1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 51 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 51

Select 2

You want to grant access to the Object Storage API only to your compute instances that carry the tag 'Department=Finance' and are making requests from your corporate IP range. Which two steps must you implement to enforce this restriction effectively?

  1. A

    Create a Dynamic Group with a rule that includes instances tagged with Department=Finance.

  2. B

    Configure a Network Source that defines your corporate IP range and reference it in the policy statement.

  3. C

    Allow a standard user group (e.g., FinanceUsers) to manage objects in Object Storage for the entire tenancy.

  4. D

    Add a host-based firewall rule on each instance to only accept requests from the corporate IP range.

  5. E

    Tag the entire compartment with Department=Finance so that all instances in that compartment are automatically allowed.

Show answer and explanation

Correct answers: A, B

Explanation

To restrict Object Storage API calls to only the correctly tagged compute instances from a specified IP range, you must define a Dynamic Group with a membership rule based on the Department=Finance tag. Then, create a Network Source that captures your corporate IP range. Finally, write an IAM policy that allows only that Dynamic Group to access Object Storage when requests arrive from the configured Network Source. Refer to the 'Managing Dynamic Groups' and 'Managing Network Sources' sections of the Oracle Cloud Infrastructure documentation for detailed instructions on these configurations.

  • A. Correct.

    Option 1 is correct. Dynamic Groups require a matching rule that targets the appropriate tags, such as Department=Finance, ensuring only those instances with this exact tag are included.

  • B. Correct.

    Option 2 is correct. A Network Source restricts resource access based on source IP ranges; referencing it in your policy ensures that only requests from the specified corporate IP range are allowed.

  • C. Incorrect.

    Option 3 is incorrect. Simply allowing a generic user group to manage Object Storage in the tenancy doesn�t restrict access to tagged instances or the corporate IP range. You need to reference the Dynamic Group tied to the tag and the Network Source.

  • D. Incorrect.

    Option 4 is incorrect. While host-based firewalls can control traffic at the instance level, this approach doesn�t integrate with OCI� Dynamic Group and Network Source mechanisms. The question specifically focuses on OCI IAM policy enforcement, not per-instance firewalls.

  • E. Incorrect.

    Option 5 is incorrect. Tagging the entire compartment doesn�t enforce the restriction on only the specifically tagged instances. You must match the Department=Finance tag at the instance level in the Dynamic Group membership rule.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam