1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 132 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 132

Select 2

Your organization runs an Oracle Container Engine for Kubernetes (OKE) cluster hosting a microservices-based application. You need to store sensitive database credentials as secrets within an OCI Vault, rotate these secrets every 30 days, and ensure that only the specific microservice pods can access them. Which two steps must you complete to meet these requirements? (Choose two.)

  1. A

    Use OCI Logging to automatically rotate the Vault secret version every 30 days

  2. B

    Create an IAM policy granting a dynamic group of OKE worker nodes permission to read the secret

  3. C

    Configure the secret with a rotation policy in the vault and set the rotation frequency to 30 days

  4. D

    Manually define a Kubernetes Secret containing the credentials instead of using the OCI Vault

Show answer and explanation

Correct answers: B, C

Explanation

To securely store and manage secrets in OCI Vault for a microservices application on OKE, you must create a secret with a defined rotation policy and grant only the OKE service (via a dynamic group and an appropriate IAM policy) permission to read it. By configuring a rotation policy in the Vault, you ensure that the secret is automatically rotated on the specified schedule, and allowing only the dynamic group of worker nodes to read the secret enforces least-privileged access. Refer to OCI Vault documentation for further details on creating and managing secrets, rotation policies, and IAM policies.

  • A. Incorrect.

    Option 1 is incorrect. OCI Logging does not provide a mechanism for automatic credential or secret rotation. Secret rotation must be configured directly in OCI Vault.

  • B. Correct.

    Option 2 is correct. To read a Vault secret from within OKE, the worker nodes (or pods) must belong to a dynamic group, and that group needs an IAM policy granting 'read secret' permissions on the Vault. This ensures only authorized pods can access the secrets.

  • C. Correct.

    Option 3 is correct. OCI Vault supports defining rotation policies for secrets. By setting a 30-day rotation schedule, the secret versions will be rotated automatically, helping meet compliance and security best practices.

  • D. Incorrect.

    Option 4 is incorrect. Storing the database credentials in a Kubernetes Secret instead of the OCI Vault bypasses the Vault� rotation and centralized key management capabilities. The requirement specifically calls for storing and rotating credentials in OCI Vault.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam