1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 35 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 35

Select 2

Your organization has recently set up a SAML-based federation with Oracle Cloud Infrastructure (OCI) so employees can sign in using their corporate credentials. A group of testers needs the ability to create and manage compute resources in the 'DevTest' compartment. However, the testers are still encountering 'not authorized' errors when attempting to provision compute instances in that compartment. Which two steps should you take to ensure the testers can successfully create and manage compute instances in the 'DevTest' compartment?

  1. A

    Create an IAM policy that grants the federated group permission to manage compute resources in the 'DevTest' compartment.

  2. B

    Register the SAML identity provider in a local identity domain scoped to the 'DevTest' compartment.

  3. C

    Add each tester to the built-in Administrators group in the tenancy to ensure full access rights.

  4. D

    Map the relevant user group in your external identity provider (IdP) to the corresponding federated group in OCI.

  5. E

    Grant the tenancy-level Tag Administrators policy to the federated group to enable resource provisioning.

Show answer and explanation

Correct answers: A, D

Explanation

To enable SAML-federated users to manage compute resources in Oracle Cloud Infrastructure, you must map the external identity provider group to an OCI group and then create a policy granting that OCI group the necessary permissions on the targeted compartment. For more details, see the Oracle Cloud Infrastructure documentation on 'Federating with Identity Providers' and 'Managing Groups and Policies'.

  • A. Correct.

    Correct. Federated users must be assigned to an OCI group that has an appropriate IAM policy granting the necessary permissions on the relevant compartment. Without an explicit policy, users will see 'not authorized' errors.

  • B. Incorrect.

    Incorrect. Federation is typically set up at the tenancy (root) level, not within a specific compartment� local identity domain. You do not register an IdP per compartment.

  • C. Incorrect.

    Incorrect. Adding users to the built-in Administrators group grants them full access across the tenancy. This violates the principle of least privilege and is not recommended for targeted access.

  • D. Correct.

    Correct. Identity federation in OCI requires mapping the IdP group to an OCI group. This ensures that members of the IdP group assume the correct OCI group membership and thus the correct permissions.

  • E. Incorrect.

    Incorrect. Granting a Tag Administrators policy only provides privileges to manage tagging. It does not grant permission to manage compute resources in a specific compartment.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam