1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 105 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 105

Single answer

Your organization hosts several critical workloads on Oracle Cloud Infrastructure (OCI) using both Compute instances for traditional applications and Oracle Container Registry for container-based microservices. The security team wants to automatically identify vulnerabilities in both hosts and container images before deploying to production. Which approach should you implement in OCI to achieve this goal?

  1. A

    Rely on manual analysis of system logs for all Compute instances and container images, flagging any high-risk issues.

  2. B

    Configure the OCI Vulnerability Scanning Service to schedule and perform scans on both Compute instances and container images in the Oracle Container Registry.

  3. C

    Deploy the OCI Web Application Firewall (WAF) on each Compute instance to override any vulnerabilities discovered in container images.

  4. D

    Enable block volume encryption on each Compute instance, as it automatically includes container vulnerability reports.

Show answer and explanation

Correct answer: B

Explanation

Using the OCI Vulnerability Scanning Service is the recommended approach for identifying and addressing vulnerabilities in both Compute instances and container images stored in the Oracle Container Registry. By scheduling regular scans, security teams can detect vulnerabilities proactively and take remedial action based on real-time analysis. For more information, see the official OCI documentation on vulnerability scanning: https://docs.oracle.com/en-us/iaas/Content/security/scanning/overview.htm.

  • A. Incorrect.

    Option 1 is incorrect. Manually analyzing logs is time-consuming and prone to oversights, and it does not leverage OCI� built-in vulnerability scanning. While monitoring logs is important, it does not replace automated vulnerability scanning for hosts or container images.

  • B. Correct.

    Option 2 is correct. OCI Vulnerability Scanning Service can be configured to run scheduled scans for both Compute instances (host scanning) and container images in the Oracle Container Registry. This provides comprehensive visibility of vulnerabilities before they become critical issues.

  • C. Incorrect.

    Option 3 is incorrect. Deploying WAF is primarily for protecting web applications from malicious traffic; it does not offer container image scanning or deep host-level scanning for vulnerabilities. WAF and vulnerability scanning are complementary but serve different security needs.

  • D. Incorrect.

    Option 4 is incorrect. Enabling block volume encryption ensures data at rest is protected but does not perform vulnerability scans on hosts or container images. Encryption addresses data confidentiality rather than vulnerability detection.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam