1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 92 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 92

Select 2

You manage an e-commerce platform running Linux-based workloads on multiple Oracle Cloud Infrastructure (OCI) compute instances. After a recent security audit revealed several unpatched OS-level vulnerabilities, your team wants to proactively protect these workloads with built-in OCI capabilities. Which two actions should you take to improve OS and workload security in this environment?

  1. A

    Configure and enable the OS Management Service on compute instances to automatically apply critical patches.

  2. B

    Deploy Oracle Vulnerability Scanning Service to regularly scan and report on OS-level vulnerabilities.

  3. C

    Rely only on manual patching once per year to simplify change management processes.

  4. D

    Remove SSH access entirely and trust the default OS configuration to patch itself automatically.

Show answer and explanation

Correct answers: A, B

Explanation

By using the OS Management Service to automate patching, you ensure that your Linux-based instances stay up to date with critical fixes. Additionally, deploying the Oracle Vulnerability Scanning Service gives you visibility into potential OS-level risks, enabling prompt remediation. For more details, consult the Oracle Cloud Infrastructure documentation on OS Management and the Vulnerability Scanning Service to learn best practices for secure and continuous workload protection.

  • A. Correct.

    Correct. Enabling the OS Management Service on OCI compute instances allows you to schedule and automate OS patching, reducing the risk of vulnerabilities and downtime.

  • B. Correct.

    Correct. Oracle Vulnerability Scanning Service detects OS security issues, providing reports that help you prioritize and address vulnerabilities before they are exploited.

  • C. Incorrect.

    Incorrect. Limiting patch updates to once per year leaves your instances vulnerable to newly discovered threats and does not leverage OCI� built-in automation capabilities.

  • D. Incorrect.

    Incorrect. Completely blocking SSH access is impractical for most workloads and does not inherently guarantee OS patches are applied. You still need proper access methods and update processes.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam