[Mar 22, 2024] Prepare For The 1z0-1104-23 Question Papers In Advance
1z0-1104-23 PDF Dumps Real 2024 Recently Updated Questions
NEW QUESTION # 88
Which statement is not true about Cloud Security Posture?
- A. Problems are defined by the type of detector that creates them: activity or configuration.
- B. Problems can be resolved, dismissed, or remediated.
- C. Problems are created when Cloud Guard discovers a deviation from a responder rule.
- D. Problems contain data about the specific type of issue that was found.
Answer: C
Explanation:
Explanation
https://www.oracle.com/security/cloud-security/what-is-cspm/
NEW QUESTION # 89
What information do youget by using the Network Visualizer tool?
- A. Organization of subnets and VLANs across availability domains
- B. Interconnectivity of VCNs
- C. Routes defined between subnets and gateways
- D. State of subnets in a VCN
Answer: B
Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/network_visualizer.htm You can view and understand the following from this diagram:
How VCNs are inter-connected
How on-premises networks are connected (using FastConnect or Site-to-Site VPN) Which routing entities (DRGs and so on) control trafficrouting How your transit routing is configured
NEW QUESTION # 90
Which statements are CORRECT about Security Zone policy in OCI ? Select TWO correct answers
- A. Resources in a security zone must be accessible from internet
- B. Bucket can't be moved from a security zone to a standard compartment
- C. Block volume canbe moved from a security zone to a standard compartment
- D. Resources in a security zone must be encrypted using customer-managed keys
Answer: B,D
Explanation:
Explanation
Table Description automatically generated
NEW QUESTION # 91
Which is NOT a compliance document?
- A. Penetration test report
- B. Certificate
- C. Bridge letter
- D. Attestation
Answer: A
Explanation:
Types of Compliance Documents
When viewing compliance documents, you can filter onthe following types:
Attestation. A Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of Compliance document.
Audit. A general audit report.
Bridge Letter (BridgeLetter). A bridge letter. Bridge letters provide compliance information forthe period of time between the end date of an SOC report and the date of the release of a new SOC report.
Certificate. A document indicating certification by a particular authority, with regard to certification requirements and examination results conforming to said requirements.
SOC3. A Service Organization Controls 3 audit report that provides information relating to a service organization's internal controls for security, availability, confidentiality, and privacy.
Other. A compliance document that doesn't fit into any of the preceding, more specific categories.
https://docs.oracle.com/en-us/iaas/Content/ComplianceDocuments/Concepts/compliancedocsoverview.htm
NEW QUESTION # 92
An automobile company needs to configure Bastion Managed SSH session to a compute instance in a private subnet. What are the TWO prerequisites to configure successfully?
- A. NAT or Service Gateway should be attached to the private subnet
- B. SSH port forwarding should be enabled
- C. There is no need for any gateway in private subnet
- D. Route rule to a NAT or Service Gateway should be associated with the subnet of the route table
Answer: A,D
Explanation:
Explanation
For a Bastion Managed SSH session to a compute instance in a private subnet, the instance must have access to the internet, which can be provided by a NAT Gateway or a Service Gateway34. Additionally, a route rule directing traffic to the NAT or Service Gateway should be associated with the subnet's route table34.
NEW QUESTION # 93
Select the component that encompasses the overall configuration of your WAF service on OCI.
- A. Web Application Firewall policy
- B. Bot Management
- C. Protection rules
- D. Origin
Answer: A
Explanation:
WAF Policy Management
Provides an overview of web application firewall (WAF) policies, including their creation, updating, and deletion.
WAF policies encompass the overall configuration of your WAF service, includingaccess rules, rate limiting rules, and protection rules.
https://docs.oracle.com/en-us/iaas/Content/WAF/Policies/waf-policy_management.htm
NEW QUESTION # 94
An e-commerce company needs to authenticate with third-party API that don't support OCI's signature-based authentication.
What can be the solution for the above scenario?
- A. Security Token
- B. Asymmetric keys
- C. Auth Token/Swift Password
- D. API Key Authentication
Answer: C
Explanation:
NEW QUESTION # 95
You have a tenancy that has five compartments across two regions, Ashburn (home region) and Phoenix. Which three steps would you perform in Cloud Guard to ensure that Cloud Guard monitors your entire tenancy accurately? (Choose three.)
- A. Attach detector recipes and the responder recipe to your target.
- B. Create a target in your root compartment.
- C. Schedule a scan recipe for each target
- D. Choose your reporting region while enabling Cloud Guard.
- E. Enable Cloud Guard in compartment settings for each of your five compartments.
Answer: B,C,D
NEW QUESTION # 96
Which two responsibilities must be taken care of by a customer while managing Web Application Firewall (WAF)? (Choose two.)
- A. Import new Open Web Application Security Project (OWASP) Core Rule Sets (CRS) as they are released
- B. Tune WAF's access rules and bot management strategies according to the web application traffic
- C. Patch their WAF instance when Oracle makes faxes available.
- D. Provide High Availability (HA) for the WAF edge nodes.
- E. Onboard and configure the WAF policy for the web application
Answer: B,E
NEW QUESTION # 97
An e-commerce company needs to authenticate with third-party API that don't support OCI's signature-based authentication.
What can be the solution for the above scenario?
- A. Security Token
- B. Asymmetric keys
- C. Auth Token/Swift Password
- D. API Key Authentication
Answer: C
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
NEW QUESTION # 98
As a solutions architect, you need to assist operations team to write an I AM policy to give users in group-uat1 and group- uat2 access to manage all resources in the compartment Uat. Which is the CORRECT IAM policy
?
- A. Allow any-user to manage all resources in tenancy where target.compartment= Uat
- B. Allow group /group-uat*/ to manage all resources in compartment Uat
- C. Allow group group-uat1 group-uat2 tomanage all resources in compartment Uat
- D. Allow any-user to manage all resources in compartment Uat where request.group=/group-uat/*
Answer: B
Explanation:
Explanation
This policy allows users in groups whose names start with "group-uat" to manage all resources in the compartment named "Uat"12.
NEW QUESTION # 99
When using Management Agent to collect logs continuously, which is therequired configuration for OCI Logging Analytics to retrieve data from numerous logs for an instance?
- A. Entity - Source Association
- B. Entity - Agent Association
- C. Source-Entity Association
- D. Agent - Entity Association
Answer: C
Explanation:
NEW QUESTION # 100
Which statement is not true about Cloud Security Posture?
- A. Problems are defined by the type of detector that creates them: activity or configuration.
- B. Problems can be resolved, dismissed, or remediated.
- C. Problems are created when Cloud Guard discovers a deviation from a responder rule.
- D. Problems contain data about the specific type of issue that was found.
Answer: C
Explanation:
https://www.oracle.com/security/cloud-security/what-is-cspm/
NEW QUESTION # 101
Your web application is protected by the Web Application Firewall (WAF) service in Oracle Cloud Infrastructure (OCT). You want to block traffic originating from a country where your company is not allowed to do business. Where would you create a WAF rule to block traffic from a specific country? (Choose the best Answer.)
- A. Access Control Rules
- B. Protection Rules
- C. Origin Management
- D. Cache Rules
- E. Bet Management
Answer: A
NEW QUESTION # 102
A http web server hosted on an Oracle cloud infrastructure compute instance in a public subnet of the vcsl virtual cloudnetwork has a stateless security ingress rule for port 80 access through internet gateway stateful network security group notification for port 80 how will the Oci vcn handle request response traffic to the compute instance for a web page from the http server with port 80?
- A. network security group would supersede the security utility list and allow both inbound and outbound traffic
- B. the union of both configuration would happen and allow both inbound and outbound traffic
- C. Because there is no Egress ruled defined in Security List, The Response would not pass through Internet Gateway.
- D. due to the conflict in security configuration inbound request traffic would not be allowed
Answer: B
Explanation:
Explanation
In OCI, if there's a stateless rule in the security list and a stateful rule in the network security group, both rules are evaluated. The union of both configurations would happen, allowing both inbound and outbound traffic. This means that if an incoming packet is allowed by either the security lists or the network security groups, then it's allowed into the instance. Similarly, if an outgoing packet is allowed by either, then it's allowed out of the instance
NEW QUESTION # 103
Oracle Object Storage achieves data durability by which of the mechanisms ? Select TWO correct answers
- A. Redundant Storage across availability domains
- B. Object Versioning
- C. Service Gateway
- D. Redundant Array of IndependentDisks
Answer: A,B
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
NEW QUESTION # 104
What is the configuration to avoid publishing messages during the specified time range known as?
- A. Resource group
- B. Statistic
- C. Suppression
- D. Trigger rule
Answer: C
Explanation:
Graphical user interface, text, application, email Description automatically generated
NEW QUESTION # 105
Which of these protects customer data at rest and in transit in a way that allows customers to meet their security and compliance requirements forcryptographic algorithms and key management?
- A. Data encryption
- B. Security controls
- C. Customer isolation
- D. Identity Federation
Answer: A
Explanation:
Explanation
DATA ENCRYPTION
Protect customer data at-rest and in-transit in a way that allows customers to meet their security and compliance requirements for cryptographic algorithms and key management.
https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm
NEW QUESTION # 106
......
Oracle 1z0-1104-23 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
1z0-1104-23 Dumps and Practice Test (172 Exam Questions): https://www.exam4docs.com/1z0-1104-23-study-questions.html
Released Oracle 1z0-1104-23 Updated Questions PDF: https://drive.google.com/open?id=1Hmce0HWx-KautpSskvGyRkKT_Ra0L5DU

