1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 116 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 116

Single answer

A research organization wants to store highly sensitive data in an Oracle Cloud Infrastructure (OCI) Object Storage bucket. They must ensure the data is encrypted at rest using keys they control. The security team also requires strict access policies so that only specific security administrators can manage key rotation. Which solution best meets these requirements with minimal administrative overhead?

  1. A

    Use Oracle-managed server-side encryption (SSE) with default keys provided by OCI.

  2. B

    Create a Vault within OCI, generate a customer-managed master encryption key, and configure Object Storage to use that key while granting key-management permissions only to security administrators.

  3. C

    Deploy Transparent Data Encryption (TDE) for the Object Storage bucket and rotate the TDE master keys regularly.

  4. D

    Encrypt all data on-premises before uploading to the Object Storage bucket, then store the keys in a local password-protected file.

Show answer and explanation

Correct answer: B

Explanation

OCI Vault allows you to generate and manage your own encryption keys while seamlessly integrating with services such as Object Storage for server-side encryption. By configuring a customer-managed key in Vault, you maintain full control over key rotation and access policies. This approach is documented in Oracle� �Using Customer-Managed Keys (CMKs) in the Vault� guidelines, ensuring alignment with best practices for protecting data at rest.

  • A. Incorrect.

    Option 1: This relies on Oracle-managed keys, which do not offer the granularity of key control or restricted administrator access required. It is simple but does not meet the requirement of controlling your own keys.

  • B. Correct.

    Option 2: Using OCI Vault to create and manage a customer-managed master encryption key specifically for Object Storage ensures that the organization controls key rotation and access. By assigning key management roles only to designated security administrators, the organization can maintain strict separation of duties. This approach provides minimal administrative overhead while meeting security requirements.

  • C. Incorrect.

    Option 3: Transparent Data Encryption (TDE) is primarily used for encrypting data in Oracle Databases, not Object Storage buckets. It does not natively apply to Object Storage data, so this would not address the stated requirements.

  • D. Incorrect.

    Option 4: While encrypting data on-premises before uploading protects data, storing the key in a local file does not leverage OCI� built-in key management features. This approach introduces more administrative overhead and potential key exposure risk.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam