1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 31 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 31

Select 2

Your organization has created a group called 'Operations' in Oracle Cloud Infrastructure (OCI) and assigned it a policy allowing the group to manage all resources in the 'ProdCompartment'. Recently, you discovered that group members can also create new compartments, which violates your security policy. You only want the 'Operations' group to manage compute instances in the 'ProdCompartment' without granting them permission to create or delete compartments. Which two actions should you take to achieve this goal? (Choose two.)

  1. A

    A. Add a new policy allowing the 'Operations' group to use compartments in the 'ProdCompartment' instead of managing them.

  2. B

    B. Add a policy: 'Allow group Operations to manage compartment in compartment ProdCompartment.'

  3. C

    C. Modify the existing policy from 'manage all-resources in compartment ProdCompartment' to 'manage instance-family in compartment ProdCompartment.'

  4. D

    D. Remove any blanket policy that grants the 'Operations' group 'manage all-resources' at the tenancy level.

  5. E

    E. Assign the 'Operations' group to a dynamic group to restrict compartment creation.

Show answer and explanation

Correct answers: C, D

Explanation

To align with the principle of least privilege, you must remove any overreaching permissions and specify only what the group can manage. According to OCI best practices, broad policies like 'manage all-resources' grant extensive privileges, including compartment creation. By adjusting your policy to 'manage instance-family in compartment ProdCompartment' and removing any tenancy-wide privileges that allow 'manage all-resources,' you ensure the 'Operations' group is restricted to managing compute instances without the ability to manage or create new compartments. Refer to OCI Identity and Access Management documentation for details on the 'manage instance-family' permission scope and best practices for compartment-level policies.

  • A. Incorrect.

    A. INCORRECT. The 'use compartments' permission allows reading compartment metadata, but the underlying 'manage all-resources' policy still confers the ability to manage all services if it remains in place. Simply adding a new policy is not enough if you don't remove or modify the existing one that grants broader privileges.

  • B. Incorrect.

    B. INCORRECT. Allowing the group to 'manage compartment' in the 'ProdCompartment' would still grant the ability to create or modify compartments nested underneath. This does not remove the compartment creation capability you want to restrict.

  • C. Correct.

    C. CORRECT. Changing the policy to 'manage instance-family in compartment ProdCompartment' limits the 'Operations' group to managing compute instances without permitting the creation of new compartments. According to Oracle Documentation, 'manage instance-family' grants privileges specifically for compute instance operations.

  • D. Correct.

    D. CORRECT. Any broad policy (e.g., 'manage all-resources in tenancy') at the tenancy level must be removed or restricted if you want to prevent compartment creation. 'manage all-resources' includes the right to create and delete compartments.

  • E. Incorrect.

    E. INCORRECT. Dynamic groups are used for resources (e.g., instances) defined by rules rather than IAM user accounts. Converting the 'Operations' group to a dynamic group is neither necessary nor does it address the compartment creation issue.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam