1Z0-997-25 exam dumps

1Z0-997-25 practice question 51 of 175

Oracle Cloud Infrastructure 2025 Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-997-25 Question 51

Select 2

Your company must comply with strict data security requirements on Oracle Cloud Infrastructure (OCI) 2025. The security team mandates that all newly created block volumes must use customer-managed encryption keys, and any attempt to create or attach an unencrypted volume should be automatically blocked. In addition, they require that no public IP addresses are assigned to Compute instances hosting sensitive data. Which two services or configurations would best address these requirements?

  1. A

    Use Security Zones to enforce the creation of only encrypted block volumes with customer-managed keys and to disallow public IP addresses on instances within those zones.

  2. B

    Enable Cloud Guard with a custom detector recipe that identifies non-compliant (unencrypted) volumes and public IP assignments, then turn on auto-remediation to correct these issues.

  3. C

    Create an IAM policy that denies resource creation whenever a Compute instance or block volume is not tagged as 'encrypted', ensuring all volumes are automatically encrypted and instances are never assigned public IP addresses.

  4. D

    Migrate all data to the File Storage service (FSS) and enable NFS-level encryption, expecting FSS encryption to apply automatically to block volumes as well.

Show answer and explanation

Correct answers: A, B

Explanation

To meet stringent security requirements on OCI, you often combine Security Zones (which prevent the creation of non-compliant resources from the start) with a service like Cloud Guard (which can detect and remediate any existing misconfigurations). Security Zones can enforce the mandatory use of your customer-managed keys for block volumes and deny public IP addresses for Compute instances in designated compartments. Cloud Guard adds continuous monitoring and remediation, helping you maintain compliance and reducing the chances of misconfigurations going undetected. Refer to the Oracle Cloud Infrastructure Security Zones documentation and Cloud Guard documentation for detailed setup instructions, best practices, and policy examples.

  • A. Correct.

    Correct. Security Zones can be configured so that any new resources (such as block volumes) must use customer-managed keys, and they can also enforce no public IP assignments on Compute instances. This automatically prevents creation of non-compliant resources in the first place.

  • B. Correct.

    Correct. By creating a custom detector recipe in Cloud Guard and enabling auto-remediation, you can detect and correct misconfigurations like unencrypted volumes or public IP assignments in sensitive environments. This helps maintain continuous compliance.

  • C. Incorrect.

    Incorrect. While IAM policies can deny resource creation under certain conditions, they cannot directly enforce encryption by referencing the encryption method (customer-managed keys vs. Oracle-managed). Also, preventing public IP addresses for all instances typically requires combined use of Security Zones or VCN-based rules to block public endpoints.

  • D. Incorrect.

    Incorrect. File Storage service encryption is separate from block volume encryption. FSS does not automatically enforce block volume encryption, so it would not address the requirement to block unencrypted volumes or prevent public IPs for Compute.

Timed practice exam

Take a 1Z0-997-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam