(Oct-2023) Get professional help from our 1z0-1104-22 Dumps PDF
Give You Free Regular Updates on 1z0-1104-22 Exam Questions
Oracle Cloud Infrastructure 2022 Security Professional certification exam covers a range of security topics, including identity and access management, network security, data protection, and compliance. 1z0-1104-22 exam tests the candidate's knowledge in securing cloud-based applications and infrastructure, and their ability to design and implement security solutions on the OCI platform.
NEW QUESTION # 57
Which tasks can you perform on a dedicated virtual machine host?
- A. Capacity reservations
- B. Creating instance pools
- C. Instance configurations
- D. Manual scaling
Answer: D
Explanation:
Supported features: Most of the Compute features for VM instances are supported for instances running on dedicated virtual machine hosts. However, the following features are not supported:
Autoscaling
Capacity reservations
Instance configurations
Instance pools
Burstable instances
Reboot migration. You can use manual migration instead
https://docs.oracle.com/en-us/iaas/Content/Compute/Concepts/dedicatedvmhosts.htm#Dedicated_Virtual_Machine_Hosts
NEW QUESTION # 58
Which statements are CORRECT about Security Zone policy in OCI ? Select TWO correct answers
- A. Resources in a security zone must be encrypted using customer-managed keys
- B. Resources in a security zone must be accessible from internet
- C. Bucket can't be moved from a security zone to a standard compartment
- D. Block volume can be moved from a security zone to a standard compartment
Answer: A,C
Explanation:
NEW QUESTION # 59
What does an audit log event include?
- A. Footer
- B. Type of input
- C. Header
- D. Audit type
Answer: C
Explanation:
The HTTP header fields and values in the request.
https://docs.oracle.com/en-us/iaas/Content/Audit/Reference/logeventreference.htm
NEW QUESTION # 60
Which volume type contains the image used to boot a compute instance?
- A. Init 6 volume
- B. Block volume
- C. Boot volume
- D. Startup volume
Answer: C
Explanation:
Boot Volumes
When you launch a virtual machine (VM) or bare metal instance based on a platform image or custom image, a new boot volume for the instance is created in the same compartment. That boot volume is associated with that instance until you terminate the instance. When you terminate the instance, you can preserve the boot volume and its data
https://docs.oracle.com/en-us/iaas/Content/Block/Concepts/bootvolumes.htm
NEW QUESTION # 61
Which statement is true about origin management in WAF?
Statement A: Multiple origins can be defined.
Statement B: Only a single origin can be active for a WAF.
- A. Both the statements are false.
- B. Both the statements are true.
- C. Only statement B is true.
- D. Only statement A is true.
Answer: B
NEW QUESTION # 62
As a security administrator, you found out that there are users outside your co network who are accessing OCI Object Storage Bucket. How can you prevent these users from accessing OCI resources in corporate network?
- A. Create an 1AM policy and create WAF rules
- B. Create PAR to restrict access the access
- C. Create an 1AM policy and add a network source
- D. Make OCI resources private instead of public
Answer: C
Explanation:
NEW QUESTION # 63
Which resources can be used to create and manage from Vault Service ? Select TWO correct answers
- A. Keys
- B. Cloud Guard
- C. Secret
- D. IAM
Answer: A,C
Explanation:
NEW QUESTION # 64
A http web server hosted on an Oracle cloud infrastructure compute instance in a public subnet of the vcsl virtual cloud network has a stateless security ingress rule for port 80 access through internet gateway stateful network security group notification for port 80 how will the Oci vcn handle request response traffic to the compute instance for a web page from the http server with port 80?
- A. Because there is no Egress ruled defined in Security List, The Response would not pass through Internet Gateway.
- B. the union of both configuration would happen and allow both inbound and outbound traffic
- C. due to the conflict in security configuration inbound request traffic would not be allowed
- D. network security group would supersede the security utility list and allow both inbound and outbound traffic
Answer: A
NEW QUESTION # 65
Where is sensitive configuration data (like certificates, and credentials) is stored by Kubernetes cluster control plane?
- A. Block Volume
- B. ETCD
- C. Oracle Functions
- D. Boot Volume
Answer: B
Explanation:
NEW QUESTION # 66
Operations team has made a mistake in updating the secret contents and immediately need to resume using older secret contents in OCI Secret Management within a Vault.
As a Security Administrator, what step should you perform to rollback to last version? Select TWO correct answers.
- A. Mark the secret version as 'Rewind'
- B. Mark the secret version as 'deprecated'
- C. Upload new secret and mark as 'Pending'. Promote this secret version as 'Current'
- D. Mark the secret version as 'Previous'
Answer: C,D
Explanation:
NEW QUESTION # 67
Which statement is true about using custom BYOI instances in Windows Servers that are managed by OS Management Service?
- A. Windows Servers that already has the minimum agent version requires an agent update or installation.
- B. Windows Servers that does not have the minimum agent version does not require an agent update or installation.
- C. Windows Servers that already has the minimum agent version does not require an agent update or installation.
- D. Windows Servers that does not have the minimum agent version requires an agent update or installation.
Answer: D
Explanation:
https://docs.oracle.com/cd/E11857_01/install.111/e15311/agnt_install_windows.htm
NEW QUESTION # 68
When creating an OCI Vault, which factors may lead to select the Virtual Private Vault ? Select TWO correct answers
- A. Ability to back up the vault
- B. Need for more than 9211 key versions
- C. To mask Pll data for non-production environment
- D. Greater degree of isolation
Answer: A,D
Explanation:
NEW QUESTION # 69
Which VCN configuration is CORRECT with regard to VCN peering within a same region ?
- A. 12.0.0.0/16 and 194.168.0.0/16
- B. 12.0.0.0/16 and 12.0.0.0/16
C 194.168.0.0/24 and 194.168.0.0/24 - C. 194.168.0.0/24 and 194.168.0.0/16
Answer: A
NEW QUESTION # 70
You have configured the Management Agent on an Oracle Cloud Infrastructure (OCI) Linux instance for log ingestion purposes.
Which is a required configuration for OCI Logging Analytics service to collect data from multiple logs of this Instance?
- A. Log - Log Group Association
- B. Source - Entity Association
- C. Log Group - Source Association
- D. Entity - Log Association
Answer: B
NEW QUESTION # 71
As a security administrator, you want to create cloud resources that align with Oracle's security principles and best practices. Which security service should you use?
- A. Web Application Firewall (WAF)
- B. Cloud Guard
- C. Identity and Access Management
- D. Security Advisor
Answer: D
Explanation:
NEW QUESTION # 72
How can you convert a fixed load balancer to a flexible load balancer?
- A. There is no way to covert the load balancer.
- B. Delete the fixed load balancer and create a new one.
- C. Use Update Shape workflows.
- D. Using the Edit Listener option.
Answer: C
NEW QUESTION # 73
Which architecture is based on the principle of "never trust, always verify"?
- A. Zero trust
- B. Fluid perimeter
- C. Defense in depth
- D. Federated identity
Answer: A
Explanation:
Enterprise Interest in Zero Trust is Growing Ransomware and breaches are top of the news cycle and a major concern for organizations big and small. So, many are now looking at the Zero Trust architecture and its primary principle "never trust, always verify" to provide greater protection.
According to Report Linker, the Zero Trust security market is projected to grow from USD 15.6 billion in 2019 to USD 38.6 billion by 2024 and that sounds right based on the large number of companies pitching their Zero Trust wares at RSA 2020.
The enterprise was well represented at the conference and there was a tremendous amount of interest in Zero Trust. Interestingly, even though Zero Trust environments are often made up of several solutions from multiple vendors it hasn't prevented each of the vendors from evangelizing their flavors of Zero Trust. This left the thousands of attendees to attempt to cut through the Zero Trust buzz and noise and make their own conclusions to the best approach.
https://blogs.oracle.com/cloudsecurity/post/rsa-2020-recap-cloud-security-moves-to-the-front
NEW QUESTION # 74
Which of the following is necessary step when creating a secret in vault?
- A. Shamir's secret sharing algorithm should be used to unseal the vault
- B. Digest Hash should be created of the secret value
- C. Vault-managed key is necessary to encrypt the secret
- D. Object Storage must be created to run secret service
Answer: C
Explanation:
https://docs.oracle.com/en/database/other-databases/essbase/21/essad/create-vault-and-secrets.html
NEW QUESTION # 75
Which components are a part of the OCI Identity and Access Management service?
- A. Policies
- B. Regional subnets
- C. Compute instances
- D. VCN
Answer: A
Explanation:
https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/overview.htm
NEW QUESTION # 76
Which of these protects customer data at rest and in transit in a way that allows customers to meet their security and compliance requirements for cryptographic algorithms and key management?
- A. Security controls
- B. Customer isolation
- C. Data encryption
- D. Identity Federation
Answer: C
Explanation:
DATA ENCRYPTION
Protect customer data at-rest and in-transit in a way that allows customers to meet their security and compliance requirements for cryptographic algorithms and key management.
https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm
NEW QUESTION # 77
Which of the following services are NOT Security Services in OCI ? Select TWO answers.
- A. Cloud Guard
- B. Block Volume
- C. Vault
- D. Data Guard
Answer: B,D
NEW QUESTION # 78
An e-commerce company needs to authenticate with third-party API that don't support OCI's signature-based authentication.
What can be the solution for the above scenario?
- A. Security Token
- B. Auth Token/Swift Password
- C. API Key Authentication
- D. Asymmetric keys
Answer: B
Explanation:
NEW QUESTION # 79
......
Achieve the 1z0-1104-22 Exam Best Results with Help from Oracle Certified Experts: https://www.dumptorrent.com/1z0-1104-22-braindumps-torrent.html
Provide 1z0-1104-22 Practice Test Engine for Preparation: https://drive.google.com/open?id=11EVLWW-fc-VIt8gRTMotysiGs8yoTJLu