1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 45 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 45

Single answer

Your organization has created a new group called 'DevGroup' in Oracle Cloud Infrastructure (OCI) that needs the ability to fully manage all compute instances in a compartment named 'DevelopmentCompartment' while also having only read access to objects in a compartment named 'LogsCompartment.' Which single set of IAM policy statements best meets these requirements?

  1. A

    A) Allow group DevGroup to manage all-resources in compartment DevelopmentCompartment; Allow group DevGroup to read buckets in compartment LogsCompartment

  2. B

    B) Allow group DevGroup to manage instance-family in compartment DevelopmentCompartment; Allow group DevGroup to read objects in compartment LogsCompartment

  3. C

    C) Allow group DevGroup to manage instance-family in compartment DevelopmentCompartment; Allow group DevGroup to manage objects in compartment LogsCompartment

  4. D

    D) Allow group DevGroup to manage all-resources in compartment DevelopmentCompartment; Allow group DevGroup to manage all-resources in compartment LogsCompartment

Show answer and explanation

Correct answer: B

Explanation

In Oracle Cloud Infrastructure, creating an IAM policy statement with the verb 'manage instance-family' restricts management privileges to compute instances without granting unnecessary permissions on other resources. For read-only access to bucket contents, use 'read objects' in the relevant compartment. The official OCI documentation recommends adopting the principle of least privilege by specifying narrower resource families and actions. Therefore, Option B provides the correct level of access for both compartments.

  • A. Incorrect.

    Option A: Incorrect. The first statement ('manage all-resources') gives unnecessary rights, but more importantly, 'read buckets' only grants permission to view bucket information, not the actual objects in the bucket. For read-access to objects, you must use the 'read objects' permission specifically. This mismatch means it doesn't fully satisfy the requirement to view objects inside the bucket.

  • B. Correct.

    Option B: Correct. Granting 'manage instance-family' in 'DevelopmentCompartment' allows DevGroup to fully manage compute instances (create, update, delete, etc.). The second statement 'Allow group DevGroup to read objects in compartment LogsCompartment' restricts their actions to read-only access to the object data, which matches the scenario perfectly.

  • C. Incorrect.

    Option C: Incorrect. While 'manage instance-family' in DevelopmentCompartment is correct for compute management, the second statement grants 'manage objects' in LogsCompartment, which goes beyond read-only access. This would allow DevGroup to create or delete objects in LogsCompartment, violating the read-only requirement.

  • D. Incorrect.

    Option D: Incorrect. Both policy statements use 'manage all-resources', which is broader than needed for either compartment. This grants DevGroup full control over resources in both compartments and does not limit them to read-only access for the LogsCompartment.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam