1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 27 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 27

Single answer

Your organization has an existing AdminGroup that is granted broad permissions via the policy: 'Allow group AdminGroup to manage all-resources in tenancy.' You create a new group called ProductionAdmins and add a policy to allow it to 'manage vcns in compartment ProductionCompartment.' However, members of ProductionAdmins can still manage compute resources in the ProductionCompartment. Which action is most likely to fix the issue so that ProductionAdmins can only manage VCNs in that compartment?

  1. A

    Remove ProductionAdmins from the AdminGroup so members don�t inherit the root-level policy

  2. B

    Raise the new policy to the root compartment level so it overrides the existing policy

  3. C

    Modify the policy to explicitly include a deny rule for compute resources in ProductionCompartment

  4. D

    Create a new dynamic group for ProductionCompartment and reassign ProductionAdmins there

Show answer and explanation

Correct answer: A

Explanation

When multiple policies apply, OCI evaluates them collectively. If a user or group has higher-level rights from one policy, no narrower policy will reduce those rights. Therefore, the most direct solution is to avoid overlapping memberships that grant full access. For details on IAM policy inheritance and best practices, see Oracle� documentation: https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/policyreference.htm.

  • A. Correct.

    Correct. If ProductionAdmins is also part of AdminGroup (which has 'manage all-resources in tenancy'), they inherit full permissions. Removing members from AdminGroup prevents inheritance of the broader privileges, ensuring they only manage VCNs in ProductionCompartment.

  • B. Incorrect.

    Incorrect. Moving the policy up to the root compartment doesn't remove the broader 'manage all-resources' permission already granted at the tenancy level to AdminGroup. Higher-level policies do not override or negate existing policies that allow broader access.

  • C. Incorrect.

    Incorrect. While deny rules can be used in certain scenarios, Oracle Cloud Infrastructure leverages allow-based policy control by default. It� more straightforward and recommended to remove the conflicting broader access (in this case by changing group membership) rather than apply blanket deny statements.

  • D. Incorrect.

    Incorrect. Simply placing the group members into a dynamic group wouldn�t remove the original 'manage all-resources' permission they inherit from being in the AdminGroup. Dynamic groups are typically used to assign policies based on instance or resource attributes, not to override user group policies.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam