1Z0-1104-25 Question 155
Select 2You have created a new Security Zone in Oracle Cloud Infrastructure (OCI) and applied it to a compartment containing existing network resources. Afterward, Security Advisor flagged multiple critical issues indicating that some resources violate the newly enforced Security Zone requirements. To ensure all resources comply with best practices, which two actions should you take?
- A
Migrate non-compliant resources to a non-security compartment if they cannot be brought into compliance.
- B
Adopt Security Advisor� recommended changes and modify the flagged resources to meet Security Zone policies.
- C
Disable the Security Zone to stop Security Advisor from flagging existing resources.
- D
Implement a custom IAM policy to override Security Zone rules for existing non-compliant resources.
Show answer and explanation
Correct answers: A, B
Explanation
Security Zones apply strict guardrails by preventing or flagging resource configurations that violate best practices. If resources cannot be reconfigured to meet these policies, you should move them to a standard compartment. For resources that can be remediated, follow Security Advisor� guidance. Consult the OCI Security Zones documentation (docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_zone-intro.htm) and Security Advisor best practices for recommended configurations.
- A. Correct.
Option 1: Correct. If certain resources cannot be configured to meet Security Zone requirements, moving them to a regular compartment ensures compliance with your organization� policies while maintaining the Security Zone� integrity.
- B. Correct.
Option 2: Correct. Security Advisor provides actionable recommendations for bringing resources into compliance with Security Zone policies. Applying these changes helps fix the identified misconfigurations.
- C. Incorrect.
Option 3: Incorrect. Disabling the Security Zone undermines its purpose of enforcing security requirements and leaves existing issues unresolved.
- D. Incorrect.
Option 4: Incorrect. An IAM policy cannot override Security Zone rules, which are enforced at a deeper level to ensure best-practice configurations.