1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 28 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 28

Select 2

Your organization uses Oracle Cloud Infrastructure (OCI) to separate Dev, Test, and Production workloads into their own compartments. A new Auditors group needs to read logs across all compartments but only manage logs in the Dev compartment. They must not have any additional privileges in Test or Production. Which two policy statements will meet these requirements while following the principle of least privilege?

  1. A
    1. Allow group Auditors to read logging-family in tenancy
  2. B
    1. Allow group Auditors to read logging-family in root compartment only
  3. C
    1. Allow group Auditors to manage logging-family in compartment Dev
  4. D
    1. Allow group Auditors to manage logging-family in tenancy
Show answer and explanation

Correct answers: A, C

Explanation

By using 'read logging-family in tenancy' and 'manage logging-family in compartment Dev,' you ensure that Auditors have the necessary read access across all compartments while restricting elevated (manage) privileges to Dev. This enforces the principle of least privilege. For more details, refer to the Oracle Cloud Infrastructure Identity and Access Management (IAM) policy documentation, which outlines best practices for creating minimal yet sufficient policies for different resource types and compartments.

  • A. Correct.

    Option 1 is correct. Assigning read privileges over the 'logging-family' resource type in the entire tenancy gives Auditors the ability to read logs in all compartments. This meets the requirement to read logs across all environments.

  • B. Incorrect.

    Option 2 is incorrect. Limiting the read privileges to only the root compartment will not allow Auditors to see logs in other compartments (Test and Production) unless explicitly inherited by subcompartments, which would not meet the requirement to read logs across all compartments.

  • C. Correct.

    Option 3 is correct. Granting 'manage' privileges in the Dev compartment allows Auditors to create, update, and delete logs within Dev. This is the desired elevated privilege for the Dev compartment and satisfies the requirement without granting too many privileges elsewhere.

  • D. Incorrect.

    Option 4 is incorrect. Granting 'manage' privileges at the tenancy level would let the Auditors group manage logs across all compartments (Dev, Test, and Production), which conflicts with the requirement to limit management actions to the Dev compartment only.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam