1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 50 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 50

Single answer

You have an OCI Vault and want to allow compute instances with the tag Department=DevOps to read secrets, but only from your on-premises IP range. You created a dynamic group named 'DevOpsInstances' that matches instances with the key Department and value DevOps, and set up a network source named 'OnPremNetwork' for your organization� IP range. Which approach should you use to restrict secret access to these instances originating only from on-premises?

  1. A

    A. Create a policy granting the dynamic group 'DevOpsInstances' read access to secrets in the vault, and include a condition referencing the 'OnPremNetwork' network source by name.

  2. B

    B. Attach a cost-tracking tag to the vault named 'OnPremNetwork' and create a dynamic group policy that filters on the vault� new cost-tracking tag.

  3. C

    C. Write a policy to allow all compute instances to read secrets in the vault, trusting that the operating system firewall will restrict off-premises access.

  4. D

    D. Create a user group named 'DevOpsInstances', add the 'OnPremNetwork' network source to it, and write a policy allowing the group to read secrets in the vault.

Show answer and explanation

Correct answer: A

Explanation

In Oracle Cloud Infrastructure, dynamic groups are used to group resources like compute instances based on defined rules (such as a Department=DevOps tag). Network sources specify trusted IP addresses, e.g., on-premises ranges, that can be used in policy conditions. The policy must reference both the dynamic group and the network source condition to restrict access to secrets only to correctly tagged instances originating from on-prem IP addresses. Refer to the Oracle Cloud Infrastructure Security documentation (Dynamic Groups, Network Sources, and Tag-based Access Control chapters) for detailed examples of policy syntax and best practices.

  • A. Correct.

    A. CORRECT. You must configure a policy statement referencing both the dynamic group and the network source condition, for example: 'Allow dynamic-group DevOpsInstances to read secret-bundles in tenancy where request.networkSource.name = OnPremNetwork'. This ensures only tagged instances within the on-prem IP range can read the secrets.

  • B. Incorrect.

    B. INCORRECT. Cost-tracking tags don't control access. You need to specify conditions in a policy referencing the network source and the dynamic group, not a cost-tracking tag.

  • C. Incorrect.

    C. INCORRECT. Allowing all compute instances to read secrets doesn't enforce your DevOps instance tag requirement. Relying solely on the operating system firewall is not sufficient for OCI policy-based restrictions.

  • D. Incorrect.

    D. INCORRECT. A user group would not filter compute instances or enforce the on-premises IP address network source. Dynamic groups are the correct mechanism to group compute instances by tags, and network source conditions are specified in policies.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam