1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 18 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 18

Single answer

Your organization is migrating an internal HR application to Oracle Cloud Infrastructure (OCI). This application processes sensitive personal data, so you need a deployment design that follows the principle of least privilege. Which approach best demonstrates this principle when configuring access to resources in OCI?

  1. A

    Create a single IAM group for all staff and assign broad management policies across all compartments to prevent accidental lockouts

  2. B

    Implement per-compartment IAM policies, granting just the necessary permissions to user groups for each environment

  3. C

    Deploy all compute instances on a public subnet and allow direct SSH access from the internet for efficient troubleshooting

  4. D

    Use a single compartment for all environments to simplify policy management and reduce administrative overhead

Show answer and explanation

Correct answer: B

Explanation

Following the principle of least privilege means granting users only the minimum set of access rights needed for their tasks. By implementing compartment-based IAM policies, you minimize risks associated with unauthorized or accidental access to sensitive data. For more details on designing secure architectures in OCI, refer to Oracle� official documentation on security best practices (https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_guide.htm).

  • A. Incorrect.

    Option 1 is incorrect. Granting broad permissions to a single group violates the principle of least privilege by providing more access than each user actually needs.

  • B. Correct.

    Option 2 is correct. Using per-compartment IAM policies and limiting each group� privileges to the minimum required directly aligns with the principle of least privilege.

  • C. Incorrect.

    Option 3 is incorrect. Placing all compute resources on a public subnet with open ingress introduces unnecessary risk and contravenes the principle of restricting access to only what� required.

  • D. Incorrect.

    Option 4 is incorrect. Combining all environments in a single compartment simplifies administration but increases blast radius and does not promote fine-grained access control.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam