1Z0-1151-25 exam dumps

1Z0-1151-25 practice question 45 of 133

Oracle Cloud Infrastructure 2025 Multicloud Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1151-25 Question 45

Select 2

You administer a MySQL Database Service with HeatWave that stores sensitive financial data for real-time analytics. Additionally, you maintain an on-premises Oracle Base Database that occasionally needs to query segments of the same data. You want to ensure that data in the MySQL HeatWave environment remains securely encrypted both at rest and in transit when accessed by the on-premises database, while keeping overhead and maintenance tasks minimal. Which two configurations or best practices should you implement to meet these requirements?

  1. A

    Enable default encryption at rest for your MySQL HeatWave instance and manage encryption keys using OCI Vault if necessary.

  2. B

    Configure TLS/SSL connections from the on-premises Oracle Base Database to MySQL HeatWave to encrypt data in transit.

  3. C

    Disable encryption at rest in the MySQL HeatWave instance to reduce CPU overhead for analytics queries.

  4. D

    Open a direct unencrypted connection from your on-premises database to MySQL HeatWave via public IP for faster performance.

  5. E

    Perform full data replication from MySQL HeatWave to your on-premises Oracle Base Database and rely solely on the Oracle Database to secure the data.

Show answer and explanation

Correct answers: A, B

Explanation

In this scenario, you must protect sensitive data both while it is stored in MySQL HeatWave (encryption at rest) and while it is transferred to the on-premises Oracle Base Database (encryption in transit). By enabling encryption at rest and using TLS/SSL for connections, you fulfill both requirements without creating unnecessary replication overhead or compromising data security. For more details, refer to the Oracle Cloud Infrastructure documentation on administering MySQL Database Service with HeatWave and configuring SSL connectivity.

  • A. Correct.

    Option 1 is correct. MySQL Database Service with HeatWave is encrypted at rest by default. You can manage your own encryption keys using OCI Vault for tighter control. This ensures that stored data remains secure even if the underlying storage is compromised.

  • B. Correct.

    Option 2 is correct. When sensitive data is accessed externally (e.g., from an on-premises Oracle Base Database), configuring a TLS/SSL connection is vital to protect data in transit. This prevents unauthorized access or interception of sensitive information.

  • C. Incorrect.

    Option 3 is incorrect. Disabling encryption at rest to reduce overhead undermines the security requirement for sensitive financial data. MySQL HeatWave is designed to provide strong security without introducing significant performance degradation.

  • D. Incorrect.

    Option 4 is incorrect. Using a direct unencrypted connection over public IP increases risk of data interception. This goes against best practices for protecting sensitive data in transit.

  • E. Incorrect.

    Option 5 is incorrect. Replicating all data into the on-premises Oracle Database does not ensure that the data in MySQL HeatWave is also protected. It merely shifts management burdens and fails to maintain security in the original source.

Timed practice exam

Take a 1Z0-1151-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam