1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 55 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 55

Select 2

You are a Security Administrator at a company that requires multi-factor authentication (MFA) for all members of the 'ProdAdmins' group to ensure secure access to production environments. Meanwhile, standard users in the 'DevGroup' group are only subject to basic sign-on policies. Additionally, you need to configure alerts for multiple failed login attempts from any user account so that your Security Operations team can investigate promptly. Which two actions should you take to achieve these requirements?

  1. A

    Create a sign-on policy requiring TOTP-based MFA for the 'ProdAdmins' group in Oracle Cloud Infrastructure (OCI).

  2. B

    Disable password complexity for the 'ProdAdmins' group to minimize login friction when MFA is applied.

  3. C

    Configure the OCI Audit service to generate events on repeated failed login attempts and integrate with the Notifications service to send alerts.

  4. D

    Create an IAM policy to deny logins from the 'DevGroup' group unless MFA is used.

Show answer and explanation

Correct answers: A, C

Explanation

In Oracle Cloud Infrastructure, sign-on policies allow targeted enforcement of MFA for specific user groups. By creating a sign-on policy for the 'ProdAdmins' group, you meet the requirement for enhanced security in production environments while keeping the 'DevGroup' on standard sign-on. Separately, using the OCI Audit service and Notifications together enables real-time alerts for repeated failed login attempts, a critical component for security monitoring. Refer to OCI documentation on Identity and Access Management (IAM), sign-on policies, and the Audit service for detailed steps.

  • A. Correct.

    Option 1 is CORRECT. Creating a targeted sign-on policy for the 'ProdAdmins' group ensures that all administrators in this group must use TOTP-based MFA, fulfilling the requirement for heightened security in production environments.

  • B. Incorrect.

    Option 2 is INCORRECT. Disabling password complexity is not advisable because it weakens overall security. MFA is an additional factor, not a replacement for a secure password policy.

  • C. Correct.

    Option 3 is CORRECT. The OCI Audit service captures login events, including failed authentication attempts. Configuring repeated failure thresholds and integrating with the Notifications service allows you to send alerts to Security Operations, meeting the requirement for monitoring suspicious login activities.

  • D. Incorrect.

    Option 4 is INCORRECT. The requirement states that only 'ProdAdmins' need MFA. Denying logins for the 'DevGroup' unless MFA is used contradicts the scenario in which 'DevGroup' users only need basic sign-on policies.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam