1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 79 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 79

Single answer

Your organization uses an OCI Load Balancer fronting a web application, with an SSL certificate managed through OCI Certificates. The existing SSL certificate is due to expire in 30 days, and your security policy mandates immediate rotation to avoid any interruption in service. You have already generated a new certificate in OCI Certificates. Which approach ensures minimal downtime when replacing the existing certificate on the load balancer?

  1. A

    Stop the load balancer, detach the old certificate, attach the new certificate, then restart the load balancer.

  2. B

    Create the new certificate in OCI Certificates, update the load balancer listener to reference it, test the connection, and then remove the old certificate.

  3. C

    Delete the old certificate from the load balancer, wait for traffic to fail over to the new certificate, and then create the new certificate in OCI Certificates.

  4. D

    Use a custom DNS entry to route traffic temporarily to a backup load balancer, update the certificate on the primary load balancer, and revert DNS changes.

Show answer and explanation

Correct answer: B

Explanation

To replace an expiring SSL certificate on an OCI Load Balancer with minimal downtime, you should create or import the new certificate into OCI Certificates, update your load balancer� listener to reference the new certificate, and then remove the old certificate after testing. This approach avoids any traffic interruption and aligns with OCI best practices. For more details, refer to the official Oracle documentation on managing OCI Certificates and load balancers: https://docs.oracle.com/en-us/iaas/Content/Certificates/Tasks/managingyourcertificates.htm and https://docs.oracle.com/en-us/iaas/Content/loadbalancer/overview.htm.

  • A. Incorrect.

    Incorrect. Stopping the load balancer introduces downtime, which violates the objective of minimal or zero downtime.

  • B. Correct.

    Correct. By adding the new certificate to the OCI Load Balancer and updating the listener's configuration, you can gracefully test traffic with the new certificate. Once verified, you can remove the old certificate with no downtime.

  • C. Incorrect.

    Incorrect. Deleting the old certificate first leads to service interruption because the load balancer no longer has a valid certificate until you attach the new one.

  • D. Incorrect.

    Incorrect. While using DNS failover might reduce downtime, you don't need an entirely separate load balancer or DNS update if your goal is simply to replace an expiring certificate. The built-in OCI certificate rotation process is more straightforward and avoids additional DNS complexity.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam