1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 150 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 150

Select 2

Your organization recently experienced a security incident where an internal Object Storage bucket was unintentionally exposed to the public. You have enabled Cloud Guard across your tenancy and want to ensure that any future misconfigurations in your Object Storage buckets are automatically detected and remediated. Which two Cloud Guard actions should you configure to address this requirement?

  1. A

    Enable the relevant Detector recipe for misconfigured Object Storage buckets.

  2. B

    Create a Responder recipe that revokes public access on misconfigured buckets.

  3. C

    Disable Cloud Guard scanning for Object Storage to reduce potential false positives.

  4. D

    Require manual review for each suspicious alert before taking any remediation.

  5. E

    Run on-demand scanning in Cloud Guard only when you suspect a misconfiguration.

Show answer and explanation

Correct answers: A, B

Explanation

Cloud Guard uses Detector recipes to monitor configurations and Responder recipes to automate remediation actions. To continuously protect Object Storage from unintended public exposure, you must enable the correct Detector recipe and pair it with a Responder recipe that revokes public access. Relying solely on manual reviews or on-demand scans increases the risk of delayed or missed detections. Refer to Oracle Cloud Guard documentation for best practices on creating Detector and Responder recipes to maintain a robust security posture.

  • A. Correct.

    Option 1 is correct. Detector recipes define the rules that identify risky configurations or activities, such as publicly accessible Object Storage buckets. Enabling this Detector ensures Cloud Guard continuously checks for that specific misconfiguration.

  • B. Correct.

    Option 2 is correct. Responder recipes specify automated actions to take when a detector rule triggers. Configuring a Responder recipe to revoke public access on a discovered misconfigured bucket handles remediation promptly and minimizes risk.

  • C. Incorrect.

    Option 3 is incorrect. Disabling Cloud Guard scanning for Object Storage would defeat the purpose of automatically detecting misconfigurations; it would leave infrastructure changes unmonitored, increasing security risks.

  • D. Incorrect.

    Option 4 is incorrect. While manual reviews can be performed for certain alerts, relying solely on manual intervention may delay remediation. Cloud Guard is designed to automate both detection and response where appropriate.

  • E. Incorrect.

    Option 5 is incorrect. Running only on-demand scanning would not offer continuous protection. Continuous monitoring is essential to identify misconfigurations in real time and remediate quickly.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam