1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 65 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 65

Select 2

You are designing a multi-tier e-commerce application on Oracle Cloud Infrastructure (OCI). The web-tier is served by an OCI Load Balancer in a public subnet, while the back-end services and database reside in private subnets. The security team requests that all incoming HTTP/HTTPS traffic be strictly filtered, and only the load balancer should be able to connect to the backend services on required ports. Which two configurations should you implement to best protect the environment while maintaining necessary connectivity?

  1. A

    Implement an OCI Web Application Firewall (WAF) in front of the load balancer with an appropriate protection rule set.

  2. B

    Allow all inbound traffic to the private subnets to simplify future integrations with third-party services.

  3. C

    Use Network Security Groups (NSGs) to restrict traffic such that only the load balancer subnet can access the web-tier on ports 80 and 443.

  4. D

    Enable public ingress rules on the private subnet security list for SSH and RDP to aid in server administration.

Show answer and explanation

Correct answers: A, C

Explanation

When creating a secure multi-tier application on OCI, you should employ multiple layers of defense. A Web Application Firewall (WAF) helps protect against common web threats at Layer 7, while Network Security Groups (NSGs) fine-tune access control for each tier of your application (front-end, mid-tier, and back-end). Following Oracle� best practices, you allow only the necessary traffic (for example, load balancer traffic to the web servers on port 80/443) and avoid exposing administrative ports on the public internet. For more details, refer to the Oracle Cloud Infrastructure documentation on 'Securing Your Load Balancer' and 'Using Network Security Groups'.

  • A. Correct.

    Correct: By placing the OCI WAF in front of the load balancer, you can filter requests for malicious traffic, apply rate limiting, and enforce various security rules at Layer 7. This is a recommended best practice to protect your application from common web attacks such as SQL injection and cross-site scripting.

  • B. Incorrect.

    Incorrect: Allowing all inbound traffic to private subnets violates the principle of least privilege and increases the attack surface. Instead, access should be restricted to the minimal required ports and sources.

  • C. Correct.

    Correct: NSGs let you define firewall rules that apply to specific resources. Restricting traffic to only allow inbound connections from the load balancer on the necessary ports (80/443) significantly reduces exposure to unauthorized access.

  • D. Incorrect.

    Incorrect: Enabling public ingress rules on a private subnet for SSH/RDP is not recommended. These administrative ports should be accessed through a bastion host, VPN, or other secure tunnels rather than directly from the public internet.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam