1Z0-1104-25 Question 146
Select 2Your organization runs critical workloads across multiple compartments and regions in Oracle Cloud Infrastructure (OCI). You have enabled Cloud Guard to monitor these resources, but you notice that the security posture details in the Cloud Guard console are incomplete. Which two steps must you take to ensure that Cloud Guard can fully assess your entire OCI environment for potential security threats? (Choose two.)
- A
Configure an aggregator target that includes all relevant compartments.
- B
Enable custom threat feeds in the Cloud Guard console.
- C
Enable Cloud Guard in each region hosting resources.
- D
Create a separate Cloud Guard target for every user account.
- E
Associate all resource instances directly with Cloud Guard detectors.
Show answer and explanation
Correct answers: A, C
Explanation
To achieve comprehensive monitoring and analysis using Cloud Guard, you must define the correct scope of resources by including all applicable compartments in a Cloud Guard target and enabling Cloud Guard in all regions where resources reside. This ensures full visibility into your organization's security posture. Refer to the OCI documentation on Cloud Guard Targets (https://docs.oracle.com/en-us/iaas/Content/cloud-guard/using/targets.htm) for guidance on configuring multi-compartment and multi-region coverage.
- A. Correct.
Correct. Cloud Guard uses targets to define the scope of which resources are monitored. An aggregator target can include multiple compartments, ensuring that Cloud Guard evaluates all relevant resources in those compartments. Without adding the correct compartments to your target, Cloud Guard can't assess them.
- B. Incorrect.
Incorrect. Enabling custom threat feeds is useful for leveraging external security intelligence, but it does not affect which compartments or regions Cloud Guard monitors. It� an optional configuration that enhances detections but does not determine coverage of your OCI environment.
- C. Correct.
Correct. Cloud Guard must be enabled in every region where you have resources. If you omit a region where resources are deployed, Cloud Guard cannot monitor or generate findings for that region, resulting in incomplete visibility.
- D. Incorrect.
Incorrect. You do not need to create separate Cloud Guard targets for each user account. Typically, you create targets based on compartments or cost centers rather than individual user accounts. This approach would also complicate administration unnecessarily.
- E. Incorrect.
Incorrect. You do not associate individual resources directly with Cloud Guard detectors. Instead, you specify a target (aggregator or compartment-level) and associated detector recipes. Cloud Guard automatically scans all resources under that scope without requiring manual per-resource configuration.