1Z0-1151-25 exam dumps

1Z0-1151-25 practice question 30 of 133

Oracle Cloud Infrastructure 2025 Multicloud Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1151-25 Question 30

Select 2

Your company is integrating Oracle Cloud Infrastructure (OCI) with an external identity provider (IdP) that supports SAML 2.0. They want employees to use their existing credentials from the IdP to access specific OCI resources without having separate OCI accounts. Which two actions must you perform to establish this federation between the OCI Identity Domain and the external IdP?

  1. A

    Import the external IdP� SAML metadata into the OCI Identity Domain and create a corresponding trust federation configuration.

  2. B

    Recreate all external IdP user accounts in your OCI Identity Domain user store to maintain consistency.

  3. C

    Configure the external IdP to send the necessary SAML assertions (e.g., user email or group membership) that map to OCI Identity Domain attributes.

  4. D

    Provision a dedicated OCI region specifically designed for external IdP federation to ensure secure isolation.

Show answer and explanation

Correct answers: A, C

Explanation

To enable federation with an external IdP in OCI Identity Domains, you must establish trust between the two systems. This typically involves importing the IdP� SAML metadata file into OCI and configuring the IdP to provide the required SAML assertions, such as user identifiers or group memberships. By properly mapping these attributes, OCI can authorize federated users without the overhead of manually creating and managing separate accounts. Refer to Oracle� documentation on 'Federating with SAML Identity Providers' for detailed configuration steps and best practices.

  • A. Correct.

    Correct: You must import the IdP� metadata (often an XML file) into the OCI console and create a trust. This allows OCI to recognize and trust the SAML assertions coming from the IdP.

  • B. Incorrect.

    Incorrect: You do not need to manually recreate each user in the OCI Identity Domain. Federation allows you to trust the IdP for authentication and map users or groups through assertions, eliminating the need to store each external user's credentials in OCI.

  • C. Correct.

    Correct: The IdP must be configured to provide valid SAML assertions (e.g., email, username, or group information). OCI uses these attributes to map the external user to local roles and permissions.

  • D. Incorrect.

    Incorrect: OCI does not require a dedicated region for external IdP federation. Federations can be configured in the existing region and do not demand an isolated region or domain.

Timed practice exam

Take a 1Z0-1151-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam