1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 124 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 124

Single answer

You are a security administrator for a financial application deployed on Oracle Cloud Infrastructure (OCI). The application stores highly sensitive transaction records in an Autonomous Database instance, with encryption keys managed by OCI Key Management Service (KMS). Your organization� policy mandates key rotation every six months to comply with regulatory requirements. You need to rotate the key while minimizing any service downtime and ensuring that existing data remains accessible. Which approach accomplishes this goal most effectively?

  1. A

    Generate a new master encryption key in a separate vault and re-encrypt all existing data using the new key before disabling the old vault.

  2. B

    Create a new key version inside the same vault, update the database to use the new key version, and keep the old version active temporarily to avoid disruptions.

  3. C

    Import an externally generated key file into the vault, immediately disable the current key, and re-encrypt data only after the external key is fully functional.

  4. D

    Permanently delete the old key version from the vault as soon as you generate the new key version to ensure complete removal of any compromised keys.

Show answer and explanation

Correct answer: B

Explanation

OCI Key Management Service supports key rotation by creating a new key version within the same vault. This allows existing data to remain accessible under the old version until the new version is fully adopted. According to Oracle� best practices, you should test and confirm that all applications and services have switched to the new key version before disabling or deleting the old one. Refer to Oracle documentation on 'Rotating Keys in Oracle Cloud Infrastructure KMS' for detailed steps and recommended procedures.

  • A. Incorrect.

    Option 1 is incorrect. Generating a new master key in a separate vault requires additional steps to manually re-encrypt data and update application configuration, risking more downtime and complexity.

  • B. Correct.

    Option 2 is correct. Best practice for OCI KMS key rotation is to create a new key version in the same vault, update your database or services to use that new version, and keep the old version enabled until you confirm the successful transition. This minimizes disruption and ensures continuous access to decrypted data.

  • C. Incorrect.

    Option 3 is incorrect. While importing an external key is a valid use case in OCI KMS, disabling the current key before verifying the new key� functionality can cause downtime or data inaccessibility. Proper rotation involves overlapping usage of old and new key versions instead of an immediate switch-off.

  • D. Incorrect.

    Option 4 is incorrect. Permanently deleting the old key version immediately after generating a new one can cause service disruptions if any active processes still rely on the old key version. Deletion should only occur once you confirm that no services or data operations require the old version.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam