1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 52 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 52

Select 2

Your organization hosts a CI/CD pipeline on Oracle Cloud Infrastructure (OCI) and wants to ensure that only compute instances tagged with 'Environment=CI/CD' can be managed by this pipeline, and only if the request originates from your corporate IP address range. You plan to use Dynamic Groups, Network Sources, and tag-based policies to achieve this. Which TWO actions must you take to enforce this configuration?

  1. A

    Create a Dynamic Group that includes instances matching the tag 'Environment=CI/CD,' then reference that group in a policy to allow manage operations on these instances.

  2. B

    Define a Network Source with your corporate IP address range, and include a condition in the policy referencing this Network Source.

  3. C

    Attach your user group directly to the Dynamic Group to inherit its tag-based privileges and bypass network restrictions for all operations.

  4. D

    Configure an 'Allow policy' that omits specifying the Network Source, relying on compartment-level policy inheritance to restrict IP ranges automatically.

  5. E

    Use Tag Defaults to automatically assign the 'Environment=CI/CD' tag to all new resources, and then rely on existing policies for IP restrictions.

Show answer and explanation

Correct answers: A, B

Explanation

By creating a Dynamic Group for resources tagged with 'Environment=CI/CD' and a Network Source that includes your corporate IP range, you can write a tag-based and IP-restricted policy that allows only requests from the specified IP addresses to manage these tagged instances. Reference: Oracle Cloud Infrastructure Documentation on Identity and Access Management (IAM) describes how to define Dynamic Groups, use Network Sources, and incorporate tag-based conditions into policies for granular access control.

  • A. Correct.

    Option 1 is correct. You must create a Dynamic Group with a matching rule that identifies resources (e.g., compute instances) tagged as 'Environment=CI/CD.' The policy then references this Dynamic Group to allow specific permissions (such as 'manage instance-family') on those tagged resources.

  • B. Correct.

    Option 2 is correct. Defining a Network Source with your corporate IP address range allows you to add a condition in the policy, for example 'where request.networkSourceName = ,' ensuring that only requests coming from these IPs can perform the specified actions on the tagged instances.

  • C. Incorrect.

    Option 3 is incorrect. You do not attach user groups to a dynamic group for resource access. Dynamic Groups are for OCI resources, whereas user groups are for IAM users. This approach would not effectively restrict access to tagged instances and does not integrate Network Source conditions.

  • D. Incorrect.

    Option 4 is incorrect. Simply omitting the Network Source condition in your policy does not restrict IP ranges. Without explicitly referencing the Network Source in the policy, requests from any IP could potentially manage your instances, contrary to your requirements.

  • E. Incorrect.

    Option 5 is incorrect. While Tag Defaults can help ensure resources in a compartment are automatically tagged, they do not inherently enforce network-based restrictions. You still need to explicitly include the Network Source in a policy to limit which IP addresses can perform actions on those tagged resources.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam