1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 91 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 91

Single answer

Your organization runs a mission-critical application on Linux-based virtual machine (VM) instances in Oracle Cloud Infrastructure (OCI). Recently, your security team identified a new OS vulnerability that requires immediate patching of multiple VM instances to maintain compliance and prevent potential breaches. You want to manage OS patching centrally, schedule patch updates during predefined maintenance windows, and verify that these instances meet your security baselines. Which approach best addresses these requirements with minimal downtime?

  1. A

    Use the OS Management Service to create a Managed Instance Group, schedule automatic patching, and apply security baselines across your instances.

  2. B

    Configure Oracle Cloud Guard to automatically patch the OS, pulling updates directly from the Oracle Linux repositories without any custom scheduling.

  3. C

    Manually SSH into each instance, run the patching process separately, and rely on monthly vulnerability scans to confirm compliance.

  4. D

    Leverage an external third-party patch management system that requires shutting down all instances during patch installation.

Show answer and explanation

Correct answer: A

Explanation

Oracle� OS Management Service simplifies enterprise OS and workload protection by providing centralized patching, package management, and vulnerability detection. It integrates with OCI for scheduling updates, automating compliance checks, and reducing manual overhead. Refer to Oracle Cloud Infrastructure documentation for best practices on creating and configuring Managed Instance Groups to ensure timely and consistent OS updates across your fleet.

  • A. Correct.

    Option 1 is correct. The OS Management Service in OCI allows you to group and centrally manage Linux-based instances, schedule patch updates, and enforce compliance baselines with minimal downtime. This is the recommended method for streamlined OS and workload protection.

  • B. Incorrect.

    Option 2 is incorrect. While Oracle Cloud Guard provides continuous monitoring and security recommendations, it does not handle OS patching directly. It identifies risks but does not natively perform patch installations or schedule maintenance windows for OS updates.

  • C. Incorrect.

    Option 3 is incorrect. Manually patching each instance is prone to human error, time-intensive, and does not provide a centralized scheduling mechanism or compliance reporting. Real-world environments typically require automated, large-scale solutions.

  • D. Incorrect.

    Option 4 is incorrect. Although third-party tools can manage patching, requiring all instances to go offline for patches is disruptive. Oracle� OS Management Service is designed to minimize downtime by scheduling patches during predefined windows.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam