1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 71 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 71

Single answer

Your organization is deploying a microservices-based application within a single VCN. The front-end services require inbound HTTP/HTTPS access from the public internet, while the internal microservices (back-end) must only accept traffic from the front-end within the same VCN. You need to restrict any direct inbound access to the back-end microservices from public IP addresses. Additionally, you want to reduce the maintenance overhead when adding or removing instances in the back-end. Which approach best meets these requirements?

  1. A

    Create a separate Security List for the back-end subnet, referencing the CIDR block of the front-end subnet for ingress rules.

  2. B

    Use Network Security Groups (NSGs) for both the front-end and back-end instances; configure the back-end NSG to allow ingress only from the front-end NSG, and rely on a network firewall for advanced threat detection.

  3. C

    Rely only on the default Security List for both front-end and back-end subnets, enabling HTTP/HTTPS from 0.0.0.0/0 but using ephemeral IP addresses for the back-end instances.

  4. D

    Use an Internet Gateway and attach it directly to each microservice instance� subnet, restricting all inbound traffic via a network firewall only.

Show answer and explanation

Correct answer: B

Explanation

Network Security Groups (NSGs) provide an efficient way to group instances that share common security requirements, allowing dynamic changes without manually updating CIDR-based rules. By configuring the back-end NSG to accept inbound traffic only from the front-end NSG, you ensure that back-end instances are shielded from direct external access. A network firewall can further inspect and filter traffic, aligning with a defense-in-depth strategy. For details, refer to Oracle Cloud Infrastructure Documentation on NSGs and Security Lists: https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/managingsecuritylistsandgroups.htm

  • A. Incorrect.

    Option 1: While a Security List can restrict traffic at the subnet level, referencing the entire front-end subnet CIDR is less granular than referencing a specific NSG. As new or retired instances appear, you may need to update CIDR rules. This approach works but can lead to higher management overhead, especially in dynamic environments.

  • B. Correct.

    Option 2 (Correct): Using NSGs for both tiers is more flexible and scalable. The back-end NSG allows traffic from the front-end NSG rather than a CIDR block, so new front-end instances automatically gain access without needing updates to CIDR-based rules. The network firewall can further enhance security by inspecting and filtering traffic for advanced threats. This approach meets requirements while minimizing maintenance.

  • C. Incorrect.

    Option 3: Relying on a single Security List and ephemeral IP addresses does not adequately separate front-end and back-end traffic. Moreover, exposing the entire subnet to 0.0.0.0/0 for HTTP/HTTPS runs counter to the requirement of restricting inbound access to the back-end.

  • D. Incorrect.

    Option 4: Directly attaching an Internet Gateway to each subnet and depending solely on the firewall for inbound restrictions is too broad and does not implement the principle of least privilege. It also leaves less control for granular internal communication rules between front-end and back-end.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam