1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 82 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 82

Select 2

Your organization has renewed its SSL/TLS certificate from a trusted Certificate Authority (CA) for a public-facing application behind an OCI Load Balancer. You want to replace the expiring certificate with the newly issued one without causing service disruption. Which two actions must you perform to ensure the new certificate is applied successfully?

  1. A

    Import the new certificate and private key into the OCI Certificates service, ensuring you store it in the same compartment as your load balancer resources.

  2. B

    Immediately remove the old certificate configuration from the load balancer before adding the new one to ensure no overlap.

  3. C

    Update the existing SSL listener to reference the new certificate once it is imported, then validate the application for proper encryption.

  4. D

    Store your new certificate in an OCI Object Storage bucket, then configure the load balancer to read your certificate from that bucket.

Show answer and explanation

Correct answers: A, C

Explanation

To replace an expiring certificate without downtime, the best practice is to import the new certificate into OCI Certificates service and reference it within the load balancer� listener configuration. Once the new certificate is active and verified, you can safely remove the old certificate. Refer to Oracle documentation on 'Managing SSL Certificates' with OCI Load Balancers for detailed guidance.

  • A. Correct.

    Option 1 is correct. You must import the new certificate and its private key into the OCI Certificates service to manage it properly and securely. Storing it in the same compartment as your load balancer resources simplifies administration and security.

  • B. Incorrect.

    Option 2 is incorrect. Removing the old certificate before the new one is in place can cause downtime and service interruptions. The recommended approach is to import and configure the new certificate, then remove the old one once traffic is confirmed to be using the new certificate.

  • C. Correct.

    Option 3 is correct. After importing the new certificate, you need to update the load balancer� SSL listener to reference it. This step ensures the load balancer terminates SSL with the correct certificate. You should then validate that the application is still reachable and secure.

  • D. Incorrect.

    Option 4 is incorrect. Storing your certificate in an OCI Object Storage bucket is not the recommended method for implementing certificates with an OCI Load Balancer. OCI Certificates service (or OCI Vault if you prefer a dedicated key vault) is the proper location for certificate management.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam