived direct SSH access to an...
  99. 99.You have been tasked with granting a third-party auditor secure, short-term SSH access to a private compute...
  100. 100.You are setting up OCI Bastion to grant a contractor short-term SSH access to a private compute instance for...
  101. 101.Your organization needs to provide a remote maintenance team with intermittent SSH access to a private Linux...
  102. 102.Your organization hires a contractor who requires SSH access to a private compute instance for a short...
  103. 103.You manage several Linux compute instances and container images hosted in OCI Container Registry. Your...
  104. 104.You are managing an e-commerce application on Oracle Cloud Infrastructure (OCI) that uses container images...
  105. 105.Your organization hosts several critical workloads on Oracle Cloud Infrastructure (OCI) using both Compute...
  106. 106.Your company is running several containerized applications on Oracle Cloud Infrastructure (OCI) Container...
  107. 107.You are a security administrator at an organization running microservices on Oracle Cloud Infrastructure...
  108. 108.Your organization stores regularly updated container images in Oracle Cloud Infrastructure (OCI) Container...
  109. 109.Your company needs to ensure that all Oracle Linux compute instances in Oracle Cloud Infrastructure (OCI)...
  110. 110.Your security team mandates that critical patches be applied to all Oracle Linux compute instances within 24...
  111. 111.You have a fleet of Oracle Linux and Windows Server instances in Oracle Cloud Infrastructure (OCI) spread...
  112. 112.You manage a fleet of Linux compute instances in Oracle Cloud Infrastructure (OCI). An upcoming security...
  113. 113.Your company recently deployed hundreds of Linux-based Compute instances in Oracle Cloud Infrastructure...
  114. 114.You are an OCI security professional overseeing a fleet of 50 Linux Compute instances that support...
  115. 115.Your organization is storing confidential HR records in an Oracle Object Storage bucket. Due to compliance...
  116. 116.A research organization wants to store highly sensitive data in an Oracle Cloud Infrastructure (OCI) Object...
  117. 117.Your finance department stores sensitive data in an Oracle Cloud Infrastructure (OCI) Object Storage bucket,...
  118. 118.Your organization runs an application that processes highly sensitive customer data in Oracle Cloud...
  119. 119.You are designing a new application in Oracle Cloud Infrastructure (OCI) to process personally identifiable...
  120. 120.Your organization needs to protect sensitive data stored in OCI Object Storage by enforcing server-side...
  121. 121.You have created a new vault in Oracle Cloud Infrastructure (OCI) Key Management Service (KMS) to secure data...
  122. 122.You have an application storing confidential documents in an OCI Object Storage bucket using a...
  123. 123.Your organization recently discovered that a sensitive OCI Block Volume is encrypted with an Oracle-managed...
  124. 124.You are a security administrator for a financial application deployed on Oracle Cloud Infrastructure (OCI)....
  125. 125.Your team has deployed an application on OCI that uses a Customer-Managed Key (CMK) stored in OCI Key...
  126. 126.Your security team enforces a policy requiring rotation of the encryption key used for protecting sensitive...
  127. 127.You manage an application that stores a database password as a secret in OCI Vault. The application needs a...
  128. 128.You are storing database credentials in an OCI Vault secret for a critical production database. The...
  129. 129.Your team stores database credentials in an OCI Vault secret to protect sensitive information. They need to...
  130. 130.Your analytics application uses a secret stored in an Oracle Cloud Infrastructure (OCI) Vault to connect to a...
  131. 131.You manage a web application that serves customer-facing transactions. To secure communications, you have an...
  132. 132.Your organization runs an Oracle Container Engine for Kubernetes (OKE) cluster hosting a microservices-based...
  133. 133.Your organization has recently migrated several Oracle Database instances to OCI. You need to pinpoint where...
  134. 134.A healthcare organization is preparing for a regulatory audit of personal health information stored in an...
  135. 135.Your company has noticed that certain database user accounts appear to have excessive privileges and...
  136. 136.Your organization has a production database containing sensitive customer information. You want to identify...
  137. 137.Your organization is preparing a new test environment from production data stored in an Oracle Autonomous...
  138. 138.Your organization is migrating its financial databases to Oracle Cloud Infrastructure (OCI). You need to...
  139. 139.Your organization recently discovered that some Security Lists in a critical OCI compartment allow inbound...
  140. 140.You are the security lead for a large e-commerce platform hosted on Oracle Cloud Infrastructure (OCI). Your...
  141. 141.Your organization has discovered that some Object Storage buckets in OCI are inadvertently set to public,...
  142. 142.Your organization is launching a set of new compute instances in Oracle Cloud Infrastructure (OCI). You need...
  143. 143.Your company recently discovered that a publicly accessible Object Storage bucket was created in a critical...
  144. 144.You are the security lead for a large e-commerce platform running on Oracle Cloud Infrastructure. Your...
  145. 145.You are responsible for securing an OCI environment with multiple compartments and a rapidly growing number...
  146. 146.Your organization runs critical workloads across multiple compartments and regions in Oracle Cloud...
  147. 147.Your organization has recently spun up a new development compartment in Oracle Cloud Infrastructure (OCI)...
  148. 148.Your organization manages multiple compartments in OCI to separate development, testing, and production...
  149. 149.Your organization has recently created additional compartments in Oracle Cloud Infrastructure (OCI). You�ve...
  150. 150.Your organization recently experienced a security incident where an internal Object Storage bucket was...
  151. 151.You have a Security Zone in your tenancy that enforces strict rules against publicly accessible storage...
  152. 152.Your organization has recently activated Security Zones and enabled Security Advisor in Oracle Cloud...
  153. 153.Your organization has created a dedicated Security Zone compartment to protect sensitive data. After...
  154. 154.Your organization is setting up a new critical application on Oracle Cloud Infrastructure (OCI). The security...
  155. 155.You have created a new Security Zone in Oracle Cloud Infrastructure (OCI) and applied it to a compartment...
  156. 156.Your organization recently imposed strict requirements on object storage configurations to prevent any public...
  157. 157.You are a Security Administrator at a large enterprise using Oracle Cloud Infrastructure (OCI). You have...
  158. 158.Your organization suspects that a privileged user is connecting from an IP address flagged as malicious by...
  159. 159.You suspect that a handful of user accounts in your OCI environment may be compromised because they are...
  160. 160.You have integrated Oracle Threat Intelligence with your OCI environment. Your security dashboard shows...
  161. 161.You are a security administrator for an organization using Oracle Cloud Infrastructure (OCI). You have...
  162. 162.Your finance department reports that the user 'JohnDoe' has been creating multiple Compute instances in an...
  163. 163.You are the security lead for a company running several critical applications on OCI Compute instances. A...
  164. 164.Your organization hosts a high-traffic web application on OCI Compute instances. The security team requires...
  165. 165.You manage a critical application running on multiple OCI Compute instances. Your security team needs to...
  166. 166.You manage a fleet of Compute instances running critical workloads in Oracle Cloud Infrastructure (OCI). Your...
  167. 167.You have a microservices application running on multiple OCI Compute instances, and you want to proactively...
  168. 168.You are a security engineer responsible for monitoring and alerting on performance metrics across multiple...
  169. 169.You are a security engineer tasked with monitoring unauthorized configuration changes to Security Lists in...
  170. 170.You are a security administrator at an e-commerce company running workloads on Oracle Cloud Infrastructure...
  171. 171.Your security team requires immediate notifications whenever a Security List is modified in your Oracle Cloud...
  172. 172.You are responsible for security in a production tenancy running multiple Compute instances in Oracle Cloud...
  173. 173.Your organization wants to be immediately notified whenever any changes are made to Security Lists within a...
  174. 174.Your organization needs to monitor any modifications to OCI IAM policies and immediately alert the security...

1Z0-1104-25 exam dumps FAQ

Are these 1Z0-1104-25 dumps real exam questions?

No. These are original practice questions written to the Oracle Cloud Infrastructure 2025 Security Professional exam objectives, not questions copied from a live exam. Memorising leaked questions violates Oracle's candidate agreement and stops working the moment the question pool rotates. Use this bank to check your understanding of each domain and to find the topics you still need to study.

How many 1Z0-1104-25 practice questions are there?

174 questions, each with the correct answer, an explanation of the answer, and a note on why every other option is wrong. The first 10 are on this page and every question has its own page linked below.

Are the 1Z0-1104-25 exam dumps free?

Yes. Every question, answer and explanation on this page and the linked question pages is free to read without an account. A free HydraNode account adds timed practice exams, scoring and progress tracking across attempts.

How do I take a timed 1Z0-1104-25 practice test?

Sign in and start the Oracle Cloud Infrastructure 2025 Security Professional exam on HydraNode. A session gives you 70 questions drawn from this bank in 90 minutes, then a score report with a per-question review.

What topics does the 1Z0-1104-25 exam cover?

The official exam domains are: Identity and Access Management; Network Security; Data Protection and Encryption; Security Monitoring and Compliance.