1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 2 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 2

Select 2

Your organization has discovered that certain Object Storage buckets in OCI are publicly accessible and some network security rules are overly permissive. The security team wants a solution that continuously detects misconfigurations and can automatically remediate them. Which TWO OCI services can you combine to achieve both real-time visibility and automated corrective actions for these security issues?

  1. A

    Cloud Guard

  2. B

    Data Safe

  3. C

    Security Zones

  4. D

    Vault

  5. E

    Vulnerability Scanning Service

Show answer and explanation

Correct answers: A, C

Explanation

Cloud Guard provides continuous security monitoring and automated remediation via responder rules, making it an excellent choice for detecting and resolving issues like publicly exposed buckets or permissive network rules. Security Zones enforce secure configurations from the start, blocking high-risk actions in designated compartments. Together, these two services address real-time detection, enforcement, and auto-remediation of misconfigurations. Refer to Oracle� Cloud Guard and Security Zones documentation for best practices and configuration details.

  • A. Correct.

    Cloud Guard is correct because it monitors resources continuously for security risks and can automate remediation through responder rules, making it ideal for detecting and fixing exposed buckets or permissive security rules.

  • B. Incorrect.

    Data Safe is incorrect because it primarily focuses on database security features like user assessment, data discovery, and activity auditing. It does not provide the continuous infrastructure misconfiguration detection and automated remediation you need for Object Storage buckets or network security configurations.

  • C. Correct.

    Security Zones is correct because it enforces security best practices from the outset. If a compartment is designated as a Security Zone, OCI prevents many misconfigurations (such as creating a public bucket) from ever happening. Used together with Cloud Guard, you get both enforcement and real-time detection/remediation.

  • D. Incorrect.

    Vault is incorrect because it provides centralized key management and supports data encryption, but it does not continuously monitor or remediate misconfigurations in OCI resources.

  • E. Incorrect.

    Vulnerability Scanning Service is incorrect because it focuses on scanning compute instances and load balancers for known vulnerabilities and open ports, rather than misconfigured Object Storage buckets or overly permissive network rules.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam