1Z0-997-25 exam dumps

1Z0-997-25 practice question 70 of 175

Oracle Cloud Infrastructure 2025 Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-997-25 Question 70

Single answer

Your organization is deploying a microservices-based application in an Oracle Container Engine for Kubernetes (OKE) cluster. The application needs frequent updates to its database credentials, and the security team requires an automated rotation process with no manual intervention. You decide to use OCI Vault to store and rotate the secrets. Which approach is recommended to implement a fully automated end-to-end secrets management solution for this scenario?

  1. A

    Store the database credentials as a secret in OCI Vault, configure a rotation policy, and set up an OCI Events rule that triggers an OCI Function to update the database credentials and increment the secret version in Vault.

  2. B

    Create a Kubernetes Secret in the OKE cluster and manually rotate the credentials using a CRON job on a compute instance whenever credentials need to be updated.

  3. C

    Embed the database credentials in your application� container images, and rebuild the containers to deploy updated credentials.

  4. D

    Store the database credentials on the local file system of each OKE node, and allow developers to rotate them via secure file transfer.

Show answer and explanation

Correct answer: A

Explanation

OCI Vault provides centralized management and rotation of sensitive credentials. By setting up a rotation policy for secrets in the Vault, and creating an OCI Events rule to trigger an OCI Function that updates the database and increments the secret version, you achieve end-to-end automation. This pattern is described in Oracle documentation on integrating OCI Vault, Events, and Functions for automated secrets rotation, ensuring better security, auditability, and minimal manual effort.

  • A. Correct.

    Correct. Storing the database credentials in OCI Vault and using a rotation policy, combined with OCI Events and an OCI Function, enforces an automated workflow. Whenever the secret needs rotation, the Event rule triggers the Function to update both the database and the secret in Vault. This setup meets the requirement for full automation and minimal manual intervention.

  • B. Incorrect.

    Incorrect. Using a standalone Kubernetes Secret without OCI Vault and manually running CRON jobs introduces additional overhead and potential security risks. It does not provide a seamless, centralized rotation mechanism managed by OCI Vault.

  • C. Incorrect.

    Incorrect. Embedding credentials in container images is a security risk and requires rebuilding the containers whenever credentials need rotation, which is cumbersome and error-prone. It also does not leverage OCI Vault� secret rotation capabilities.

  • D. Incorrect.

    Incorrect. Storing credentials on node file systems is insecure and not centralized. This approach lacks any built-in rotation or versioning mechanism, making it much more difficult to automate and audit.

Timed practice exam

Take a 1Z0-997-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam