1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 39 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 39

Select 2

Your organization has created a new IAM domain (named 'BU_Acquired') in Oracle Cloud Infrastructure to isolate an acquired business unit. You must grant the new employees in that domain read-only access to the existing 'Finance' compartment in the main domain, without granting them any other privileges. Which two steps must you take to achieve this requirement?

  1. A

    Create a group in the BU_Acquired domain for the new employees and add the users to it.

  2. B

    Attach a policy in the BU_Acquired domain that directly references the Finance compartment in the main domain for read access.

  3. C

    Create a policy in the main domain that grants the group in the BU_Acquired domain read-only access to the Finance compartment.

  4. D

    Assign the new employees to the built-in Administrators group in the BU_Acquired domain to automatically inherit read privileges on the Finance compartment.

  5. E

    Enable automatic domain bridging so that any user in the BU_Acquired domain can read resources in the main domain without extra policy steps.

Show answer and explanation

Correct answers: A, C

Explanation

To grant users in another IAM domain access to resources in a compartment, you must create a group in the domain where the users reside, then define a policy in the domain that owns the resources. In this scenario, the 'Finance' compartment is in the main domain, so the policy must be created there, referencing the group from the BU_Acquired domain. For more information, refer to the official Oracle Cloud Infrastructure Identity and Access Management documentation on managing IAM domains, users, and compartments.

  • A. Correct.

    Correct. You need to create a group in the domain where the users reside (BU_Acquired). Adding the users to this group sets up the identity component you will reference in a policy.

  • B. Incorrect.

    Incorrect. The policy to access a compartment must be created in the domain that owns the compartment (the main domain in this case). Attaching a policy in BU_Acquired domain cannot grant access to compartments owned by another domain.

  • C. Correct.

    Correct. Because the Finance compartment resides in the main domain, the policy granting read access must also be created there. You reference the group in BU_Acquired domain within that policy statement.

  • D. Incorrect.

    Incorrect. Granting membership in the built-in Administrators group would give far more privileges than read-only. This group effectively allows administrative operations within the domain, not limited read access.

  • E. Incorrect.

    Incorrect. There is no feature in OCI called 'automatic domain bridging' that grants cross-domain access by default. Policies must be explicitly created in the domain that owns the resource.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam