1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 24 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 24

Single answer

You are responsible for securing a new web application that processes sensitive data in Oracle Cloud Infrastructure (OCI). The application stores its data in Oracle Object Storage. You want to ensure you have full control over the encryption keys used to secure the stored data, including the ability to manage key rotation schedules. Which approach meets these requirements with minimal overhead?

  1. A

    Use Oracle-managed keys with server-side encryption automatically enabled on Object Storage.

  2. B

    Provision an OCI Vault, create a customer-managed master encryption key, configure Object Storage to use that key, and enable automatic key rotation.

  3. C

    Deploy a third-party hardware security module (HSM) in your on-premises data center and integrate it with OCI through a custom plug-in.

  4. D

    Rely on native Transparent Data Encryption (TDE) for Object Storage.

Show answer and explanation

Correct answer: B

Explanation

Oracle recommends using OCI Vault when you require full control over your encryption keys for services like Object Storage. This approach enables you to implement your own key management policies, including regular key rotation. Refer to OCI documentation on Vault and Key Management (https://docs.oracle.com/en-us/iaas/Content/KeyManagement/Concepts/keyoverview.htm) for best practices in configuring and managing customer-managed keys.

  • A. Incorrect.

    Option 1: While Oracle-managed keys are convenient, they do not provide customers with full control over key rotation or lifecycle management. The customer cannot configure the rotation schedule with Oracle-managed keys, so this does not meet the requirement for managing the keys directly.

  • B. Correct.

    Option 2: Provisioning an OCI Vault and creating a customer-managed key provides full control over the key lifecycle, including rotation scheduling. You can configure Object Storage to use this key for encryption, ensuring you maintain complete control and can automate key rotation, making this the best answer.

  • C. Incorrect.

    Option 3: Integrating a third-party HSM on-premises adds significant complexity and overhead. While theoretically possible, it would not be the most straightforward approach for aligning with OCI� native security features and automated rotation capabilities.

  • D. Incorrect.

    Option 4: Transparent Data Encryption (TDE) is a feature primarily used for database encryption. It does not apply to data stored in Object Storage, so it does not meet the stated requirements.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam