1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 81 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 81

Select 2

Your organization has obtained a third-party CA-signed certificate and wants to store it in the OCI Certificates service. You also need to assign this certificate to an OCI Load Balancer for secure client connections. Which TWO of the following steps must you ensure are completed correctly for a successful import and configuration of your externally signed certificate?

  1. A

    Include the entire certificate chain in the upload, ensuring the leaf certificate comes first and any intermediate certificates follow in PEM format.

  2. B

    Convert your private key to PKCS#12 format before uploading, as OCI Certificates only supports this key format.

  3. C

    Provide the private key's passphrase if it is encrypted, or remove the passphrase before uploading if you cannot specify it.

  4. D

    Use a self-signed leaf certificate, because OCI Certificates does not support uploading certificates signed by a third-party CA.

Show answer and explanation

Correct answers: A, C

Explanation

When working with externally signed certificates in OCI, it is crucial to follow specific formatting requirements. The certificate chain must be in PEM format and in the correct order (leaf certificate first, then intermediate certificates, followed by the root CA). The private key also needs to be in PEM format, and if it is passphrase-protected, the passphrase must be provided. For more details, refer to the official OCI Certificates documentation: https://docs.oracle.com/en-us/iaas/Content/certificates/home.htm

  • A. Correct.

    Correct. When importing an externally signed certificate into OCI Certificates, you must include the complete certificate chain in PEM format. The order should be: leaf certificate first, followed by intermediate certificates, and ending with the root CA if applicable.

  • B. Incorrect.

    Incorrect. The Oracle Cloud Infrastructure Certificates service requires the private key to be in PEM format, not PKCS#12. PKCS#12 is a container format that includes certificates and keys, but OCI expects separate PEM-encoded files for the key and certificate.

  • C. Correct.

    Correct. If your private key is secured with a passphrase, you must supply the passphrase when creating the certificate in OCI Certificates. Alternatively, you can remove the passphrase using a tool like OpenSSL if necessary.

  • D. Incorrect.

    Incorrect. OCI Certificates does support uploading certificates issued by a third-party CA. A self-signed certificate is only one of several valid options but not a requirement for OCI Certificates.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam