1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 149 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 149

Select 2

Your organization has recently created additional compartments in Oracle Cloud Infrastructure (OCI). You�ve noticed that Cloud Guard� security findings do not include resources in these new compartments, even though Cloud Guard is active in the tenancy. You need to ensure all existing and future compartments are monitored without having to manually configure each one. Which two actions should you take?

  1. A

    Enable the 'Include All Compartments' coverage setting in the Cloud Guard Target configuration for the root compartment.

  2. B

    Grant Cloud Guard Viewer permissions in the newly created compartments so it can scan associated resources.

  3. C

    Create or update a detection recipe that targets the root compartment, ensuring any newly created compartments inherit coverage.

  4. D

    Manually enable Cloud Guard on each new compartment through the Security Zones console.

Show answer and explanation

Correct answers: A, C

Explanation

In OCI Cloud Guard, creating a Target at the root compartment and enabling coverage for all compartments removes the need for per-compartment configuration. You can further ensure automatic coverage by referencing the root compartment in your detection recipes, so any newly created compartments inherit the Cloud Guard monitoring. Refer to OCI documentation on Cloud Guard Targets (https://docs.oracle.com/en-us/iaas/cloud-guard/doc/cloud-guard-targets.html) for best practices in configuring tenancy-wide coverage.

  • A. Correct.

    Correct. By enabling 'Include All Compartments' coverage in your Cloud Guard Target at the root compartment level, you ensure that Cloud Guard automatically includes newly created compartments. This setting removes the need to individually configure coverage each time you create a compartment.

  • B. Incorrect.

    Incorrect. While Cloud Guard needs appropriate permissions, simply assigning the Cloud Guard Viewer role to newly created compartments does not automatically guarantee coverage. You still need to configure Cloud Guard Targets for the compartments you want monitored.

  • C. Correct.

    Correct. Using or updating a detection recipe that targets the root compartment ensures that newly created compartments within that root compartment are automatically included in Cloud Guard� detection scope. This is part of configuring coverage at the tenancy level.

  • D. Incorrect.

    Incorrect. Manually enabling Cloud Guard on each new compartment might work but is not efficient and doesn't address the requirement for automatic coverage. Security Zones are for enforcing security policies, not for universal Cloud Guard coverage.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam