1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 89 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 89

Single answer

You manage an online store hosted in Oracle Cloud Infrastructure (OCI) behind a public load balancer. You notice frequent malicious attempts such as SQL injection and cross-site scripting targeting your web application. How should you create and configure a Web Application Firewall (WAF) policy in OCI to protect your application while ensuring minimal disruption?

  1. A

    Create a new WAF policy, add the domain of your web application under Protected Sites, configure the built-in protection rules for SQL injection and cross-site scripting, and attach the policy to the public load balancer.

  2. B

    Enable the default firewall within the compute instance operating system, configure IP whitelisting rules, and rely on the load balancer to block all other traffic.

  3. C

    Set up an Intrusion Detection System (IDS) in a separate compartment, forward all traffic to the IDS using a NAT gateway, and configure the IDS to block malicious requests.

  4. D

    Attach a Network Security Group (NSG) to your compute instance, enable the 'Block All Suspicious Requests' setting, and route traffic through the NSG for inspection.

Show answer and explanation

Correct answer: A

Explanation

In OCI, the primary method to protect an application from layer 7 (application-layer) threats such as SQL injection and cross-site scripting is to create a WAF policy and attach it to your web application. Using OCI's Web Application Firewall, you can configure built-in protection rules, set custom rules if needed, and integrate seamlessly with your load balancer to filter and block malicious requests. For more guidance, refer to the Oracle Cloud Infrastructure documentation on Creating and Configuring WAF Policies.

  • A. Correct.

    Option 1 is correct. The recommended approach is to create a WAF policy in the OCI console, add your domain to Protected Sites, enable relevant protection rules (such as SQL injection and cross-site scripting), and attach the WAF policy to the public load balancer or configure your DNS if needed. This ensures that traffic is inspected for malicious patterns and blocked if it is identified as an attack.

  • B. Incorrect.

    Option 2 is incorrect. Merely enabling an operating system firewall with IP whitelisting does not provide application-layer protection against threats like SQL injection or cross-site scripting. You need OCI� WAF to handle these sophisticated attacks at layer 7.

  • C. Incorrect.

    Option 3 is incorrect. While an IDS can help detect intrusions, it is not the recommended method for real-time blocking of web application threats in OCI. Additionally, a NAT gateway is used primarily for egress traffic and not typically for rerouting all incoming web traffic to an external system.

  • D. Incorrect.

    Option 4 is incorrect. Network Security Groups (NSGs) operate at a lower layer and are typically used to control network traffic based on protocols and ports. They do not provide the same level of application-layer inspection and rule sets offered by a dedicated WAF.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam