1Z0-1104-25 Question 7
Single answerYour financial services company is migrating a critical HR application to an Oracle Cloud Infrastructure (OCI) Compute instance. You need to ensure the environment meets strict regulatory requirements for data security, patches, and access controls. According to the OCI Shared Security Responsibility model, which statement best reflects your responsibilities versus Oracle� responsibilities?
- A
A) Oracle handles all aspects of data security, including operating system patching and encryption within the guest operating system.
- B
B) Your team is responsible for configuring and maintaining the guest operating system, applying application-level patches, and managing data encryption, while Oracle secures the underlying physical and virtual infrastructure.
- C
C) Oracle covers application-level security controls and user access management, and your team only needs to manage network firewall and traffic filtering rules.
- D
D) You are only required to manage authentication for users logging into OCI. Oracle implements all other security controls, including encryption and compliance.
Show answer and explanation
Correct answer: B
Explanation
The OCI Shared Security Responsibility model clearly divides duties: Oracle secures the underlying infrastructure (hardware, network, hypervisor, and physical data centers), while the customer is accountable for the security of their own instances, operating systems, application software, and data. For more details, refer to Oracle� official documentation on Shared Security Responsibility, which outlines the boundaries between Oracle� responsibilities and those of the customer (e.g., OS-level patching, encryption management, and application configuration).
- A. Incorrect.
Option A: Incorrect. While Oracle manages security of the underlying physical infrastructure and cloud services, customers must still patch and secure the operating system and configure encryption within their own instances. It is a misconception to assume Oracle covers all aspects of data security.
- B. Correct.
Option B: Correct. Under the Shared Security Responsibility model, Oracle is responsible for the physical data centers, network, and hypervisor layers, while customers are responsible for what runs on top of those layers, including guest OS patching, application security, and data protection controls.
- C. Incorrect.
Option C: Incorrect. Customers manage not only network firewall rules but also operating system security and application patches. Oracle does not assume responsibility for application-level security in the customer� environment.
- D. Incorrect.
Option D: Incorrect. This suggests that the customer has almost no responsibilities beyond authentication, which is not accurate. Customers also handle OS-level patching, data encryption, and compliance tasks within their tenant� scope.