1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 151 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 151

Select 2

You have a Security Zone in your tenancy that enforces strict rules against publicly accessible storage buckets. The Security Advisor flags a bucket in this zone as publicly accessible. The development team needs external read access for some objects in that bucket. Which two steps should you take to resolve the Security Advisor� recommendation while maintaining a secure environment?

  1. A

    A. Configure an IAM policy to allow anonymous read access and disable the conflicting Security Zone rule for the bucket.

  2. B

    B. Remove public access from the bucket so that it complies with the Security Zone policy requirements.

  3. C

    C. Delete the bucket in the Security Zone and re-create it in a standard compartment if public access is absolutely required.

  4. D

    D. Attach a new VCN security list to the bucket� resource configuration to restrict unauthorized IP ranges.

Show answer and explanation

Correct answers: B, C

Explanation

In Oracle Cloud Infrastructure Security Zones, object storage buckets must not be publicly accessible to comply with security rules. When the Security Advisor identifies such a violation, you must either remove public access for the bucket to make it compliant or, if external access is absolutely necessary, recreate it in a non-Security Zone compartment. References: Oracle Documentation on Security Zones and the Security Advisor outlines these requirements and best practices for handling publicly accessible resources.

  • A. Incorrect.

    A. Incorrect. Disabling the Security Zone rule contradicts the principle of the Security Zone and isn't supported as a best practice. Configuring an IAM policy to allow anonymous read would keep the bucket publicly accessible, which violates Security Zone constraints.

  • B. Correct.

    B. Correct. One valid approach is to remove the public access setting on the bucket, so it fully complies with Security Zone requirements. This ensures no public endpoint is exposed and aligns with secure best practices.

  • C. Correct.

    C. Correct. If public access is a hard requirement for your business use case, recreating the bucket outside the Security Zone is necessary. You cannot simply convert or move a bucket from a Security Zone to a standard compartment without re-creating it; the Security Zone policy enforces strict limitations to prevent public exposure.

  • D. Incorrect.

    D. Incorrect. Attaching a new VCN security list is not applicable to object storage buckets, and even if you could restrict IP ranges, it would not address the fundamental public access violation flagged by the Security Advisor.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam