1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 56 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 56

Select 2

Your organization requires mandatory multi-factor authentication (MFA) for all OCI console sign-ins. Additionally, the security team wants to receive an alert if an identity administrator disables MFA for any user, so they can immediately investigate. Which two actions should you take to meet these requirements?

  1. A
    1. Create a new IAM sign-on policy requiring MFA for all console logins and attach it at the tenancy level.
  2. B
    1. Configure an ExemptMFA group and add all administrators to it so they can bypass MFA.
  3. C
    1. Define an alert rule for the UpdateUserMFA event in the Monitoring service and send notifications to the security team� channel.
  4. D
    1. Subscribe to the Identity domain audit events for MFA-related actions and route them to a Notification topic accessible by the security team.
Show answer and explanation

Correct answers: A, C

Explanation

To enforce MFA for all console sign-ins in OCI, you typically create a sign-on policy at the root (tenancy) or identity domain level that applies to all users. For alerting, you can define rules that listen for specific MFA-related events, such as UpdateUserMFA, and route those events to an appropriate Notification topic for the security team. Refer to OCI documentation on IAM sign-on policies and event rules to ensure the policy is configured correctly and that alerts are set up to capture disabling or modification of MFA.

  • A. Correct.
    1. Correct. Creating a sign-on policy at the tenancy level ensures that every user attempting to sign in via the console must complete MFA. Attaching the policy at the root level is the recommended approach for organization-wide coverage.
  • B. Incorrect.
    1. Incorrect. Exempting administrators from MFA defeats the purpose of mandatory MFA. It also introduces a security gap because high-privileged accounts should always be protected by MFA.
  • C. Correct.
    1. Correct. Defining an alert rule (for the UpdateUserMFA event) ensures you receive immediate notifications whenever an administrator disables or updates the MFA settings on a user account, allowing the security team to investigate promptly.
  • D. Incorrect.
    1. Incorrect. While subscribing to domain audit events may capture broad identity changes, a more targeted approach for MFA changes is to use the specific UpdateUserMFA event. Simply forwarding all audit events could create noise without necessarily alerting on the critical MFA disable action.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam