1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 20 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 20

Select 2

You are deploying a microservices-based application in Oracle Cloud Infrastructure (OCI) with a public-facing load balancer and a back-end database. The security team requires that database credentials be centrally stored, regularly rotated, and accessible only to the microservices that need them. Which two actions should you take to fulfill these requirements using OCI� core security services?

  1. A

    Create an IAM policy granting the microservices permission to retrieve and decrypt secrets from OCI Vault.

  2. B

    Include the database credentials directly in your microservices� container images for simplicity.

  3. C

    Use the OCI Bastion service to obtain credentials via SSH sessions whenever the microservices need to connect to the database.

  4. D

    Store the database credentials as secrets in OCI Vault and set up a rotation policy for automatic key and secret updates.

  5. E

    Enable public internet access for OCI Vault so the microservices can easily fetch the credentials.

Show answer and explanation

Correct answers: A, D

Explanation

To securely manage sensitive credentials in OCI, leverage the native OCI Vault service and IAM policies. OCI Vault allows you to store secrets (such as database credentials) and configure rotation policies to automate updates and reduce risk. Proper IAM policies ensure that only the correct instances or microservices can decrypt and retrieve these credentials. Refer to OCI Security and Vault documentation for detailed best practices on storing, rotating, and granting controlled access to secrets.

  • A. Correct.

    Correct. An IAM policy must be configured to allow only the appropriate microservice or instance principal to access secrets in the Vault, ensuring least privilege.

  • B. Incorrect.

    Incorrect. Storing credentials inside container images violates best practices because it can expose sensitive information if the container is pulled from an external repository or if the image is compromised.

  • C. Incorrect.

    Incorrect. OCI Bastion is primarily used for secure, controlled SSH access to private resources. It does not replace secret storage or provide automatic rotation for credentials.

  • D. Correct.

    Correct. Using OCI Vault to store and rotate secrets is a recommended best practice for secure credential management. Automatic rotation helps maintain compliance and reduce the risk of credential exposure.

  • E. Incorrect.

    Incorrect. Granting public access to Vault secrets is a security risk. OCI Vault should only be accessible via properly configured IAM policies and private connectivity.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam