1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 93 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 93

Select 3

You manage a multi-tier application running on Oracle Linux compute instances in Oracle Cloud Infrastructure (OCI). Your organization requires that you keep operating systems fully patched, detect and flag suspicious activity, and ensure remote management is limited only to authorized administrators. Which three actions should you implement using OCI features to meet these requirements?

  1. A

    Enable OS Management on each compute instance and configure a patch schedule to automatically apply updates.

  2. B

    Attach a public Load Balancer to each compute instance to facilitate direct SSH access over the internet.

  3. C

    Enable Cloud Guard in your tenancy and configure its recipes to detect suspicious activity on your compute instances.

  4. D

    Use OCI Bastion to establish ephemeral SSH sessions for authorized administrators connecting to private compute instances.

  5. E

    Disable host-based firewalls on each instance to ensure OS Management patching tasks run without interference.

Show answer and explanation

Correct answers: A, C, D

Explanation

To fulfill OS and workload protection requirements in Oracle Cloud Infrastructure, you should use OS Management for automated patching (per Oracle documentation on OS Management), enable Cloud Guard to detect suspicious activity (per the Oracle Cloud Guard Best Practices), and restrict external access to authorized administrators via OCI Bastion (per Bastion service documentation). Disabling essential security controls like host-based firewalls or using public endpoints for SSH access violate OCI security best practices.

  • A. Correct.

    Correct. Enabling OS Management and setting a scheduled patch plan automates OS patching, ensuring all systems consistently receive the latest security updates. This addresses the requirement for frequent OS patching.

  • B. Incorrect.

    Incorrect. Exposing compute instances via a public Load Balancer for direct SSH access introduces significant security risks. OCI best practices recommend minimizing public endpoints and using more secure access services like Bastion.

  • C. Correct.

    Correct. Cloud Guard provides security posture management and can be configured to detect and raise alerts on suspicious events, such as unexpected process executions or configuration changes, across your tenancy. This helps meet the requirement for detecting suspicious activity.

  • D. Correct.

    Correct. OCI Bastion offers restricted, ephemeral SSH sessions to compute instances without needing a public IP address. This aligns with the requirement to allow remote management only for authorized administrators.

  • E. Incorrect.

    Incorrect. Disabling host-based firewalls is a common misconception. It weakens security and is not necessary for OS Management. The OS Management service can work with properly configured firewalls, so there is no need to disable them.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam