1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 147 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 147

Single answer

Your organization has recently spun up a new development compartment in Oracle Cloud Infrastructure (OCI) with unique configuration requirements that deviate from standard production security policies. You have Cloud Guard enabled at the tenancy level for continuous monitoring. However, you notice an influx of false positives related to your development compartment. You want to minimize noise while still monitoring the rest of your OCI resources across other compartments. Which approach should you take?

  1. A

    Disable Cloud Guard at the tenancy level to avoid false positives in the dev compartment.

  2. B

    Create a dedicated Cloud Guard target for the development compartment and apply a custom detector recipe tailored to the dev environment.

  3. C

    Mark individual development instances as 'excluded' in the Cloud Guard console so they are not scanned.

  4. D

    Use the default Cloud Guard target for the entire tenancy, but manually archive any incidents from the dev compartment.

Show answer and explanation

Correct answer: B

Explanation

To tailor Cloud Guard to your environment, you can create separate targets and apply custom detector recipes, allowing you to maintain appropriate security controls in specialized compartments like development. This approach mitigates false positives while preserving overall monitoring. For detailed guidance, refer to Oracle's documentation on creating Cloud Guard targets, detector recipes, and configuring scope settings in OCI.

  • A. Incorrect.

    Option 1: Disabling Cloud Guard at the tenancy level is too broad. This would remove coverage for all resources, which defeats the purpose of continuous monitoring.

  • B. Correct.

    Option 2: This is the correct solution. By creating a separate Cloud Guard target and applying a custom detector recipe, you can accommodate the dev compartment's unique security needs while still monitoring it effectively. This reduces false positives while maintaining coverage.

  • C. Incorrect.

    Option 3: Simply marking instances as 'excluded' without proper configuration or a targeted recipe is not recommended because it may ignore valid issues or create operational overhead. Cloud Guard does not provide a blanket 'exclude' setting at the individual resource level in this manner.

  • D. Incorrect.

    Option 4: Relying on the default target for the entire tenancy and manually archiving incidents will cause unnecessary manual intervention. It is more efficient to adjust the detection rules for the dev compartment from the start by using separate targets and custom detector recipes.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam