1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 152 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 152

Single answer

Your organization has recently activated Security Zones and enabled Security Advisor in Oracle Cloud Infrastructure to enforce strict security policies. The Security Advisor flagged an existing Object Storage bucket for allowing public read access in a Security Zone where public access is prohibited. Which action should you take to rectify this issue while maintaining compliance?

  1. A

    Move the bucket to a non-Security Zone compartment, then reapply the same public read policy outside the security zone.

  2. B

    Rely on Security Advisor to automatically apply remediation actions by itself without any manual changes to the bucket's settings.

  3. C

    Modify the bucket to remove public access or change it to private, ensuring it adheres to Security Zone policies.

  4. D

    Disable the Security Zone temporarily, fix the bucket settings, then re-enable the Security Zone.

Show answer and explanation

Correct answer: C

Explanation

In a Security Zone, resources must comply with a set of enforced security policies. The Security Advisor identifies non-compliant configurations but does not automatically remediate them. Per Oracle Cloud Infrastructure best practices, you should correct the flagged resource to align with the enforced security policies�here, by removing public access or making the bucket private. Moving or recreating the resource outside of a Security Zone circumvents the protections, and temporarily disabling the security zone is not recommended because it lowers your overall security posture. For more details, consult Oracle Security Zones documentation on effectively remediating flagged resources.

  • A. Incorrect.

    Option A is incorrect because simply moving the bucket outside the security zone defeats the purpose of applying strict security controls. Moreover, you would still need to address the public access issue, which is disallowed by best practices whether or not you�re using a security zone.

  • B. Incorrect.

    Option B is incorrect because Security Advisor only flags potential issues and provides recommendations; it does not automatically enforce corrections. You must manually update the resource so that it aligns with the recommended settings.

  • C. Correct.

    Option C is correct because removing the public read policy or changing the bucket to private resolves the non-compliance issue while keeping the bucket within the security zone. This aligns with the security policies enforced by Security Zones and the guidance provided by Security Advisor.

  • D. Incorrect.

    Option D is incorrect because disabling the security zone just to fix the configuration undermines the security posture. Best practice is to correct the resource configuration while the security zone remains in force.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam