1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 36 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 36

Single answer

Your company has two groups in Oracle Cloud Infrastructure (OCI): 'Finance' and 'Dev'. The Finance team needs read-only access to all resources across your tenancy for auditing, while the Dev team should only have the ability to create and manage resources in a specific compartment named 'DevCompartment'. Which approach best meets both requirements in accordance with OCI IAM best practices?

  1. A

    Create a policy in the root compartment that allows the Finance group to inspect all resources and the Dev group to manage all resources in DevCompartment.

  2. B

    Grant the Finance group the Administrator role for the entire tenancy and the Dev group the Administrator role for DevCompartment.

  3. C

    Attach a custom policy to the DevCompartment that allows the Finance group to manage all resources, while granting the Dev group only read access in that compartment.

  4. D

    Use only default policies created at tenancy level, relying on the built-in Administrator policy for DevCompartment.

Show answer and explanation

Correct answer: A

Explanation

The key to meeting the scenario requirements is understanding how OCI policies work at different levels. By placing the correct policy in the root compartment to differentiate the Dev group� scope (only manage in DevCompartment) and the Finance group� privileges (inspect or read-only across the tenancy), you maintain tight access controls while adhering to OCI IAM best practices. Refer to Oracle� official documentation on IAM policies for precise policy syntax and best practice guidelines (https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/policies.htm).

  • A. Correct.

    Option 1 is correct. You achieve the goal by creating policies at the root (tenancy) level. For Finance: 'Allow group Finance to inspect all-resources in tenancy' provides read-only privileges across all compartments, and for Dev: 'Allow group Dev to manage all-resources in compartment DevCompartment' gives the desired scope. This setup follows OCI best practices by using minimal privileges for each group and restricting Dev� scope to DevCompartment.

  • B. Incorrect.

    Option 2 is incorrect. Granting the Administrator role to any group confers wide-ranging privileges that exceed simple read or compartment-limited management. It violates the principle of least privilege and would give both groups more access than required.

  • C. Incorrect.

    Option 3 is incorrect. This policy is reversed: it grants management permissions to Finance and only read permissions to Dev. It does not match the specified requirement of read-only for Finance across the tenancy and compartment-limited management for Dev.

  • D. Incorrect.

    Option 4 is incorrect. Default tenancy-level Administrator policies grant full access across all compartments, which is more access than the Dev group needs and does not satisfy Finance� read-only requirement.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam