1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 171 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 171

Single answer

Your security team requires immediate notifications whenever a Security List is modified in your Oracle Cloud Infrastructure (OCI) network. You have configured OCI Logging to capture relevant events. Which approach should you implement to ensure your team is automatically alerted in real-time when a Security List is changed?

  1. A

    Enable and analyze VCN Flow Logs, then manually review the logs to detect Security List changes.

  2. B

    Create an OCI Event rule that triggers on 'UpdateSecurityList' and delivers notifications to an OCI Notifications topic subscribed by the security team.

  3. C

    Deploy an Oracle Cloud Guard Detector Recipe to automatically remediate any network configuration change in the VCN.

  4. D

    Use Logging Analytics to periodically query for Security List modifications and send email reports to the security team.

Show answer and explanation

Correct answer: B

Explanation

To receive timely alerts about Security List modifications, you must use OCI Events in conjunction with OCI Notifications. You define a rule in the Events service that specifies the Security List resource type and the 'UpdateSecurityList' event type. This rule then triggers an action, such as publishing a message to an OCI Notifications topic. Subscribed team members or systems will receive immediate notifications. Refer to Oracle documentation on Logging and Events for best practices and architectural guidance.

  • A. Incorrect.

    Option 1 is incorrect. VCN Flow Logs capture traffic flow information, not configuration changes to Security Lists. Manually reviewing these logs does not provide real-time alerts or specific resource change tracking.

  • B. Correct.

    Option 2 is correct. Configuring an OCI Event rule for 'UpdateSecurityList' will generate an event each time that resource is changed. By routing the event to OCI Notifications, you can send automated, real-time alerts to subscribed channels (e.g., email, pager, or Slack).

  • C. Incorrect.

    Option 3 is incorrect. While Cloud Guard can detect and raise findings for certain misconfigurations, you must specifically configure relevant detectors and policies. Simply deploying a Detector Recipe does not guarantee granular alerts for every Security List modification in real-time.

  • D. Incorrect.

    Option 4 is incorrect. Logging Analytics is ideal for deeper log analysis and pattern detection, but it typically involves periodic queries or scheduled searches. This would not provide immediate (�near real-time�) alerts on Security List changes.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam