1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 96 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 96

Select 2

You are a security engineer with 200 Linux compute instances spread across multiple compartments in Oracle Cloud Infrastructure (OCI). To maintain compliance with corporate security policies, you need to automate the application of critical OS patches, reduce exposure to known vulnerabilities, and track patching status across all instances. Which two actions must you take to effectively implement OS and workload protection using Oracle OS Management Service?

  1. A

    Install and configure the OS Management Agent on each instance, then register them with Oracle OS Management Service.

  2. B

    Rely on manual patching by periodically connecting via SSH and running your distribution� package manager.

  3. C

    Create and enable a patch compliance policy in Oracle OS Management to automatically schedule and apply security updates.

  4. D

    Remove the OS Management Agent after the first patch cycle to optimize resource usage on the instances.

Show answer and explanation

Correct answers: A, C

Explanation

To implement OS and workload protection in OCI using Oracle OS Management Service, you must first enable and configure the OS Management Agent on each instance and then register those instances with the service. This setup allows you to create patch compliance policies, schedule automatic updates, and continuously track patch status for compliance. Manual or ad-hoc methods are error-prone and make it difficult to maintain consistent security across large fleets. For more details, refer to the latest Oracle OS Management documentation.

  • A. Correct.

    Correct. Each compute instance must have the OS Management Agent installed and configured before it can be registered with the Oracle OS Management Service. This agent facilitates communication with the service, enabling patch automation and compliance checks.

  • B. Incorrect.

    Incorrect. While manual patching can work for small environments or ad-hoc updates, it does not provide automated enforcement or comprehensive visibility. Oracle OS Management Service is designed to streamline patching at scale, so relying on manual patching undermines security and compliance goals.

  • C. Correct.

    Correct. Creating a patch compliance policy in Oracle OS Management and scheduling security updates ensures that your instances remain patched against known vulnerabilities. This approach automates patching, keeps workloads secure, and provides patch status visibility.

  • D. Incorrect.

    Incorrect. Removing the OS Management Agent negates the benefits of continuous monitoring, automated patching, and compliance reporting. The agent should remain installed and active to maintain OS and workload protection.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam