Oracle 1z0-1104-22 Practice Test Pdf Exam Material
1z0-1104-22 Answers 1z0-1104-22 Free Demo Are Based On The Real Exam
NEW QUESTION # 28
An automobile company needs to configure Bastion Managed SSH session to a compute instance in a private subnet. What are the TWO prerequisites to configure successfully?
- A. SSH port forwarding should be enabled
- B. There is no need for any gateway in private subnet
- C. NAT or Service Gateway should be attached to the private subnet
- D. Route rule to a NAT or Service Gateway should be associated with the subnet of the route table
Answer: C,D
NEW QUESTION # 29
you are part of security operation of an organization with thousand of your users accessing Oracle cloud infrastructure it was reported that an unknown user action was executed resulting in configuration error you are tasked to quickly identify the details of all users who were active in the last six hours also with any rest API call that were executed. Which oci feature should you use?
- A. management agent log integration
- B. service connector hub
- C. objectcollectionrule
- D. audit analysis dashboard
Answer: D
NEW QUESTION # 30
Which Security Zone policy is NOT valid?
- A. A compute instance cannot be moved from a security zone to a standard compartment.
- B. Resources in a security zone should not be accessible from the public internet.
- C. A boot volume can be moved from a security zone to a standard compartment.
- D. Resources in a security zone must be automatically backed up regularly.
Answer: C
NEW QUESTION # 31
With regard to WAF in OCI, which of the following statements are NOT customer's responsibility? Select TWO answers.
- A. WAF edge nodes with High Availability
- B. Configure WAF policies for websites
- C. Import latest OWASP Core Rule Sets
- D. Configure Bot Management strategies for a website traffic
Answer: A,C
NEW QUESTION # 32
Which statement is true about Oracle Cloud Infrastructure (OCI) Object Storage server-side encryption?
- A. Each object in a bucket is always encrypted with the same data encryption key.
- B. Customer-provided encryption keys are never stored in OCI Vault service.
- C. All the traffic to and from object storage is encrypted by using Transport Layer Security.
- D. Encryption is not enabled by default.
Answer: C
NEW QUESTION # 33
Operations team has made a mistake in updating the secret contents and immediately need to resume using older secret contents in OCI Secret Management within a Vault.
As a Security Administrator, what step should you perform to rollback to last version? Select TWO correct answers.
- A. Upload new secret and mark as 'Pending'. Promote this secret version as 'Current'
- B. Mark the secret version as 'Rewind'
- C. Mark the secret version as 'Previous'
- D. Mark the secret version as 'deprecated'
Answer: A,C
Explanation:
NEW QUESTION # 34
As a security architect, how can you prevent unwanted bots while desirable bots are allowed to enter?
- A. Vault
- B. Data Guard
- C. Compartments
- D. Web Application Firewall (WAF)
Answer: D
NEW QUESTION # 35
Which volume type contains the image used to boot a compute instance?
- A. Boot volume
- B. Init 6 volume
- C. Block volume
- D. Startup volume
Answer: A
Explanation:
Boot Volumes
When you launch a virtual machine (VM) or bare metal instance based on a platform image or custom image, a new boot volume for the instance is created in the same compartment. That boot volume is associated with that instance until you terminate the instance. When you terminate the instance, you can preserve the boot volume and its data
https://docs.oracle.com/en-us/iaas/Content/Block/Concepts/bootvolumes.htm
NEW QUESTION # 36
What is the matching rule syntax for a single condition?
- A. Option B
- B. Option C
- C. Option D
- D. Option A
Answer: B
Explanation:
NEW QUESTION # 37
Which Cloud Guard component identifies issues with resources or user actions and alerts you when an issue is found?
- A. Targets
- B. Problems
- C. Responders
- D. Detectors
Answer: D
Explanation:
Detector
Performs checks to identify potential security problems based on activities or configurations. Rules followed to identify problems are the same for all compartments in a target.
https://docs.oracle.com/en-us/iaas/cloud-guard/using/part-start.htm
NEW QUESTION # 38
As a Security Admin you want to inspect the metadata and actual data in your Oracle databases to discover sensitive data and provide comprehensive results listing the sensitive columns and related information. Which Data Safe feature will help you to achieve the above requirement ?
- A. Data Discovery
- B. Data Masking
- C. Security Assessment
- D. User Assessment
Answer: A
Explanation:
NEW QUESTION # 39
Select the component that encompasses the overall configuration of your WAF service on OCI.
- A. Protection rules
- B. Origin
- C. Bot Management
- D. Web Application Firewall policy
Answer: D
Explanation:
WAF Policy Management
Provides an overview of web application firewall (WAF) policies, including their creation, updating, and deletion.
WAF policies encompass the overall configuration of your WAF service, including access rules, rate limiting rules, and protection rules.
https://docs.oracle.com/en-us/iaas/Content/WAF/Policies/waf-policy_management.htm
NEW QUESTION # 40
Which Oracle Data Safe feature minimizes the amount of personal data and allows internal test, development, and analytics teams to operate with reduced risk?
- A. data encryption
- B. data masking
- C. data discovery
- D. security assessment
- E. data auditing
Answer: B
NEW QUESTION # 41
Which statements are CORRECT about Multi-Factor Authentication in OCI ? Select TWO correct answers
- A. Members of the Administrators group can disable MFA for other users
- B. A user can register multiple devices to use for MFA.
- C. Members of the Administrators group cannot enable MFA for another user
- D. Users cannot enable MFA for themselves
Answer: A,C
Explanation:

NEW QUESTION # 42
With regard to vulnerability and cloud penetration testing, which rules of engagement apply? Select TWO correct answers.
- A. You are responsible for any damages to Oracle Cloud customers that are caused by your testing activities
- B. Testing should target any other subscription or any other Oracle Cloud customer resources
- C. Physical penetration and vulnerability testing of Oracle facilities is prohibited
- D. Any port scanning must be performed in an aggressive mode
Answer: A,C
Explanation:
NEW QUESTION # 43
Which Oracle Cloud Service provides restricted access to target resources?
- A. Bastion
- B. Load balancer
- C. SSL certificate
- D. Internet Gateway
Answer: A
Explanation:
Bastion
Oracle Cloud Infrastructure Bastion provides restricted and time-limited access to target resources that don't have public endpoints.
https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_features.htm
NEW QUESTION # 44
Which cache rules criterion matches if the concatenation of the requested URL path and query are identical to the contents of the value field?
- A. URL_PART_ENDS_WITH
- B. URL_PART_CONTAINS
- C. URL_IS
- D. URL_STARTS_WITH
Answer: C
Explanation:
URL_IS: Matches if the concatenation of request URL path and query is identical to the contents of the value field. URL must start with a /.
https://docs.oracle.com/en-us/iaas/tools/terraform-provider-oci/4.57.0/docs/d/waas_waas_policy.html
NEW QUESTION # 45
When does Cloud Guard re-open an issue and update the history?
- A. If it detects an issue for a previously resolved/dismissed activity problem
- B. If it detects an issue for a previously dismissed configuration problem
- C. If it detects an issue for a previously resolved configuration problem
- D. If it detects an issue again for an Open (unresolved) problem
Answer: C
Explanation:
If Cloud Guard detects an issue again for:
An Open (unresolved) problem, it updates the problem history, but doesn't create a new problem.
A previously solved problem, it reopens the issue and updates the history.
A previously dismissed problem, it updates the history.
https://docs.oracle.com/en-us/iaas/cloud-guard/using/problems-page.htm
NEW QUESTION # 46
You subscribe to a PaaS service that follows the Shared Responsibility model.
Which type of security is your responsibility?
- A. Data
- B. Guest OS
- C. Network
- D. Infrastructure
Answer: A
Explanation:
https://www.oracle.com/a/ocom/docs/cloud/oracle-ctr-2020-shared-responsibility.pdf
NEW QUESTION # 47
......
Oracle 1z0-1104-22 exam is specifically focused on testing the knowledge and expertise of professionals in securing applications and data in the Oracle Cloud Infrastructure environment. 1z0-1104-22 exam covers a variety of topics such as network security, identity and access management, encryption, data protection, and compliance. These topics are all critical components of cloud security and are essential for professionals to master in order to succeed in this field.
Oracle 1z0-1104-22 Certification Exam is designed for security professionals who want to demonstrate their expertise in securing Oracle Cloud Infrastructure (OCI) environments. 1z0-1104-22 exam is ideal for individuals who are responsible for implementing and managing security controls in an OCI environment, such as security administrators or cloud security architects. 1z0-1104-22 exam is also suitable for anyone who wants to validate their skills and knowledge in cloud security.
1z0-1104-22 [Dec-2023] Newly Released] Exam Questions For You To Pass: https://learningtree.actualvce.com/Oracle/1z0-1104-22-valid-vce-dumps.html