1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 86 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 86

Single answer

Your security team has noticed an increase in malicious traffic targeting a public web application hosted behind an OCI Load Balancer. They ask you to configure an OCI Web Application Firewall (WAF) to block suspicious IP addresses, allow specific tester IP ranges, and enable a built-in rule set to prevent common attacks. Which of the following approaches correctly creates and applies the WAF policy?

  1. A

    A. Create a WAF compartment, add the WAF to the application subnet, enable logs, and route all traffic through the WAF using custom DNS

  2. B

    B. Configure a built-in WAF on the Load Balancer by adding a listening port that inspects requests, then apply rule sets and add IP whitelists to the Load Balancer� security list

  3. C

    C. Create a WAF policy in OCI, link it to the existing Load Balancer public endpoint, define block rules for malicious IP addresses, configure an allow list for tester IPs, and enable built-in protection rule sets for SQL injection and XSS

  4. D

    D. Migrate the application to a private subnet, disable the public Load Balancer, add the WAF to an internal NAT gateway route table, and rely on the default rule sets

Show answer and explanation

Correct answer: C

Explanation

In OCI, you create and configure a WAF policy in the Web Application Firewall service and then attach it to the traffic source, which is typically the public IP or domain provided by the OCI Load Balancer. Once attached, you define block or allow rules based on IP addresses, configure built-in rule sets (e.g., for SQL injection or XSS), and ensure traffic routes through the WAF. Refer to the official Oracle Cloud Infrastructure documentation on WAF deployment and rule configuration for further guidance.

  • A. Incorrect.

    Option A: Incorrect. Simply creating a WAF "compartment" is not how OCI WAF is configured. You don't place the WAF directly in the application subnet, and while configuring custom DNS is plausible, this doesn�t reflect the correct procedure in OCI for creating and attaching a WAF policy.

  • B. Incorrect.

    Option B: Incorrect. OCI Load Balancer does not have a built-in WAF that you enable by adding a listening port. WAF policies are created and administered separately. Applying IP whitelists at the Load Balancer's security list doesn't provide the comprehensive web application protection needed.

  • C. Correct.

    Option C: Correct. The typical process in OCI is to create a dedicated WAF policy, associate it with the desired public endpoint (in this case, the Load Balancer), and then configure the rule sets and access control lists (ACLs). Allowing legitimate tester IP ranges and blocking malicious IPs satisfies the security requirements while the built-in rule sets add protection from common web attacks.

  • D. Incorrect.

    Option D: Incorrect. Moving the application to a private subnet and disabling the public Load Balancer would break external access. Additionally, an internal NAT gateway is not where you would attach a WAF policy. This approach does not align with standard methods of deploying an OCI WAF.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam