1Z0-1104-25 Sample Questions

1Z0-1104-25 Sample Questions & Answers

Free OCI 2025 Security Professional practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full 1Z0-1104-25 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Protecting Infrastructure - Network and Applications · Implement Network Security Groups (NSGs), Security Lists, and Network Firewalls

    A security architect is configuring OCI Network Firewall to inspect traffic between an on-premises data center and a VCN. The traffic flows through a Dynamic Routing Gateway (DRG). To ensure the firewall inspects this traffic, how should the VCN routing be configured?

    Show answer & explanation

    Correct answer: B

    To insert a Network Firewall into the flow, you must use VCN ingress routing. You attach a route table to the DRG attachment (ingress to VCN) that directs traffic destined for the VCN subnets to the private IP address of the OCI Network Firewall.

  2. Question 2IntermediateSelect 2

    Detecting, Remediating, and Monitoring OCI Resources · Use Cloud Guard to monitor and analyze the security posture

    Which TWO statements accurately describe the behavior of OCI Cloud Guard when a problem is detected? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    Cloud Guard uses Detector Recipes (Configuration and Activity) to define what constitutes a problem. When a rule in a recipe is triggered, a Problem is created.

    Cloud Guard Responders can be set to 'Automatic' mode, allowing them to execute remediation actions (like disabling a public bucket) immediately upon detection.

  3. Question 3Beginner

    Protecting Data · Configure and manage secrets within the OCI Vault

    A developer needs to store database credentials securely and retrieve them programmatically within an application running on OCI Container Instances. The credentials must not be hardcoded. Which OCI Vault component should be used to store these specific credentials?

    Show answer & explanation

    Correct answer: D

    In OCI Vault, a 'Secret' is used to store credentials, passwords, certificates, and other sensitive data. Keys are used for encryption/decryption, whereas Secrets are for storage and retrieval of sensitive text/binary data.

  4. Question 4Intermediate

    Detecting, Remediating, and Monitoring OCI Resources · Implement Security Zones and Security Advisor

    True or False: When a compartment is assigned to a Security Zone, you can selectively exempt specific resources within that compartment from the zone's security policies.

    Show answer & explanation

    Correct answer: B

    This is False. Security Zones enforce policies on the entire compartment. You cannot exempt individual resources within a Security Zone compartment. To have resources with different security postures, they must be placed in a different compartment.

  5. Question 5Advanced

    Implementing Identity and Access Management (IAM) · Implement IAM policies to control access to resources

    You need to create an IAM policy that allows a group 'Auditors' to view all resources in the tenancy but specifically prevents them from viewing the contents of Secrets in OCI Vault. Which policy statement achieves this using 2025 IAM optimization best practices?

    Show answer & explanation

    Correct answer: D

    The verb 'inspect' provides the ability to list resources and view general metadata but does not grant access to sensitive details or user-specified content (like Secret bundles). 'Read' would allow viewing the secret contents.

  6. Question 6Advanced

    Protecting Infrastructure - Network and Applications · Ensure high availability with Load Balancers

    Case Study:

    Company Overview
    TechSafe Solutions is a healthcare analytics provider migrating to OCI. They handle highly sensitive patient data and must comply with strict regulatory requirements (HIPAA).

    Current Situation
    TechSafe has deployed a VCN with public and private subnets. The web servers are in the public subnet, and the database is in the private subnet. They are using Security Lists for access control.

    Requirement
    The security team requires that all SSL traffic to the web servers be terminated at a central point before inspection. Additionally, they need to prevent SQL injection attacks and ensure that no database traffic can be initiated from the internet directly, even if misconfigured.

    Constraint
    The solution must minimize the management overhead of certificates on individual web servers.

    Based on the scenario, which combination of OCI services provides the most secure and manageable solution?

    Show answer & explanation

    Correct answer: B

    This solution meets all requirements: 1) LB terminates SSL (centralized cert management), 2) WAF attached to LB prevents SQL injection, 3) Database in private subnet with NSGs ensures isolation. It minimizes overhead by not managing certs on individual servers.

Ready for the real thing?

The full 1Z0-1104-25 simulator has every exam-style question, timed mode, and instant scoring.