1Z0-997-25 exam dumps

1Z0-997-25 practice question 53 of 175

Oracle Cloud Infrastructure 2025 Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-997-25 Question 53

Select 2

You are an OCI architect at a financial services company. They want their sensitive data in Object Storage to be encrypted with a key they control and also want to automatically block suspicious IP addresses that appear in the tenancy. Which TWO steps would address both of these security requirements?

  1. A

    A) Configure RSA key-pair encryption on the Object Storage bucket through a custom script

  2. B

    B) Use the OCI Vault service with a customer-managed master encryption key for the Object Storage bucket

  3. C

    C) Enable Cloud Guard Responder rules to automatically block malicious IP addresses upon detection

  4. D

    D) Create an IAM policy that denies access to the Object Storage bucket from unrecognized IP ranges

  5. E

    E) Manage encryption for Object Storage by enabling the default Oracle-managed keys

Show answer and explanation

Correct answers: B, C

Explanation

To meet both requirements of controlling encryption keys and blocking suspicious IP addresses automatically, you should store and manage your own keys in OCI Vault (B) and leverage Cloud Guard (C) with appropriate Responder rules. This ensures that your data in Object Storage is protected by keys fully under your control, while Cloud Guard continuously monitors and remediates anomalous traffic. Refer to the 'Vault' and 'Cloud Guard' sections of the OCI documentation for detailed implementation guides and best practices.

  • A. Incorrect.

    A) Incorrect. RSA key-pair encryption with a custom script is neither a standardized nor a recommended approach. Although you could theoretically encrypt data with your own script, it fails to leverage OCI's native encryption at rest. It also doesn�t provide the necessary workflow or manageability for large-scale operations.

  • B. Correct.

    B) Correct. Using OCI Vault with a customer-managed key allows you to have full control over the encryption keys for your Object Storage data, meeting the requirement to manage your own keys rather than relying on Oracle-managed keys.

  • C. Correct.

    C) Correct. Cloud Guard can detect suspicious or malicious events and, with properly configured Responder rules, take automated actions such as blocking the associated IP addresses. This addresses the requirement to automatically stop suspicious IP activity in the tenancy.

  • D. Incorrect.

    D) Incorrect. While creating an IAM policy to restrict unrecognized IP addresses may help reduce unwanted access, it does not automatically block malicious IP addresses based on real-time threat detection. It is a static rule, not an automated response mechanism.

  • E. Incorrect.

    E) Incorrect. Default Oracle-managed keys do encrypt your data, but they do not meet the requirement that you specifically manage (own) the encryption keys. You must use customer-managed keys for that level of control.

Timed practice exam

Take a 1Z0-997-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam