1Z0-997-25 exam dumps

1Z0-997-25 practice question 102 of 175

Oracle Cloud Infrastructure 2025 Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-997-25 Question 102

Single answer

You have been tasked with designing a hybrid identity solution for a global financial services firm that operates an on-premises Active Directory (AD) environment, along with Oracle Cloud Infrastructure (OCI) and Microsoft Azure. The firm requires a consistent, secure single sign-on experience across all environments to meet strict regulatory standards and minimize administrative overhead. Which design approach should you recommend?

  1. A

    Manually replicate and synchronize all on-premises AD user accounts directly within OCI IAM and Azure AD, updating each environment separately.

  2. B

    Configure single sign-on by federating the on-premises AD with Oracle Identity Cloud Service (IDCS) and Azure Active Directory, leveraging automated user provisioning capabilities.

  3. C

    Deploy separate domain controllers within each cloud and manually configure trust relationships among the clouds and on-premises AD.

  4. D

    Implement password-synchronization scripts that copy hashed credentials from on-premises AD to each cloud environment on a daily basis.

Show answer and explanation

Correct answer: B

Explanation

When designing multicloud and hybrid identity solutions, federating your existing on-premises Active Directory with a cloud Identity Provider�such as Oracle Identity Cloud Service�while also integrating other cloud directories like Azure AD is the recommended practice. This allows for a single sign-on experience, reduces administrative overhead, and meets compliance requirements. Refer to official OCI and Azure documentation on identity federation and unified authentication for best practices.

  • A. Incorrect.

    Option 1 is incorrect because manually replicating accounts into each cloud environment is cumbersome and prone to synchronization errors. It increases administrative overhead and does not provide a seamless single sign-on experience.

  • B. Correct.

    Option 2 is correct. Federating on-premises AD with IDCS and Azure AD provides a single identity authority, automated provisioning, and consistent access controls across on-premises and both cloud environments. This approach significantly simplifies administration and enhances security.

  • C. Incorrect.

    Option 3 is incorrect because deploying separate domain controllers adds complexity, requires more infrastructure management, and does not inherently provide a unified single sign-on solution across OCI, Azure, and on-premises AD.

  • D. Incorrect.

    Option 4 is incorrect because relying solely on password synchronization scripts is less secure, requires constant maintenance, and fails to provide the robust federation or automated provisioning needed for enterprise-scale identity management.

Timed practice exam

Take a 1Z0-997-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam