1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 80 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 80

Select 2

You manage a production application behind an OCI Load Balancer that uses a certificate from the Oracle Cloud Infrastructure Certificates service. The certificate is about to expire, and you have already created a new certificate (including its private key) in the Certificates service. Which two steps must you perform to replace the expiring certificate with minimal downtime?

  1. A

    Create a new certificate version in the Certificates service, then update the load balancer� listener to reference the new version.

  2. B

    Revoke the expiring certificate in the Certificates service before provisioning the new certificate.

  3. C

    Configure a new listener on the load balancer and point it to the newly created certificate, then disable the old listener immediately.

  4. D

    Delete the old certificate from the Certificates service before you update the load balancer, so that it does not conflict with the new certificate.

  5. E

    Update the existing load balancer's SSL configuration to reference the new certificate and key pair, ensuring the listener points to the correct certificate name.

Show answer and explanation

Correct answers: A, E

Explanation

When rotating an expiring certificate on an OCI Load Balancer, professionals typically create a new certificate (or version) within the Certificates service and then update the existing load balancer listener to use the new resource. This avoids service downtime or interruptions. Revocation and immediate deletion of the old certificate are not best practices unless there is a security compromise, and provisioning a separate listener for rotation should be carefully planned to avoid connection drops. For more information, refer to Oracle's 'Certificate Services' and 'Load Balancing' documentation on performing certificate rotation with minimal downtime.

  • A. Correct.

    Correct. In OCI, you typically create a new certificate or certificate version in the Certificates service and then update the load balancer� listener configuration to use the freshly created certificate. This approach allows you to rotate the certificate with minimal service interruption.

  • B. Incorrect.

    Incorrect. You do not need to revoke the existing certificate prior to provisioning the new one. Revocation is used if a key is compromised or invalidated, but for expiration rotation, you simply create a new certificate or version and update references in dependent resources.

  • C. Incorrect.

    Incorrect. While creating a new listener could work mechanically, disabling the old listener �immediately� can cause disruptions if clients are still connected. OCI best practices recommend updating the existing listener with the new certificate to minimize downtime.

  • D. Incorrect.

    Incorrect. It� not recommended to delete the old certificate right away, because you might need it for rollback until you confirm the new certificate is working properly. Removing the old certificate prematurely can introduce additional risks and timeline pressures.

  • E. Correct.

    Correct. You must ensure that the load balancer� SSL configuration (the protocol-specific listener or certificate configuration) references the new certificate and private key�this is how the load balancer knows to terminate TLS with the fresh certificate after the rotation.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam