1Z0-1104-25 Question 148
Single answerYour organization manages multiple compartments in OCI to separate development, testing, and production resources. You have enabled Cloud Guard for your tenancy, but after analyzing the findings, you realize that certain critical compartments are not being monitored. Which action should you take to ensure Cloud Guard includes those missing compartments in its analysis?
- A
Add the missing compartments to the existing Cloud Guard target scope.
- B
Create a new user group for each missing compartment and enable Cloud Guard for those groups.
- C
Switch Cloud Guard to Read-Only mode and wait for the service to automatically discover all compartments.
- D
Enable a separate compartment-level governance recipe for each missing compartment within Cloud Guard.
Show answer and explanation
Correct answer: A
Explanation
When using Cloud Guard, you define 'targets' to specify the compartments (or the entire tenancy) that the service should monitor. If some compartments are missing in Cloud Guard findings, you need to update the existing target configuration to include those compartments. Refer to Oracle Cloud Infrastructure documentation on Cloud Guard for details on setting up and managing targets.
- A. Correct.
Correct. Cloud Guard uses targets to define the scope of resources it monitors. You must explicitly add all relevant compartments to the target scope so Cloud Guard can track and flag security issues in those compartments.
- B. Incorrect.
Incorrect. Cloud Guard scopes are not defined by user groups. While groups and compartments are common ways to manage OCI access, Cloud Guard monitoring is configured at the target level to specify compartments, not user groups.
- C. Incorrect.
Incorrect. Cloud Guard� Read-Only mode prevents automatic or manual changes to the environment. It does not automatically discover or include all compartments. You must explicitly configure which compartments should be monitored.
- D. Incorrect.
Incorrect. While you can customize policies (recipes) at the target level, creating a separate governance recipe for each compartment is not the recommended approach. It is more efficient to add compartments under a single target with an appropriate recipe for consistent monitoring.