Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Oracle 1z0-1104-25 Practice Exam with Questions & Answers

Questions 1

Challenge 2 -Task 1

In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.

As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.

Review the architecture diagram, which outlines the resoures you'll need to address the requirement:

1z0-1104-25 Question 1

Preconfigured

To complete this requirement, you are provided with the following:

Access to an OCI tenancy, an assigned compartment, and OCI credentials

Required IAM policies

Task 2: Create a Security Zone

Create a security Zone named IAD_SAP-PBT-CSZ-01 in your assigned compartement and associate it with the Custom Security Zone Recipe (IAD-SAP-PBT-CSP-01) created in the previous task.

Enter the OCID of the created Security zone in the box below.

1z0-1104-25 Question 1

Options:
Oracle 1z0-1104-25 Premium Access
Questions 2

Challenge 2 -Task 1

In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.

As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.

Review the architecture diagram, which outlines the resoures you'll need to address the requirement:

1z0-1104-25 Question 2

Preconfigured

To complete this requirement, you are provided with the following:

Access to an OCI tenancy, an assigned compartment, and OCI credentials

Required IAM policies

Task3: Create and configure a Virtual Cloud Network and Private Subnet

Createand configure virtual cloud Network (VCN) named IAD SP-PBT-VCN-01, with an internet Gateway and configure appropriate route rules to allow external connectivity.

Enter the OCID of the created VCN in the text box below.

Options:
Questions 3

Task 7: Verify the OCI Certificate with Load Balancer

Verify HTTPS connection to the load balancer by running the following command in Cloud Shell

curl -k https://

Enter the following URL in the web browser:

https://

If prompted with a certificate error, accept the risk and continue.

Verify web page content by ensuring the text, "You are visiting Web Server 1" from the index.html file is displayed in the browser

Options:
Questions 4

Task 2: Create a Compute Instance and Install the Web Server

Create a compute instance, where:

Name: PBT-CERT-VM-01

Image: Oracle Linux 8

Shape: VM.Standard.A1.Flex

Subnet: Compute-Subnet-PBT-CERT

Install and configure Apache web server:

a.

Install Apache

sudo yum -y install httpd

b.

Enable and start Apache

sudo systemctl enable httpd

sudo systemctl restart httpd

2. Install and configure Apache web server:

a. Install Apache

sudo yum -y install httpd

b. Enable and start Apache

sudo systemctl enable httpd

sudo systemctl restart httpd

c. Configure firewall to allow HTTP traffic (port 80)

sudo firewall-cmd --permanent --add-port=80/tcp

sudo firewall-cmd --reload

d. Create an index.html file

sudo bash -c 'echo You are visiting Web Server 1 >> /var/www/html/index.html'

Enter the OCID of the created compute instance PBT-CERT-VM-01 in the text box below.

Options:
Questions 5

Challenge 2

In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.

As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.

Review the architecture diagram, which outlines the resoures you'll need to address the requirement:

1z0-1104-25 Question 5

Preconfigured

To complete this requirement, you are provided with the following:

Access to an OCI tenancy, an assigned compartment, and OCI credentials

Required IAM policies

Task 5: Provision a Compute Instance

Provision a compute instance in the IAD-SP-PBT-PUBSNET-01 public subnet, where:

Name IAD-SP-PBT-1-VM-01

image: Oracle Linux 8

Shape VM: Standard, A1, Flex

Enter the OCID of the created compute instance in the text box below.

Options:
Questions 6

"Your company is in the process of migrating its sensitive data to Oracle Cloud Infrastructure (OCI) and is prioritizing the strongest possible security measures. Encryption is a key part of this strategy, but you are particularly concerned about the physical security of the hardware where your encryption keys will be stored.

Which characteristic of OCI Key Management Service (KMS) helps ensure the physical security of your encryption keys?

Options:
A.

Granular customer control over key access permissions

B.

Centralized key management for simplified administration

C.

Seamless integration with other OCI services for streamlined workflows

D.

Utilization of FIPS 140-2 validated Hardware Security Modules (HSMs)"

Questions 7

A company has implemented OCI IAM policies with multiple levels of compartments. A policy attached to a parent compartment grants "manage virtual-network-family" permissions. A policy attached to a child compartment grants "use virtual-network-family" permissions.

1z0-1104-25 Question 7

According to OCI IAM policy inheritance, how does the OCI IAM policy engine resolve the permissions for a user attempting to perform an operation that requires 'manage' permissions in the child compartment?

Options:
A.

The operation is denied due to conflicting policies.

B.

The policy in the parent compartment takes precedence, and the user is granted "manage" permissions.

C.

The policy in the child compartment takes precedence, and the user is granted "use" permissions only.

Questions 8

Which are the essential components to create a rule for the Oracle Cloud Infrastructure (OCI) Events Service?

Options:
A.

Install Key and Service Connector

B.

Rule Conditions and Management Agent Cloud Service

C.

Rule Conditions and Actions

D.

Install Key and Actions

Questions 9

Your organization needs to implement strong password policies for users in OCI.

Which of the following statements is TRUE about password policies in OCI IAM?

Options:
A.

Custom password policies allow for granular control over password complexity.

B.

The default password policy cannot be modified.

C.

Only one password policy can be applied to all users in a domain.

D.

Simple password policies are suitable for production environments.

Questions 10

Within OCI IAM identity domains, the AD Bridge component serves a critical role. How does the AD Bridge functionality specifically enhance Identity and Access Management (IAM) practices?

Options:
A.

It simplifies user provisioning by enabling automated synchronization of user accounts and group memberships from an existing Microsoft Active Directory (AD) environment.

B.

It facilitates delegated administration, allowing authorized AD users to manage specific resources within the OCI identity domain.

C.

It strengthens access security by providing an additional layer of authentication through AD integration.

D.

It directly integrates with OCI MFA providers, allowing for seamless enforcement of MFA for users authenticated through AD credentials.

Exam Code: 1z0-1104-25
Certification Provider: Oracle
Exam Name: Oracle Cloud Infrastructure 2025 Security Professional
Last Update: Jul 11, 2025
Questions: 36
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

Oracle Related Exams

How to pass Oracle 1z0-1105-23 - Oracle Cloud Data Management 2023 Foundations Associate Exam
How to pass Oracle 1z0-1119-1 - Oracle Cloud Infrastructure for Sunbird Ed Specialty - Rel 1 Exam
How to pass Oracle 1z0-1123-24 - Oracle Cloud Infrastructure 2024 Migration Architect Professional Exam
How to pass Oracle 1z0-1109-24 - Oracle Cloud Infrastructure 2024 Security Professional Exam
How to pass Oracle 1z0-1067-24 - Oracle Cloud Infrastructure 2024 Cloud Operations Professional Exam
How to pass Oracle 1z0-1084-24 - Oracle Cloud Infrastructure 2024 Developer Professional Exam
How to pass Oracle 1z0-1085-24 - Oracle Cloud Infrastructure 2024 Foundations Associate Exam

Oracle Free Exams

Oracle Free Exams
Examstrack offers comprehensive free resources and practice tests for Oracle exams.