1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 14 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 14

Single answer

You are designing a multi-tier application on Oracle Cloud Infrastructure (OCI) that processes sensitive customer data in a backend database. To adhere to recommended security design principles, you must ensure multiple layers of protection and restrict traffic as much as possible. Which approach best aligns with the principle of �Defense in Depth� to minimize potential attack vectors and secure your data?

  1. A

    Deploy the entire application, including the database, in a single public subnet behind an internet gateway.

  2. B

    Segment the application into separate subnets, place the database in a private subnet, and restrict incoming traffic to only the application tier.

  3. C

    Use a single security group with permissive inbound policies for all resources to reduce management overhead.

  4. D

    Rely solely on user authentication and encryption at rest without using additional network segmentation or firewall rules.

Show answer and explanation

Correct answer: B

Explanation

Oracle� recommended security design principles emphasize that no single measure is sufficient to secure sensitive applications and data. Instead, �Defense in Depth� involves multiple layers, including proper subnet isolation, finely tuned security lists or network security groups, and minimal privileges. For more details, refer to Oracle Cloud Infrastructure Best Practices for Security (https://docs.oracle.com/en/).

  • A. Incorrect.

    Option 1 is incorrect. Placing all components (including the database) in a single public subnet greatly increases the attack surface. Even with an internet gateway in place, the database is potentially exposed to more threats than if segregated properly.

  • B. Correct.

    Option 2 is correct. Separating the application into distinct subnets and placing the database in a private subnet protected by network security rules follows the �Defense in Depth� principle. It minimizes the accessible surface area and ensures each tier is isolated from direct external access.

  • C. Incorrect.

    Option 3 is incorrect. Using a single, permissive security group for all components violates the principles of least privilege and compartmentalization. It also increases the likelihood that a compromise in one instance can spread laterally.

  • D. Incorrect.

    Option 4 is incorrect. While user authentication and encryption at rest are crucial elements, neglecting network segmentation and firewall rules leaves many potential attack vectors unaddressed. A layered approach is vital.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam