Valid 1z0-1104-23 Test Answers & Oracle 1z0-1104-23 Exam PDF [Q44-Q61]

Share

Valid 1z0-1104-23 Test Answers & Oracle 1z0-1104-23 Exam PDF

Oracle 1z0-1104-23 Certification Real 2023 Mock Exam

NEW QUESTION # 44
which two responsibilities will be oracle when you move your it infrastructure to oracle cloud infrastructure?

  • A. PROVIDING STRONG SECURITY LIST
  • B. MAINTAINING CUSTOMER DATA
  • C. Strong IAM Framework
  • D. Strong Isolation
  • E. ACCOUNT ACCESS MANAGEMENT

Answer: C,D

Explanation:
Oracle is responsible for providing a strong Identity and Access Management (IAM) framework in OCI.
The IAM service lets you control who has access to your cloud resources, what type of access they have, and to which specific resources. You can find more details about this in the Oracle Cloud Infrastructure documentation.
Oracle also ensures strong isolation in its cloud infrastructure, which means that your resources are isolated from other tenants and from Oracle staff. This isolation extends from physical separation of hardware all the way up to access controls on APIs. You can find more details about this in the Oracle Cloud Infrastructure documentation.


NEW QUESTION # 45
Which OCI cloud service lets you centrally manage the encryption keys thatprotect your data and the secret credentials that you use to securely access resources?

  • A. Data Guard
  • B. Data Safe
  • C. Vault
  • D. Cloud Guard

Answer: C

Explanation:
Explanation
Oracle Cloud Infrastructure Vault is a managed service that lets you centrally manage the encryption keysthat protect your data and the secret credentials that you use to securely access resources. Vaults securely store master encryption keys and secrets that you might otherwise store in configuration files or in code.
Specifically, depending on the protection mode, keys are either stored on the server or they are stored on highly available and durable hardware security modules (HSM) that meet Federal Information Processing Standards (FIPS) 140-2 Security Level 3 security certification.
https://docs.oracle.com/en-us/iaas/Content/KeyManagement/Concepts/keyoverview.htm


NEW QUESTION # 46
Where is sensitive configuration data (like certificates, and credentials) is stored by Kubernetes cluster control plane?

  • A. Boot Volume
  • B. Oracle Functions
  • C. Block Volume
  • D. ETCD

Answer: D

Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated


NEW QUESTION # 47
In which two ways can you improve data durability in Oracle Cloud Infrastructure Object Storage?

  • A. Limit delete permissions
  • B. Enable client-side encryption
  • C. Enable Versioning
  • D. Enable server-sideencryption
  • E. Setup volumes in a RAID1 configuration

Answer: A,C

Explanation:
Enabling versioning can improve data durability in OCI Object Storage by keeping multiple versions of an object in the same bucket5.
Limiting delete permissions can also improve data durability by preventing unauthorized users from deleting data


NEW QUESTION # 48
Which Oracle Cloud Service provides restricted accessto target resources?

  • A. Internet Gateway
  • B. Bastion
  • C. SSL certificate
  • D. Load balancer

Answer: B

Explanation:
Explanation
Bastion
Oracle Cloud Infrastructure Bastion provides restricted and time-limited access to target resources that don't have public endpoints.
Diagram Description automatically generated

https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_features.htm


NEW QUESTION # 49
Operations team has made a mistake in updating the secret contents and immediately need to resume usingolder secret contents in OCI Secret Management within a Vault.
As a Security Administrator, what step should you perform to rollback to last version? Select TWO correct answers.

  • A. Upload new secret and mark as 'Pending'. Promote this secret version as 'Current'
  • B. Mark the secret version as'Previous'
  • C. Mark the secret version as 'Rewind'
  • D. Mark the secret version as 'deprecated'

Answer: A,B

Explanation:
Explanation
Graphical user interface, text, application Description automatically generated


NEW QUESTION # 50
Which IAM policy should be created to give XYZ the ability to list contents of a resource excluding the fneeds to authenticatein prod compartment ? Principle of least priviledge should be used.

  • A. Allow group XYZ to inspect all resources in tenancy where target.compartment.name != prod
  • B. Allow group XYZ to manage all resources in compartment != prod
  • C. Allow group XYZ to use all resources in compartment != prod
  • D. Allow group XYZ to read all resources in tenancy where target.compartment.name != prod

Answer: A

Explanation:
Explanation
Graphical user interface, text, application Description automatically generated


NEW QUESTION # 51
Which statement is true about using custom BYOI instances in Windows Servers that are managed by OS Management Service?

  • A. Windows Servers that already has the minimum agent version requires an agent update or installation.
  • B. Windows Servers that does not have the minimum agent version requires an agent update or installation.
  • C. Windows Servers that does not have the minimum agent version does not require an agent update or installation.
  • D. Windows Servers that already has the minimum agent version does not require an agent update or installation.

Answer: B

Explanation:
Explanation
https://docs.oracle.com/cd/E11857_01/install.111/e15311/agnt_install_windows.htm


NEW QUESTION # 52
What do the features of OS Management Service do?

  • A. Provide paid service and support to OCI subscribers for fixes on priority.
  • B. Add complexity in using multiple tools tomanage mixed-OS environments.
  • C. Increase security and reliability by regular bug fixes.
  • D. Encourage manual setup to avoid machine-induced errors.

Answer: C

Explanation:
Explanation
https://docs.oracle.com/en/solutions/oci-best-practices/manage-your-operating-systems1.html


NEW QUESTION # 53
A http web server hosted on an Oracle cloud infrastructure compute instance in a public subnet of the vcsl virtual cloudnetwork has a stateless security ingress rule for port 80 access through internet gateway stateful network security group notification for port 80 how will the Oci vcn handle request response traffic to the compute instance for a web page from the http server with port 80?

  • A. the union of both configuration would happen and allow both inbound and outbound traffic
  • B. Because there is no Egress ruled defined in Security List, The Response would not pass through Internet Gateway.
  • C. due to the conflict in security configuration inbound request traffic would not be allowed
  • D. network security group would supersede the security utility list and allow both inbound and outbound traffic

Answer: A

Explanation:
Explanation
In OCI, if there's a stateless rule in the security list and a stateful rule in the network security group, both rules are evaluated. The union of both configurations would happen, allowing both inbound and outbound traffic. This means that if an incoming packet is allowed by either the security lists or the network security groups, then it's allowed into the instance. Similarly, if an outgoing packet is allowed by either, then it's allowed out of the instance


NEW QUESTION # 54
Cloud Guard detected a risk score of zeroin the dashboard, what does this mean ?

  • A. Risk score doesn't say anything. These are just numbers
  • B. LOW or MINOR issues
  • C. No problem detected for any resource
  • D. Larger number of problems that have high risk levels ( HIGH or CRITICAL )

Answer: C

Explanation:
Explanation
Graphical user interface, text, application Description automatically generated


NEW QUESTION # 55
Which OCI service canindex, enrich, aggregate, explore, search, analyze, correlate, visualize and monitor data?

  • A. Data Guard
  • B. Data Safe
  • C. WAF
  • D. Logging Analytics

Answer: D

Explanation:
Explanation


NEW QUESTION # 56
Which statement is not true about Cloud Security Posture?

  • A. Problems are created when Cloud Guard discovers a deviation from a responder rule.
  • B. Problems are defined by the type of detector that creates them: activity or configuration.
  • C. Problems can be resolved, dismissed, or remediated.
  • D. Problems contain data about the specific type of issue that was found.

Answer: A

Explanation:
Explanation
https://www.oracle.com/security/cloud-security/what-is-cspm/


NEW QUESTION # 57
An automobile company needs to configure Bastion Managed SSH session to a compute instance in a private subnet. What are the TWO prerequisites to configure successfully?

  • A. Route rule to a NAT or Service Gateway should be associated with the subnet of the route table
  • B. NAT or Service Gateway should be attached to the private subnet
  • C. There is no need for any gateway in private subnet
  • D. SSH port forwarding should be enabled

Answer: A,B

Explanation:
Explanation
For a Bastion Managed SSH session to a compute instance in a private subnet, the instance must have access to the internet, which can be provided by a NAT Gateway or a Service Gateway34. Additionally, a route rule directing traffic to the NAT or Service Gateway should be associated with the subnet's route table34.


NEW QUESTION # 58
Which of these protects customer data at rest and in transit in a way that allows customers to meet their security and compliance requirements forcryptographic algorithms and key management?

  • A. Security controls
  • B. Customer isolation
  • C. Data encryption
  • D. Identity Federation

Answer: C

Explanation:
Explanation
DATA ENCRYPTION
Protect customer data at-rest and in-transit in a way that allows customers to meet their security and compliance requirements for cryptographic algorithms and key management.
https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm


NEW QUESTION # 59
which three resources are required to encrypt a block volume with the customer managed key?

  • A. SYMMETRIC MASTER KEY ENCRYPTlON KEY
  • B. MAXIMUM SECURITY ZONE
  • C. Secrets
  • D. BLOCK KEY
  • E. OCI VAIRT
  • F. IAM Policy Allowing Block Storage to Use Keys

Answer: C,E,F

Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/SecurityAdvisor/Tasks/creatingsecureblockvolume.htm


NEW QUESTION # 60
Which statement is true about origin management in WAF?
Statement A: Multiple origins can be defined.
Statement B: Only a single origin can be active fora WAF.

  • A. Only statement B is true.
  • B. Both the statements are false.
  • C. Both the statements are true.
  • D. Only statement A is true.

Answer: D

Explanation:
Statement A: Multiple origins can be defined1. This is true. In Oracle Cloud Infrastructure's Web Application Firewall (WAF), multiple origins can be defined for a WAF policy using Origin Groups1. When at least two origins are configured, load balancing is enabled1.
Statement B: Only a single origin can be active for a WAF2. This is false. In the Origin Settings of the WAF policy, all origins are active under origin groups2.


NEW QUESTION # 61
......

1z0-1104-23 Exam Questions and Valid 1z0-1104-23 Dumps PDF: https://www.torrentexam.com/1z0-1104-23-exam-latest-torrent.html

1z0-1104-23 Brain Dump: A Study Guide with Tips & Tricks for passing Exam: https://drive.google.com/open?id=18t-r8Hs9FySWkriSaZqVhWYS-jVFL6LR