1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 62 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 62

Single answer

You are managing an e-commerce application deployed on Oracle Cloud Infrastructure (OCI). The front end is exposed via a public load balancer in a public subnet, while your application servers reside in a private subnet. Although you have implemented an OCI Web Application Firewall (WAF) to block common application-level attacks (like SQL injection and cross-site scripting), your IDS has reported potential port scans targeting the private subnet. Which single approach best mitigates external port-scanning attempts against your private subnet while maintaining valid user access to the application?

  1. A

    Configure a route table entry to blackhole any IP address flagged by your IDS.

  2. B

    Enable advanced WAF rules to block requests by scanning source IPs for open ports.

  3. C

    Use a Network Security Group (NSG) that restricts inbound traffic on the application servers to only the load balancer's subnet.

  4. D

    Allow outbound traffic from your private subnet to the internet solely through an internet gateway.

Show answer and explanation

Correct answer: C

Explanation

Port scanning is a network-level threat often blocked by carefully controlling inbound and outbound traffic in OCI using Security Lists or Network Security Groups (NSGs). In this scenario, the most effective method to stop direct scans is to allow traffic into your private subnet only from the load balancer's subnet, mitigated through appropriate NSG rules. This approach follows Oracle best practices for network segmentation and helps ensure that malicious scanners cannot directly reach application servers. Refer to the Oracle Cloud Infrastructure documentation on Network Security Groups for detailed guidance on limiting traffic to specific sources while preserving legitimate access.

  • A. Incorrect.

    Incorrect: Blackholing IP addresses directly in the route table is not a scalable or recommended solution for mitigating port scans. You would need to constantly update the route table with every suspicious IP, and it doesn't effectively isolate traffic at the network level.

  • B. Incorrect.

    Incorrect: A WAF typically operates at the HTTP/HTTPS layers to filter application-level threats. Blocking port scans requires controlling traffic at the network layer, not just at the application layer. Advanced WAF rules alone won't prevent uninvited TCP/UDP scanning attempts on your private subnet.

  • C. Correct.

    Correct: By configuring a Network Security Group (NSG) to allow inbound traffic only from the load balancer subnet, you ensure that external traffic to the private subnet must originate from the load balancer. This prevents direct port-scanning from the internet on the private subnet while still allowing legitimate user traffic to pass through the load balancer.

  • D. Incorrect.

    Incorrect: Restricting outbound traffic from the private subnet does not address inbound port scans. An internet gateway primarily handles outbound traffic to the internet, but does not mitigate unauthorized inbound traffic scanning for open ports.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam