1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 153 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 153

Select 2

Your organization has created a dedicated Security Zone compartment to protect sensitive data. After deploying resources, the Security Advisor flags two issues: multiple block volumes are not encrypted, and there is at least one externally accessible subnet in the same Security Zone compartment. Which two actions should you take to correct these issues according to best practices?

  1. A

    Convert the block volumes to ephemeral volumes, thus bypassing encryption requirements.

  2. B

    Enable encryption at rest for the block volumes to meet Security Zone standards.

  3. C

    Create a public subnet and allow internal resources to connect via an Internet Gateway.

  4. D

    Remove or reconfigure the externally accessible subnet to restrict public access.

Show answer and explanation

Correct answers: B, D

Explanation

Security Zones enforce compartment-level security requirements, including mandatory encryption for storage volumes and restricted public access to subnets. The Security Advisor identifies these violations and recommends remediation steps, such as enabling encryption and removing or reconfiguring public subnets. For more details, refer to the Oracle Cloud Infrastructure documentation on Security Zones and the Security Advisor.

  • A. Incorrect.

    Option 1 is incorrect. Converting block volumes to ephemeral volumes does not address encryption requirements. Security Zones require encryption, and ephemeral volumes do not negate that requirement.

  • B. Correct.

    Option 2 is correct. Enabling encryption at rest for block volumes is a common Security Zone policy requirement. This ensures data is secured and meets the enforced security posture.

  • C. Incorrect.

    Option 3 is incorrect. Creating or remaining with a publicly accessible subnet contradicts Security Zone best practices. Public subnets are typically flagged by the Security Advisor if they exist in a compartment designated as a Security Zone.

  • D. Correct.

    Option 4 is correct. Restricting or removing externally accessible subnets aligns with Security Zone requirements, which generally prohibit public internet access to resources in the compartment.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam