1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 16 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 16

Single answer

Your team has deployed an e-commerce application on Oracle Cloud Infrastructure (OCI) that stores sensitive customer data in an Autonomous Database. As part of a security review, the team wants to apply the principle of least privilege to manage administrative access to the database environment. Which approach best satisfies this requirement?

  1. A

    Create a single administrative user with read/write privileges for all OCI compartments and services.

  2. B

    Use a shared API key on a compute instance, granting it full tenancy-wide access to manage the database.

  3. C

    Place the database in a dedicated compartment and define IAM policies that grant only essential privileges to specific administrator groups.

  4. D

    Allow all users in the Administrators group to access the Autonomous Database by default, relying on manual approvals for critical queries.

Show answer and explanation

Correct answer: C

Explanation

Oracle Cloud Infrastructure security design principles recommend isolating sensitive resources in dedicated compartments and granting only the privileges necessary for specific roles. By segregating the Autonomous Database in a dedicated compartment, administrators can craft IAM policies tailored to the minimum required privileges. This safeguards sensitive data against unauthorized or overly broad access. Refer to OCI documentation on Compartment Security and IAM Policies for more information on implementing least privilege.

  • A. Incorrect.

    Option 1: This violates the principle of least privilege because a single administrative user with broad read/write privileges is over-privileged and can create unnecessary security risks.

  • B. Incorrect.

    Option 2: Using a shared API key on a compute instance with tenancy-wide permissions provides no granular control over database access, making it impossible to enforce strict privileges.

  • C. Correct.

    Option 3: Placing the database in its own compartment and granting specific groups only the privileges they need follows the principle of least privilege and limits the blast radius in case of compromised credentials.

  • D. Incorrect.

    Option 4: Automatically granting database access to the entire Administrators group is too broad and violates least privilege. Relying on manual approvals still gives all group members direct database access, which is not a recommended practice.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam