1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 90 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 90

Select 2

Your e-commerce application runs behind an OCI public load balancer, and you recently created a new WAF policy to block common vulnerabilities (such as SQL injection) identified by the OWASP Top 10. Which two steps must you take next in order for the new WAF policy to actively protect incoming traffic to your application?

  1. A

    Attach the WAF policy to the public load balancer and enable protection enforcement

  2. B

    Configure the WAF policy to use a separate custom SSL certificate and key from the load balancer

  3. C

    Directly enable logging to Object Storage in the WAF policy settings to start protection

  4. D

    Enable blocking rules within the WAF policy and associate it with the load balancer in the same AD (Availability Domain)

Show answer and explanation

Correct answers: A, D

Explanation

After creating a WAF policy that addresses common web attacks, you must associate it with the appropriate load balancer and enable the blocking mode to ensure that malicious requests are actually blocked (instead of only being detected). Logging and SSL configuration can be handled as needed but are not, by themselves, sufficient to activate WAF protection. For more detailed steps, refer to official Oracle Cloud Infrastructure Web Application Firewall documentation on attaching a WAF policy to a load balancer and enabling enforcement.

  • A. Correct.

    Correct. To actively protect your application, you need to associate the policy with the actual load balancer. Enabling protection enforcement (OCRS detection and blocking) ensures traffic is inspected and malicious requests are blocked.

  • B. Incorrect.

    Incorrect. While WAF can handle SSL, you do not necessarily need a separate custom certificate. You can use the same certificate used by the public load balancer unless there is a specific compliance or business reason otherwise.

  • C. Incorrect.

    Incorrect. Simply enabling logging to Object Storage does not make the policy enforce protection. Logging is for auditing and monitoring. You must still attach the policy to the load balancer and enable enforcement.

  • D. Correct.

    Correct. The WAF policy must be set to block malicious traffic, and it must be linked to the relevant load balancer in the same region and AD so that it can actively inspect and filter incoming requests.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam