1Z0-1151-25 exam dumps

1Z0-1151-25 practice question 34 of 133

Oracle Cloud Infrastructure 2025 Multicloud Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1151-25 Question 34

Select 2

Your organization wants to enable single sign-on (SSO) for the engineering team using a third-party SAML 2.0 identity provider. You have created a new OCI Identity Domain for this team and need to configure federation. Which two steps are essential to ensure users can seamlessly sign in using their existing corporate credentials?

  1. A

    Generate an SP (Service Provider) metadata file from your external identity provider and upload it to the OCI Identity Domain as part of the federation.

  2. B

    Create a SAML application in the external identity provider, configuring the Assertion Consumer Service (ACS) URL, Entity ID, and audience claims to match your OCI Identity Domain settings.

  3. C

    Manually provision each user from your identity provider into the OCI Identity Domain by adding them individually under 'Users' in the Tenant Console.

  4. D

    Import the identity provider� SAML signing certificate into the OCI Identity Domain trust store to validate inbound SAML assertions.

Show answer and explanation

Correct answers: B, D

Explanation

Federating an OCI Identity Domain with a SAML 2.0 identity provider involves configuring trust from both sides. In OCI, you typically import the IdP� metadata (or at least the IdP signing certificate) and provide the SP metadata or key settings to the IdP. You must specify the appropriate ACS URL, Entity ID, and configure claims or attributes so SAML tokens are accepted by OCI. Refer to Oracle� documentation on �Federating an Identity Domain with a SAML Identity Provider� for step-by-step guidance on exchanging metadata, configuring your IdP application, and importing certificates to establish a secure and trusted SSO flow.

  • A. Incorrect.

    Option 1: INCORRECT. Typically, you download the metadata from OCI (the SP) and import it into the IdP, or download the IdP's metadata to import into OCI. Generating an SP metadata file from your IdP is not the usual approach. Instead, you generally export your IdP� SAML metadata and import or configure it in OCI, or vice versa.

  • B. Correct.

    Option 2: CORRECT. When federating a third-party SAML 2.0 IdP with an OCI Identity Domain, you must create or configure a SAML application on the IdP side. You then specify details such as the ACS URL, Entity ID (sometimes called Audience), and the required claims so OCI can properly process the SAML assertions.

  • C. Incorrect.

    Option 3: INCORRECT. You do not need to manually recreate all users in the OCI Identity Domain. The purpose of federation is to allow user authentication via the IdP without duplicating or manually managing multiple user accounts in OCI for each user.

  • D. Correct.

    Option 4: CORRECT. The identity provider� signing certificate is essential for OCI to verify the authenticity of incoming SAML assertions. Failing to include the correct IdP certificate in the OCI Identity Domain trust store results in invalid or untrusted SAML tokens.

Timed practice exam

Take a 1Z0-1151-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam