1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 67 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 67

Select 2

You are responsible for a three-tier web application deployed to Oracle Cloud Infrastructure (OCI). The front-end instance is in a public subnet and must allow inbound HTTPS (port 443) from the internet only. The application server is in a private subnet and should only accept traffic from the front-end on port 8080. The database is in a separate private subnet and should only accept traffic from the application server on port 1521. Additionally, you need to enable advanced threat detection and intrusion prevention for your VCN. Which two actions should you take to achieve these requirements using NSGs, Security Lists, and the OCI Network Firewall?

  1. A

    A) Configure Security Lists for each subnet to allow all inbound ports, and rely solely on the OCI Network Firewall for traffic inspection.

  2. B

    B) Create separate NSGs for the front-end, application server, and database, applying ingress rules that only allow each tier's required traffic. Maintain Security Lists with minimal (default) open ports.

  3. C

    C) Deploy the OCI Network Firewall and associate it with each subnet, enforcing advanced threat detection on ingress and egress traffic. Update your NSG rules to allow only necessary ports between tiers.

  4. D

    D) Replace all NSGs and Security Lists with a single, wide-open Security List on the VCN, then use the OCI Network Firewall to block untrusted ports.

  5. E

    E) Use a single NSG for all components, but actively deny all outbound traffic from the application server to the database. Place the OCI Network Firewall only in the public subnet for advanced threat detection.

Show answer and explanation

Correct answers: B, C

Explanation

In OCI, you should adopt a layered defense that utilizes NSGs for granular, instance-level rules, Security Lists for default subnet-level restrictions, and the OCI Network Firewall for deep packet inspection and advanced threat mitigation. Oracle recommends creating separate NSGs for each tier, blocking unnecessary ports by default, and using the OCI Network Firewall to enhance threat detection and filtering per subnet. Refer to Oracle documentation on Network Security Groups, Security Lists, and OCI Network Firewall for best practices on configuring layered security.

  • A. Incorrect.

    A) Incorrect. Relying solely on the OCI Network Firewall with Security Lists that allow all ports is not aligned with the principle of least privilege. Security Lists should not be left wide open; you still need to limit traffic to essential ports.

  • B. Correct.

    B) Correct. Creating separate NSGs for each tier and applying strict ingress rules to match the required traffic (443 for front-end, 8080 for application tier, 1521 for database) is a recommended practice for layered security. Keeping Security Lists minimal protects subnets by default.

  • C. Correct.

    C) Correct. Deploying the OCI Network Firewall at each subnet boundary (or configured appropriately for multi-subnet inspection) provides advanced threat detection and intrusion prevention. Coupled with NSG rules that allow only essential traffic, this approach offers an effective multi-layered defense.

  • D. Incorrect.

    D) Incorrect. A single, wide-open Security List on the entire VCN defeats the purpose of segmentation and least privilege. The OCI Network Firewall is most effective when combined with restricted Security Lists or NSGs, not a broad allowance of all traffic.

  • E. Incorrect.

    E) Incorrect. A single NSG for all resources does not provide sufficient segmentation. Also, placing the OCI Network Firewall only in the public subnet fails to inspect or protect internal subnet traffic between the application and database tiers.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam