1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 145 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 145

Select 2

You are responsible for securing an OCI environment with multiple compartments and a rapidly growing number of resources. Your organization wants to continuously monitor all current and newly created compartments for configuration anomalies and suspicious activity. Which two steps should you take to ensure Cloud Guard provides comprehensive security posture monitoring across all compartments?

  1. A

    Create a single Cloud Guard Target at the root compartment level and enable automatic inclusion of all compartments in its configuration.

  2. B

    Deploy a Cloud Guard agent on all new compute instances to stream security logs into OCI Logging for analysis.

  3. C

    Enable the relevant Cloud Guard Data Sources (e.g., Activity and Configuration) to ensure events and configuration changes across compartments are monitored.

  4. D

    Establish a separate Cloud Guard Target for each new compartment as it is created.

Show answer and explanation

Correct answers: A, C

Explanation

In multi-compartment OCI environments, best practice is to create a single Cloud Guard Target at the root compartment and enable 'Include all compartments' to automatically discover and monitor new compartments. Additionally, you must enable relevant Data Sources like Activity and Configuration so Cloud Guard can collect security-relevant information (e.g., events, logs, configuration changes) across the entire tenancy. Refer to the official OCI Cloud Guard documentation for detailed steps on Target configuration and enabling Data Sources.

  • A. Correct.

    Option 1 is correct. By setting up a Cloud Guard Target at the root compartment and enabling 'Include all compartments,' you ensure that every existing and newly created compartment is covered automatically, simplifying management and providing full coverage.

  • B. Incorrect.

    Option 2 is incorrect. Cloud Guard does not require the deployment of specialized agents on each instance. Instead, it collects data from OCI services (e.g., Logging, Events, Configuration) without the need for additional agents.

  • C. Correct.

    Option 3 is correct. Enabling Cloud Guard Data Sources, such as Activity and Configuration, is essential to capture and analyze relevant events and configuration changes. Without these data sources, Cloud Guard would not receive the necessary information to assess the environment's security posture.

  • D. Incorrect.

    Option 4 is incorrect. Setting up separate Cloud Guard Targets for each new compartment introduces unnecessary overhead and complexity. Using a single Target at the root compartment level is a more efficient solution.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam