1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 143 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 143

Single answer

Your company recently discovered that a publicly accessible Object Storage bucket was created in a critical compartment, exposing sensitive data. You want to ensure this does not happen again by automatically detecting any newly created public buckets and reverting them to private. Which approach should you implement in Oracle Cloud Infrastructure (OCI) to achieve this?

  1. A

    Enable Cloud Guard for the relevant compartments, configure a custom Detector recipe to flag any public Object Storage bucket, and define a Responder rule that automatically removes public access.

  2. B

    Write a custom IAM policy that prevents the creation of Object Storage buckets in any compartment with the 'public' keyword in its name.

  3. C

    Rely solely on Audit logs to track bucket modification events, and manually change bucket permissions afterward.

  4. D

    Use Security Zones in all compartments to enforce block storage encryption, assuming it also prevents public buckets.

Show answer and explanation

Correct answer: A

Explanation

Oracle Cloud Guard offers a comprehensive approach to continuously monitor, detect, and remediate security risks across OCI resources. By enabling Cloud Guard on the target compartments, creating or customizing a Detector recipe to identify publicly accessible Object Storage buckets, and configuring a corresponding Responder rule, you can ensure that any such bucket is automatically reverted to private upon detection. For more information, refer to OCI documentation on using Cloud Guard for detection and remediation: https://docs.oracle.com/en-us/iaas/Content/CloudGuard/Concepts/overview.htm.

  • A. Correct.

    Correct. Cloud Guard, when enabled for the relevant compartments, can detect security problems with public Object Storage buckets by using Detector recipes. The associated Responder rules can then remediate, for instance by automatically changing the bucket� access type from public to private. This is a common and recommended approach to continuously monitor and remediate security vulnerabilities in OCI.

  • B. Incorrect.

    Incorrect. While an IAM policy can control bucket creation and access at a high level, this approach is overly restrictive and does not specifically address making an existing or newly created bucket public. It also lacks continuous detection and automatic remediation capabilities.

  • C. Incorrect.

    Incorrect. Relying on Audit logs alone is largely reactive. You would only discover a public bucket after the fact, and you would still need to manually fix it. This does not meet the requirement for automated detection and remediation.

  • D. Incorrect.

    Incorrect. Security Zones help enforce best practices for resources in specific compartments, but merely enabling them for encryption settings does not automatically prevent creation of, or remediate, publicly accessible buckets. You would need specific Security Zone policies or other solutions, like Cloud Guard, to detect and remediate public buckets.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam