Updated Jan-2024 1z0-1104-22 Exam Practice Test Questions
Verified 1z0-1104-22 dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump
To pass the Oracle 1z0-1104-22 exam, candidates need to have a solid understanding of cloud security concepts and Oracle Cloud Infrastructure services. They should be familiar with the latest security threats and vulnerabilities and know how to apply security controls to mitigate those risks.
Oracle 1z0-1104-22 Certification Exam is a computer-based exam that consists of 60 multiple-choice questions. Candidates are given two hours to complete the exam, and must achieve a passing score of 70% or higher to earn their certification. 1z0-1104-22 exam can be taken at a Pearson VUE testing center or online from the comfort of your own home or office.
NEW QUESTION # 24
Which Security Zone policy is NOT valid?
- A. A boot volume can be moved from a security zone to a standard compartment.
- B. Resources in a security zone should not be accessible from the public internet.
- C. Resources in a security zone must be automatically backed up regularly.
- D. A compute instance cannot be moved from a security zone to a standard compartment.
Answer: A
NEW QUESTION # 25
What do the features of OS Management Service do?
- A. Provide paid service and support to OCI subscribers for fixes on priority.
- B. Add complexity in using multiple tools to manage mixed-OS environments.
- C. Encourage manual setup to avoid machine-induced errors.
- D. Increase security and reliability by regular bug fixes.
Answer: D
Explanation:
https://docs.oracle.com/en/solutions/oci-best-practices/manage-your-operating-systems1.html
NEW QUESTION # 26
Which type of file system does file storage use?
- A. NVMe
- B. SSD
- C. Paravirtualized
- D. iSCSI
- E. NFSv3
Answer: E
Explanation:
The File Storage service supports the Network File System version 3.0 (NFSv3) protocol. The service supports the Network Lock Manager (NLM) protocol for file locking functionality.
https://docs.oracle.com/en-us/iaas/Content/File/Concepts/filestorageoverview.htm
NEW QUESTION # 27
Which resources can be used to create and manage from Vault Service ? Select TWO correct answers
- A. Keys
- B. IAM
- C. Cloud Guard
- D. Secret
Answer: A,D
Explanation:
NEW QUESTION # 28
Which security issues can be identified by Oracle Vulnerability Scanning Service? Select TWO correct answers
- A. CIS published Industry-standard benchmarks
- B. Distributed Denial of Service (DDoS)
- C. SQL Injection
- D. Ports that are unintentionally left open can be a potential attack vector for cloud resources
Answer: A,D
Explanation:
NEW QUESTION # 29
What is the matching rule syntax for a single condition?
- A. Option D
- B. Option C
- C. Option B
- D. Option A
Answer: B
Explanation:
NEW QUESTION # 30
Which statement about Oracle Cloud Infrastructure Multi-Factor Authentication (MFA) is NOT valid?
- A. A user can register only one device to use for MFA.
- B. Users cannot disable MFA for themselves.
- C. An administrator can disable MFA for another user.
- D. Users must install a supported authenticator app on the mobile device they intend to register for MFA.
Answer: B
NEW QUESTION # 31
Which tasks can you perform on a dedicated virtual machine host?
- A. Manual scaling
- B. Instance configurations
- C. Creating instance pools
- D. Capacity reservations
Answer: A
Explanation:
Supported features: Most of the Compute features for VM instances are supported for instances running on dedicated virtual machine hosts. However, the following features are not supported:
Autoscaling
Capacity reservations
Instance configurations
Instance pools
Burstable instances
Reboot migration. You can use manual migration instead
https://docs.oracle.com/en-us/iaas/Content/Compute/Concepts/dedicatedvmhosts.htm#Dedicated_Virtual_Machine_Hosts
NEW QUESTION # 32
How can you establish private connectivity over two VCN within same OCI region without traversing the traffic over public internet ?
- A. Remote VCN Peering
- B. NAT Gateway
- C. Data Guard
- D. Local VCN Peering
Answer: D
Explanation:
NEW QUESTION # 33
You want to make API calls against other OCI services from your instance without configuring user credentials. How would you achieve this?
- A. Create a dynamic group and add your instance.
- B. Create a group and add a policy.
- C. Create a dynamic group and add a policy.
- D. No configuration is required for making API calls.
Answer: C
Explanation:
DYNAMIC GROUP
Dynamic groups allow you to group Oracle Cloud Infrastructure instances as principal actors, similar to user groups. You can then create policies to permit instances in these groups to make API calls against Oracle Cloud Infrastructure services. Membership in the group is determined by a set of criteria you define, called matching rules. https://docs.cloud.oracle.com/en-us/iaas/Content/Identity/Tasks/callingservicesfrominstances.htm
NEW QUESTION # 34
Which Cloud Guard component identifies issues with resources or user actions and alerts you when an issue is found?
- A. Problems
- B. Targets
- C. Detectors
- D. Responders
Answer: C
Explanation:
Detector
Performs checks to identify potential security problems based on activities or configurations. Rules followed to identify problems are the same for all compartments in a target.
https://docs.oracle.com/en-us/iaas/cloud-guard/using/part-start.htm
NEW QUESTION # 35
Which cache rules criterion matches if the concatenation of the requested URL path and query are identical to the contents of the value field?
- A. URL_PART_CONTAINS
- B. URL_IS
- C. URL_PART_ENDS_WITH
- D. URL_STARTS_WITH
Answer: B
Explanation:
URL_IS: Matches if the concatenation of request URL path and query is identical to the contents of the value field. URL must start with a /.
https://docs.oracle.com/en-us/iaas/tools/terraform-provider-oci/4.57.0/docs/d/waas_waas_policy.html
NEW QUESTION # 36
As a Security Admin you want to inspect the metadata and actual data in your Oracle databases to discover sensitive data and provide comprehensive results listing the sensitive columns and related information. Which Data Safe feature will help you to achieve the above requirement ?
- A. Data Masking
- B. Security Assessment
- C. User Assessment
- D. Data Discovery
Answer: D
Explanation:
NEW QUESTION # 37
As a solutions architect, you need to assist operations team to write an I AM policy to give users in group-uat1 and group- uat2 access to manage all resources in the compartment Uat. Which is the CORRECT IAM policy ?
- A. Allow group group-uat1 group-uat2 to manage all resources in compartment Uat
- B. Allow any-user to manage all resources in compartment Uat where request.group=/group-uat/*
- C. Allow group /group-uat*/ to manage all resources in compartment Uat
- D. Allow any-user to manage all resources in tenancy where target.compartment= Uat
Answer: A
NEW QUESTION # 38
An e-commerce company needs to authenticate with third-party API that don't support OCI's signature-based authentication.
What can be the solution for the above scenario?
- A. Auth Token/Swift Password
- B. Asymmetric keys
- C. API Key Authentication
- D. Security Token
Answer: A
Explanation:
NEW QUESTION # 39
You want software that can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm.
Which software must you use?
- A. Security Information and Event Management (SIEM)
- B. Security Event Management (SEM)
- C. Security Information Management (SIM)
- D. Security Integration Management (SIM)
Answer: A
NEW QUESTION # 40
Select the component that encompasses the overall configuration of your WAF service on OCI.
- A. Origin
- B. Protection rules
- C. Web Application Firewall policy
- D. Bot Management
Answer: C
Explanation:
WAF Policy Management
Provides an overview of web application firewall (WAF) policies, including their creation, updating, and deletion.
WAF policies encompass the overall configuration of your WAF service, including access rules, rate limiting rules, and protection rules.
https://docs.oracle.com/en-us/iaas/Content/WAF/Policies/waf-policy_management.htm
NEW QUESTION # 41
When does Cloud Guard re-open an issue and update the history?
- A. If it detects an issue again for an Open (unresolved) problem
- B. If it detects an issue for a previously resolved/dismissed activity problem
- C. If it detects an issue for a previously resolved configuration problem
- D. If it detects an issue for a previously dismissed configuration problem
Answer: C
Explanation:
If Cloud Guard detects an issue again for:
An Open (unresolved) problem, it updates the problem history, but doesn't create a new problem.
A previously solved problem, it reopens the issue and updates the history.
A previously dismissed problem, it updates the history.
https://docs.oracle.com/en-us/iaas/cloud-guard/using/problems-page.htm
NEW QUESTION # 42
Which VCN configuration is CORRECT with regard to VCN peering within a same region ?
- A. 194.168.0.0/24 and 194.168.0.0/16
- B. 12.0.0.0/16 and 12.0.0.0/16
C 194.168.0.0/24 and 194.168.0.0/24 - C. 12.0.0.0/16 and 194.168.0.0/16
Answer: C
NEW QUESTION # 43
......
Ultimate Guide to Prepare Free 1z0-1104-22 Exam Questions and Answer: https://drive.google.com/open?id=12nUmKuNDZX_W4v76rzZg19128tkXJZtS
Pass Oracle Cloud Infrastructure 1z0-1104-22 Exam With 95 Questions: https://www.passtestking.com/Oracle/1z0-1104-22-practice-exam-dumps.html