1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 95 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 95

Select 3

You are managing a set of Linux-based instances that handle sensitive financial data in Oracle Cloud Infrastructure (OCI). Due to strict compliance requirements, you need to ensure the operating systems are consistently patched, scanned for vulnerabilities, and monitored for suspicious activity. Which three actions should you implement to achieve robust OS and workload protection?

  1. A

    Deploy the Oracle OS Management agents on your compute instances and schedule patch updates through OS Management Hub.

  2. B

    Configure Oracle Cloud Infrastructure Vulnerability Scanning Service to run regular OS scans for known security vulnerabilities.

  3. C

    Periodically generate compliance reports using Oracle Cloud Guard to identify out-of-date OS kernels and manage patching directly.

  4. D

    Implement a centralized audit trail and monitor OS events using Oracle Logging and Oracle Logging Analytics.

  5. E

    Grant OS Management Admin permissions in a broad IAM policy to simplify patch deployments across all environments.

Show answer and explanation

Correct answers: A, B, D

Explanation

By deploying OS Management agents (Option 1) and configuring Vulnerability Scanning Service (Option 2), you ensure your instances are regularly patched and scanned for common security flaws. Centralized logging (Option 4) helps detect anomalies quickly and maintain regulatory compliance. Relying too heavily on Cloud Guard reports alone (Option 3) will not handle automated patching, and granting broad admin permissions (Option 5) violates least-privilege principles. Refer to the Oracle Cloud Infrastructure documentation on OS Management Hub, Vulnerability Scanning, and Logging Analytics for best practices and implementation details.

  • A. Correct.

    Option 1 is correct. Enabling Oracle OS Management agents and using OS Management Hub allows you to centrally schedule and automate patching, improving consistency and reducing manual errors.

  • B. Correct.

    Option 2 is correct. OCI Vulnerability Scanning Service can regularly check for known OS vulnerabilities, helping ensure your instances remain updated against critical security risks.

  • C. Incorrect.

    Option 3 is incorrect. While Cloud Guard helps identify security posture issues, it does not directly manage OS patching. Generating compliance reports is useful, but you still need OS Management or manual patching to address outdated kernels.

  • D. Correct.

    Option 4 is correct. Using Oracle Logging and Logging Analytics for centralized auditing and real-time monitoring is crucial to detect unusual activities and maintain compliance, especially in environments handling sensitive data.

  • E. Incorrect.

    Option 5 is incorrect. Granting broad OS Management Admin permissions to many users introduces excessive privilege risks. Following the principle of least privilege is a better security practice.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam