1Z0-1104-25 Question 135
Select 2Your company has noticed that certain database user accounts appear to have excessive privileges and potentially access sensitive data in an Oracle Autonomous Database on OCI. You need to quickly identify these high-risk user accounts and uncover which sensitive data they might be able to view. Which two OCI Data Safe features should you use to address these requirements?
- A
User Assessment
- B
Data Discovery and Classification
- C
Data Masking
- D
Security Zone Configuration
Show answer and explanation
Correct answers: A, B
Explanation
OCI Data Safe offers multiple features, but User Assessment and Data Discovery and Classification are specifically designed to identify high-risk user accounts and locate sensitive data in your databases. By using these two features together, you can pinpoint accounts with potentially dangerous access levels and understand where your most sensitive data resides. For more details and best practices, refer to the official Oracle documentation on OCI Data Safe.
- A. Correct.
User Assessment is correct because it helps identify user accounts with excessive privileges and provides insights into user risk levels. This directly addresses the issue of locating high-risk accounts.
- B. Correct.
Data Discovery and Classification is correct because it locates and catalogs sensitive data. This allows you to see if high-risk accounts can access particularly sensitive information.
- C. Incorrect.
Data Masking is incorrect in this context because, while it helps protect sensitive data by obfuscating it in non-production environments, it does not address the immediate need to identify users with excessive privileges or discover existing sensitive data in production.
- D. Incorrect.
Security Zone Configuration is incorrect because Security Zones govern how resources are created and secured in OCI but do not provide user account privilege analysis or data classification capabilities.