[Aug 17, 2022] Uplift Your 1z0-1104-21 Exam Marks With The Help of 1z0-1104-21 Dumps
Use Oracle 1z0-1104-21 Dumps To Succeed Instantly in 1z0-1104-21 Exam
NEW QUESTION 29
Which storage type is most effective when you want to move some unstructured data, consisting of images and videos, to cloud storage?
- A. Standard storage
- B. Block volume
- C. File storage
- D. Archive storage
Answer: A
Explanation:
Use Oracle Cloud Infrastructure Object Storage for data to which you need fast, immediate, and frequent access. Data accessibility and performance justifies a higher price point to store data in the Object Storage tier.
The Object Storage service can store an unlimited amount of unstructured data of any content type, including analytic data and rich content, like images and videos.
https://docs.oracle.com/en/solutions/learn-migrate-app-data-to-cloud/considerations-object-storage.html#GUID-AC192B08-5160-4DA7-B43E-001753D99CF1
NEW QUESTION 30
An e-commerce company needs to authenticate with third-party API that don't support OCI's signature-based authentication.
What can be the solution for the above scenario?
- A. Security Token
- B. API Key Authentication
- C. Asymmetric keys
- D. Auth Token/Swift Password
Answer: D
Explanation:
NEW QUESTION 31
Which architecture is based on the principle of "never trust, always verify"?
- A. Defense in depth
- B. Zero trust
- C. Fluid perimeter
- D. Federated identity
Answer: B
Explanation:
Enterprise Interest in Zero Trust is Growing Ransomware and breaches are top of the news cycle and a major concern for organizations big and small. So, many are now looking at the Zero Trust architecture and its primary principle "never trust, always verify" to provide greater protection.
According to Report Linker, the Zero Trust security market is projected to grow from USD 15.6 billion in 2019 to USD 38.6 billion by 2024 and that sounds right based on the large number of companies pitching their Zero Trust wares at RSA 2020.
The enterprise was well represented at the conference and there was a tremendous amount of interest in Zero Trust. Interestingly, even though Zero Trust environments are often made up of several solutions from multiple vendors it hasn't prevented each of the vendors from evangelizing their flavors of Zero Trust. This left the thousands of attendees to attempt to cut through the Zero Trust buzz and noise and make their own conclusions to the best approach.
https://blogs.oracle.com/cloudsecurity/post/rsa-2020-recap-cloud-security-moves-to-the-front
NEW QUESTION 32
Which statement is true about using custom BYOI instances in Windows Servers that are managed by OS Management Service?
- A. Windows Servers that already has the minimum agent version requires an agent update or installation.
- B. Windows Servers that does not have the minimum agent version does not require an agent update or installation.
- C. Windows Servers that already has the minimum agent version does not require an agent update or installation.
- D. Windows Servers that does not have the minimum agent version requires an agent update or installation.
Answer: D
Explanation:
https://docs.oracle.com/cd/E11857_01/install.111/e15311/agnt_install_windows.htm
NEW QUESTION 33
Which challenge is generally the first level of bot mitigation, but not sufficient with more advanced bot tools?
- A. Human interaction challenge
- B. Device fingerprint challenge
- C. JavaScript challenge
- D. CAPTCHA challenge
Answer: C
NEW QUESTION 34
What would you use to make Oracle Cloud Infrastructure Identity and Access Management govern resources in a tenancy?
- A. Groups
- B. Policies
- C. Dynamic groups
- D. Users
Answer: B
Explanation:
POLICY
A document that specifies who can access which resources, and how. Access is granted at the group and compartment level, which means you can write a policy that gives a group a specific type of access within a specific compartment, or to the tenancy itself. If you give a group access to the tenancy, the group automatically gets the same type of access to all the compartments inside the tenancy. For more information, see Example Scenario and How Policies Work. The word "policy" is used by people in different ways: to mean an individual statement written in the policy language; to mean a collection of statements in a single, named "policy" document (which has an Oracle Cloud ID (OCID) assigned to it); and to mean the overall body of policies your organization uses to control access to resources.
https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/overview.htm
NEW QUESTION 35
On which option do you set Oracle Cloud Infrastructure Budget?
- A. Tenancy
- B. Compartments
- C. Instances
- D. Free-form tags
Answer: B
Explanation:
How Budgets Work
Budgets are set on cost-tracking tags or on compartments (including the root compartment) to track all spending in that cost-tracking tag or for that compartment and its children.
https://docs.oracle.com/en-us/iaas/Content/Billing/Concepts/budgetsoverview.htm
NEW QUESTION 36
Where is sensitive configuration data (like certificates, and credentials) is stored by Kubernetes cluster control plane?
- A. Block Volume
- B. Oracle Functions
- C. ETCD
- D. Boot Volume
Answer: C
Explanation:
NEW QUESTION 37
What does the following identity policy do?
Allow group my-group to use fn-invocation in compartment ABC where target.function.id = '<function-OCID>'
- A. Enables users to invoke all the functions in a specific application
- B. Enables users in a group to create, update, and delete ALL applications and functions in a compartment
- C. Enables users to invoke all the functions in a compartment except for one specific function
- D. Enables users to invoke just one specific function
Answer: D
NEW QUESTION 38
Which volume type contains the image used to boot a compute instance?
- A. Startup volume
- B. Block volume
- C. Init 6 volume
- D. Boot volume
Answer: D
Explanation:
Boot Volumes
When you launch a virtual machine (VM) or bare metal instance based on a platform image or custom image, a new boot volume for the instance is created in the same compartment. That boot volume is associated with that instance until you terminate the instance. When you terminate the instance, you can preserve the boot volume and its data
https://docs.oracle.com/en-us/iaas/Content/Block/Concepts/bootvolumes.htm
NEW QUESTION 39
Which Cloud Guard component identifies issues with resources or user actions and alerts you when an issue is found?
- A. Problems
- B. Responders
- C. Detectors
- D. Targets
Answer: C
Explanation:
Detector
Performs checks to identify potential security problems based on activities or configurations. Rules followed to identify problems are the same for all compartments in a target.
https://docs.oracle.com/en-us/iaas/cloud-guard/using/part-start.htm
NEW QUESTION 40
Operations team has made a mistake in updating the secret contents and immediately need to resume using older secret contents in OCI Secret Management within a Vault.
As a Security Administrator, what step should you perform to rollback to last version? Select TWO correct answers.
- A. Mark the secret version as 'deprecated'
- B. Mark the secret version as 'Rewind'
- C. Upload new secret and mark as 'Pending'. Promote this secret version as 'Current'
- D. Mark the secret version as 'Previous'
Answer: C,D
Explanation:
NEW QUESTION 41
As a security architect, how can you prevent unwanted bots while desirable bots are allowed to enter?
- A. Compartments
- B. Data Guard
- C. Web Application Firewall (WAF)
- D. Vault
Answer: C
NEW QUESTION 42
Which WAF service component must be configured to allow, block, or log network requests when they meet specified criteria?
- A. Origin
- B. Web Application Firewall policy
- C. Bot Management
- D. Protection rules
Answer: D
Explanation:
Protection rules
Protection rules can be configured to either allow, block, or log network requests when they meet the specified criteria of a protection rule. The WAF will observe traffic to your web application over time and suggest new rules to apply.
https://www.oracle.com/security/cloud-security/what-is-waf/
NEW QUESTION 43
Which IAM policy should be created to give XYZ the ability to list contents of a resource excluding the f needs to authenticate in prod compartment ? Principle of least priviledge should be used.
- A. Allow group XYZ to use all resources in compartment != prod
- B. Allow group XYZ to manage all resources in compartment != prod
- C. Allow group XYZ to inspect all resources in tenancy where target.compartment.name != prod
- D. Allow group XYZ to read all resources in tenancy where target.compartment.name != prod
Answer: C
Explanation:
NEW QUESTION 44
Which statement is not true about Cloud Security Posture?
- A. Problems are created when Cloud Guard discovers a deviation from a responder rule.
- B. Problems can be resolved, dismissed, or remediated.
- C. Problems contain data about the specific type of issue that was found.
- D. Problems are defined by the type of detector that creates them: activity or configuration.
Answer: A
Explanation:
https://www.oracle.com/security/cloud-security/what-is-cspm/
NEW QUESTION 45
As a solutions architect, you need to assist operations team to write an I AM policy to give users in group-uat1 and group- uat2 access to manage all resources in the compartment Uat. Which is the CORRECT IAM policy ?
- A. Allow group /group-uat*/ to manage all resources in compartment Uat
- B. Allow any-user to manage all resources in tenancy where target.compartment= Uat
- C. Allow group group-uat1 group-uat2 to manage all resources in compartment Uat
- D. Allow any-user to manage all resources in compartment Uat where request.group=/group-uat/*
Answer: C
NEW QUESTION 46
Which statement about Oracle Cloud Infrastructure Multi-Factor Authentication (MFA) is NOT valid?
- A. Users cannot disable MFA for themselves.
- B. Users must install a supported authenticator app on the mobile device they intend to register for MFA.
- C. An administrator can disable MFA for another user.
- D. A user can register only one device to use for MFA.
Answer: A
NEW QUESTION 47
A company has OCI tenancy which has mount target associated with two File Systems, CG_1 and CG_2. These File Systems are accessed by IP-based clients AB_1 and AB_2 respectively. As a security administrator, how can you provide access to both clients such that CGI has Read only access on AB1 and CG_2 has Read/Write access on AB_2?
- A. Access Control Lists
- B. NFS Export Option
- C. NFS v3 Unix Security
- D. Vault
Answer: B,C
Explanation:
NEW QUESTION 48
Which statement is true about Oracle Cloud Infrastructure (OCI) Object Storage server-side encryption?
- A. All the traffic to and from object storage is encrypted by using Transport Layer Security.
- B. Customer-provided encryption keys are never stored in OCI Vault service.
- C. Encryption is not enabled by default.
- D. Each object in a bucket is always encrypted with the same data encryption key.
Answer: A
NEW QUESTION 49
Bot Management in OCI provides which of the features? Select TWO correct answers.
- A. Good Bot Allowlist
- B. CAPTCHA Challenge
- C. Bad Bot Denylist
- D. IP Prefix Steering
Answer: A,B
Explanation:
NEW QUESTION 50
......
Oracle 1z0-1104-21 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
Oracle Dumps - Learn How To Deal With The Exam Anxiety: https://pass4sure.practicedump.com/1z0-1104-21-exam-questions.html