1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 58 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 58

Select 2

Your security team wants to enforce multi-factor authentication (MFA) on all administrator console logins in Oracle Cloud Infrastructure (OCI). In addition, they need an alert whenever a user fails or bypasses the MFA challenge. Which two actions should you take to satisfy these requirements?

  1. A

    Create a sign-on policy that explicitly requires MFA for administrators accessing the console.

  2. B

    Enable MFA at the root compartment only, assuming all subcompartments will inherit the same rule automatically.

  3. C

    Configure an Event Rule or Monitoring Alert to notify the security team each time an MFA challenge fails or is bypassed.

  4. D

    Use a password policy with strong complexity rules to negate the need for MFA alerts.

Show answer and explanation

Correct answers: A, C

Explanation

To fulfill the requirement of enforcing MFA for administrator console logins, you must configure a dedicated sign-on policy in OCI IAM. For real-time visibility and alerts about failed or bypassed MFA attempts, you can set up Event Rules or use the Monitoring service to detect and notify the security team. Refer to the Oracle Cloud Infrastructure documentation on IAM sign-on policies, MFA configuration, and event-based notifications for detailed steps and best practices.

  • A. Correct.

    Option 1 is correct: Sign-on policies in OCI IAM allow you to enforce MFA on specific user groups or for all console logins. By creating or modifying a sign-on policy that includes administrators, you ensure MFA is applied at every login attempt.

  • B. Incorrect.

    Option 2 is incorrect: Simply enabling MFA at the root compartment doesn't guarantee enforcement in all scenarios, especially if there are existing policies or groups that override or exclude MFA requirements. You must explicitly configure a sign-on policy targeting the administrators.

  • C. Correct.

    Option 3 is correct: OCI Event Rules or Monitoring Alerts can be used to detect and notify security teams of failed or bypassed MFA challenges. This helps you monitor suspicious login behavior and promptly respond to potential threats.

  • D. Incorrect.

    Option 4 is incorrect: Relying exclusively on strong password policies without alerts for failed or bypassed MFA challenges leaves a gap in visibility and security. MFA is designed to provide an additional layer of defense beyond passwords alone.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam