1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 157 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 157

Single answer

You are a Security Administrator at a large enterprise using Oracle Cloud Infrastructure (OCI). You have recently noticed suspicious login attempts from a known malicious IP address to an important compartment within your tenancy. As part of investigating whether an internal IAM user has been compromised, you want to leverage OCI Threat Intelligence to identify rogue user activity. Which approach should you implement to confirm unauthorized activity and immediately block any further malicious attempts?

  1. A

    Integrate Cloud Guard with OCI Threat Intelligence to detect and alert on known malicious IP addresses, then create a custom responder recipe to quarantine the compromised user automatically.

  2. B

    Disable all IAM users except the root user until the pre-existing firewall rules are updated to deny that IP range.

  3. C

    Schedule a daily manual check of the Audit service logs for suspicious IP addresses, reporting any anomalies to the Security Teams after 24 hours.

  4. D

    Terminate all compute instances in the compromised compartment to remove any potential infiltration by the malicious IP address, then re-deploy from scratch.

Show answer and explanation

Correct answer: A

Explanation

OCI Threat Intelligence integrates seamlessly with Cloud Guard to detect known malicious IP addresses in near real time. By creating custom responder recipes, you automate remediation steps�such as quarantining the identified user�while maintaining minimal disruption to other services. Refer to OCI Cloud Guard and Threat Intelligence documentation for configuration details and best practices on responding to high-risk events.

  • A. Correct.

    Correct. Cloud Guard integrates with OCI Threat Intelligence to profile malicious IP addresses. By creating a custom responder recipe, you can trigger automated actions like quarantining or disabling an IAM user once suspicious activity is confirmed. This approach is proactive and prevents further unauthorized access.

  • B. Incorrect.

    Incorrect. Disabling all IAM users except root is overly disruptive and does not leverage Threat Intelligence to identify a specific compromised user. It also risks halting critical operations for legitimate users.

  • C. Incorrect.

    Incorrect. Manual inspection of logs on a daily basis leaves a large detection gap and fails to leverage real-time threat intelligence. Meanwhile, the rogue user could continue exploiting resources unnoticed.

  • D. Incorrect.

    Incorrect. Terminating all compute instances is a drastic measure and does not isolate or identify the compromised user. While it may remove some attack vectors, it does not address the root cause (the suspicious IAM user) and can cause unnecessary downtime.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam