1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 3 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 3

Select 2

Your organization is migrating critical workloads to Oracle Cloud Infrastructure (OCI). You have been tasked with setting up the initial security configuration to align with the principle of least privilege. Which two actions should you prioritize to ensure that users only have access to the resources they need and to reduce the overall attack surface?

  1. A

    Create a single compartment for all resources and assign broad administrative privileges to administrators for easier maintenance

  2. B

    Organize resources into multiple compartments based on different functional or environment-specific requirements

  3. C

    Define and apply IAM policies that grant each user group only the permissions necessary to perform their tasks

  4. D

    Enable all advanced security features like Web Application Firewall (WAF) and Bastion by default, regardless of the environment� actual requirements

Show answer and explanation

Correct answers: B, C

Explanation

Implementing compartments and defining targeted IAM policies from the outset aligns with OCI best practices for least privilege. By segmenting resources and granting minimal but sufficient permissions, you reduce the potential blast radius of any security breach. Oracle� documentation emphasizes compartmentalization and precise policy management to maintain strong oversight of resource access while avoiding unnecessary privileges.

  • A. Incorrect.

    Incorrect. Consolidating all resources into a single compartment and assigning broad privileges contradicts the principle of least privilege. This approach increases the risk of unauthorized access if an administrator account is compromised, as it potentially grants them control over all resources.

  • B. Correct.

    Correct. Configuring separate compartments for different functional or environment-specific groups (e.g., Production, Development, Finance) is a best practice. Compartments help segment resources, allowing security boundaries to be properly enforced through policies.

  • C. Correct.

    Correct. IAM policies control who can access which resources and how. By granting only the necessary privileges to each group, you reduce the risk of accidental or malicious activity on resources outside a team� scope.

  • D. Incorrect.

    Incorrect. While enabling security features like WAF or Bastion when appropriate is important, turning them on indiscriminately without evaluating specific requirements can lead to unnecessary costs and complexity. Not all environments require every advanced security feature by default.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam