1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 159 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 159

Select 2

You suspect that a handful of user accounts in your OCI environment may be compromised because they are logging in from IP addresses flagged by Oracle Cloud Infrastructure Threat Intelligence as malicious. You want to identify these rogue users, investigate their suspicious activities, and guard against possible breaches while minimizing disruption to legitimate users. Which two actions should you take to achieve this objective?

  1. A
    1. Integrate Threat Intelligence with OCI Cloud Guard to automatically generate incidents for logins originating from malicious IP addresses, then use these incidents to investigate and quarantine suspicious users.
  2. B
    1. Immediately block all IP addresses listed in the threat feed at the VCN level for the entire OCI tenancy without further verification.
  3. C
    1. Collect and analyze all recent sign-in events via OCI Logging, then compare known malicious IP addresses from Threat Intelligence to generate alerts or notifications for suspicious logins.
  4. D
    1. Disable all IAM user credentials across the OCI tenancy and re-enable them once the flagged IP addresses are validated as legitimate or malicious.
Show answer and explanation

Correct answers: A, C

Explanation

A common best practice is to automate threat detection wherever possible and only take targeted enforcement actions against suspicious accounts or IP addresses. Integrating Oracle Cloud Infrastructure Threat Intelligence with Cloud Guard allows for prompt incident creation when logins originate from known malicious IPs, enabling focused investigations and timely countermeasures. Additionally, analyzing sign-in logs and cross-referencing them with threat feeds is an effective method to spot anomalies without affecting legitimate traffic or users. For more details, refer to OCI documentation on 'Using Oracle Cloud Infrastructure Threat Intelligence' and 'Working with Cloud Guard.'

  • A. Correct.

    Explanation for Option 1: This is correct. By integrating OCI Threat Intelligence with Cloud Guard, you can automatically generate incidents whenever a user attempts to log in from a flagged IP address. These incidents let you quickly identify and investigate potential rogue users. You can then decide on targeted corrective actions (such as isolating or locking specific accounts) without disrupting other legitimate users.

  • B. Incorrect.

    Explanation for Option 2: This is incorrect. Completely blocking every IP address listed on the threat feed at once can cause unnecessary disruption for valid traffic that may occasionally appear on threat lists (e.g., due to dynamic IP allocation). It� best practice to investigate suspicious IPs more granularly rather than issuing a blanket block.

  • C. Correct.

    Explanation for Option 3: This is correct. By collecting sign-in logs through OCI Logging and cross-referencing them with Threat Intelligence data, you isolate suspicious login attempts associated with known malicious IPs. Setting up notifications and alerts around these events allows you to monitor anomalous behavior in near real-time and respond quickly.

  • D. Incorrect.

    Explanation for Option 4: This is incorrect. Disabling all IAM credentials tenant-wide is overly disruptive and does not discriminate between genuine and potentially compromised accounts. It stalls normal operations and is not a best practice. Instead, you should focus your enforcement actions on the few accounts flagged by Cloud Guard or via direct investigation.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam