1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 49 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 49

Select 3

Your organization wants to ensure that only compute instances tagged with Department=Finance can read objects in the 'Finance' compartment, and only when those requests originate from your corporate IP range 192.168.0.0/16. You plan to create a Dynamic Group that matches the Department=Finance tag, define a Network Source for the IP range, and then create an IAM policy that references both. Which three configuration steps accomplish this scenario? (Choose three.)

  1. A
    1. Create a Dynamic Group with the rule ANY {resource.matchTag('Department','Finance')}.
  2. B
    1. Create a Network Source listing 192.168.0.0/16 as the corporate IP range.
  3. C
    1. In the IAM policy, include a condition where request.networkSource.name equals the corporate Network Source you created.
  4. D
    1. Attach the policy at the root compartment and allow dynamic-group access to all resources with no mention of the Network Source.
  5. E
    1. Create a Dynamic Group with the rule ANY {resource.compartment.id = }.
Show answer and explanation

Correct answers: A, B, C

Explanation

In Oracle Cloud Infrastructure, Dynamic Groups can be configured to match resources based on tags, enabling fine-grained access control. Defining a Network Source allows you to restrict requests to specific IP addresses or ranges, and the IAM policy can reference both the Dynamic Group (by name) and the Network Source (by name) to enforce the desired security requirements. For more information, consult the official Oracle documentation on 'Managing Dynamic Groups,' 'Network Sources,' and 'Tag-Based Access Control.'

  • A. Correct.

    Option 1 is CORRECT. Using resource.matchTag('Department','Finance') ensures that the Dynamic Group only includes compute instances tagged with Department=Finance.

  • B. Correct.

    Option 2 is CORRECT. Defining a Network Source for 192.168.0.0/16 restricts access to requests originating from your corporate IP range.

  • C. Correct.

    Option 3 is CORRECT. Including request.networkSource in the policy statement enforces the rule that only requests from your named corporate Network Source are allowed.

  • D. Incorrect.

    Option 4 is INCORRECT. If you attach a policy at the root compartment without referencing the Network Source or limiting access by tag, it grants broader access than intended and fails to restrict usage to the corporate IP range.

  • E. Incorrect.

    Option 5 is INCORRECT. Matching resources based on compartment ID alone does not use the Department=Finance tag. The requirement is to restrict membership specifically to instances tagged with Department=Finance.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam