1Z0-997-25 exam dumps

1Z0-997-25 practice question 54 of 175

Oracle Cloud Infrastructure 2025 Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-997-25 Question 54

Select 2

You are the lead architect for a financial services firm that manages sensitive customer data in Oracle Cloud Infrastructure (OCI). Your company wants to enforce the following security requirements to protect its production environment: � Only traffic from specific corporate IP addresses can reach the application. • Direct SSH access to production compute instances must be restricted. • All sensitive data must be encrypted at rest with customer-managed keys using an external Key Management Service (KMS) integrated with OCI.

Which two solutions should you implement to address these requirements with minimal administrative overhead?

  1. A
    1. Create a Network Security Group (NSG) that allows inbound traffic only from the approved corporate CIDR blocks, and configure OCI Vault to integrate with your external KMS for customer-managed encryption keys.
  2. B
    1. Configure Security Lists with broad inbound rules for all IP addresses to simplify administration, and manually rotate third-party encryption keys on a quarterly basis via a local process.
  3. C
    1. Use a public load balancer with a Web Application Firewall (WAF) configured to whitelist the corporate IP range and provide SSH access for administrators, while storing the encryption keys in OCI Vault using Oracle-managed keys.
  4. D
    1. Implement a WAF policy to allow only the specified corporate CIDR blocks to reach the load balancer, block direct SSH access to compute instances by exposing only bastion hosts, and integrate the external KMS with OCI Vault for end-to-end encryption of data at rest.
Show answer and explanation

Correct answers: A, D

Explanation

When implementing security solutions in OCI, Network Security Groups (NSGs) or a Web Application Firewall (WAF) can be used to control inbound traffic based on source IP addresses. Restricting SSH access typically involves using bastion hosts, instead of exposing compute keys directly to the internet. For data encryption, Oracle Cloud Infrastructure Vault can integrate with external Key Management Service (KMS) solutions, allowing customers full control over their encryption keys. Refer to Oracle's documentation on 'OCI Vault and Key Management' and 'Web Application Firewall' for details on configuring secure access and external key integrations.

  • A. Correct.

    Option 1 is CORRECT. Network Security Groups (NSGs) can be used to restrict inbound traffic to specific source IP addresses, offering more granular control than Security Lists. Additionally, integrating an external KMS with OCI Vault for customer-managed encryption keys is a best practice for enhanced control over key rotation and ownership.

  • B. Incorrect.

    Option 2 is INCORRECT. Configuring Security Lists with broad inbound rules violates the requirement that only corporate IP addresses should be able to reach the environment. Manually rotating keys outside a managed service also adds unnecessary operational complexity rather than minimizing overhead.

  • C. Incorrect.

    Option 3 is INCORRECT. While using WAF for whitelisting traffic is appropriate, storing the data encryption keys as Oracle-managed keys (instead of using an external KMS) fails to satisfy the specific requirement for externally managed, customer-owned keys. Additionally, providing SSH access through the WAF does not address the need to restrict direct SSH access at the compute instance level.

  • D. Correct.

    Option 4 is CORRECT. Using the WAF to filter inbound traffic exclusively to the specified corporate IP addresses meets the requirement of restricting application access. Blocking direct SSH and relying on bastion hosts aligns with security best practices for production environments. Finally, integrating an external KMS with OCI Vault ensures data is encrypted at rest with customer-managed keys, meeting the requirement for external key control.

Timed practice exam

Take a 1Z0-997-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam