Pass 1z0-1104-23 Exam with Updated 1z0-1104-23 Exam Dumps PDF 2024
1z0-1104-23 Exam Dumps - Free Demo & 365 Day Updates
Oracle 1z0-1104-23 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION # 49
As a cloud network administrator, you have been tasked with defining ingress and egress access rules for microservices deployed as functions in Oracle Functions. In addition to defining some general access rules in the subnet's security list, you define more fine-grained rules for different functions using Oracle Cloud Infrastructure (OCI) Network Security Groups (NSGs). Once the NSGs are created, where should they be attached in order to apply to a specific deployed function? (Choose the best Answer.)
- A. The application hosting the function
- B. The function's docker container
- C. The pod hosting the application
- D. The function itself
Answer: A
NEW QUESTION # 50
You are using a custom application with third-party APIs to manage application and data hosted in an Oracle Cloud Infrastructure(OCI) tenancy. Although your third-party APIs don't support OCI's signature-based authentication, you want them to communicate with OCI resources. Which authentication option must you use to ensure this?
- A. Auth Token
- B. OCI username and Password
- C. API Signing Key
- D. SSH Key Pair with 2048-bit algorithm
Answer: A
Explanation:
An auth token in OCI is an Oracle-generated token that you can use to authenticate with third-party APIs78. This can be useful when the third-party APIs do not support OCI's signature-based authentication
NEW QUESTION # 51
You need to create matching rules for a conditional policy. Which TWO matching rules syntax can be used? (Choose two.)
- A. Key =| !='value'
- B. any/all {<condition>, <condition>,...}
- C. namespace =| !='value'
- D. variable =|!="value"
Answer: B,D
NEW QUESTION # 52
What information do youget by using the Network Visualizer tool?
- A. Routes defined between subnets and gateways
- B. Organization of subnets and VLANs across availability domains
- C. Interconnectivity of VCNs
- D. State of subnets in a VCN
Answer: C
Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/network_visualizer.htm You can view and understand the following from this diagram:
How VCNs are inter-connected
How on-premises networks are connected (using FastConnect or Site-to-Site VPN) Which routing entities (DRGs and so on) control trafficrouting How your transit routing is configured
NEW QUESTION # 53
Which statements are CORRECT about Multi-Factor Authentication in OCI ? Select TWO correct answers
- A. Users cannot enable MFA for themselves
- B. Members of the Administrators group can disable MFA for other users
- C. Members of the Administrators group cannot enable MFA for another user
- D. A user can registermultiple devices to use for MFA.
Answer: B,C
Explanation:

NEW QUESTION # 54
Which tasks can you perform on a dedicated virtual machine host?
- A. Instance configurations
- B. Manual scaling
- C. Capacity reservations
- D. Creating instance pools
Answer: B
Explanation:
Supported features: Most of the Compute features for VM instances are supported for instances running on dedicated virtual machine hosts. However, the following features arenot supported:
Autoscaling
Capacity reservations
Instance configurations
Instance pools
Burstable instances
Reboot migration. You can use manual migration instead
https://docs.oracle.com/en-us/iaas/Content/Compute/Concepts/dedicatedvmhosts.htm#Dedicated_Virtual_Machine_Hosts
NEW QUESTION # 55
Which statement about Oracle Cloud Infrastructure Multi-Factor Authentication (MFA)is NOT valid?
- A. Users cannot disable MFA for themselves.
- B. Users must install a supported authenticator app on the mobile device they intend to register for MFA.
- C. A user can register only one device to use for MFA.
- D. An administrator can disable MFA for another user.
Answer: A
Explanation:
Explanation
In Oracle Cloud Infrastructure, users can disable Multi-Factor Authentication (MFA) for themselves456. If a user loses their MFA device or wants to register a new one, they can disable MFA for their account and then set it up again with the new device
NEW QUESTION # 56
An automobile company needs to configure Bastion Managed SSH session to a compute instance in a private subnet. What are the TWO prerequisites to configure successfully?
- A. SSH port forwarding should be enabled
- B. Route rule to a NAT or Service Gateway should be associated with the subnet of the route table
- C. NAT or Service Gateway should be attached to the private subnet
- D. There is no need for any gateway in private subnet
Answer: B,C
Explanation:
Explanation
For a Bastion Managed SSH session to a compute instance in a private subnet, the instance must have access to the internet, which can be provided by a NAT Gateway or a Service Gateway34. Additionally, a route rule directing traffic to the NAT or Service Gateway should be associated with the subnet's route table34.
NEW QUESTION # 57
Which volume type contains the image used to boot a compute instance?
- A. Boot volume
- B. Startup volume
- C. Init 6 volume
- D. Block volume
Answer: A
Explanation:
Boot Volumes
When you launch a virtual machine (VM) or bare metal instance based on a platform image or custom image, a new boot volume for the instance is created in the same compartment. That boot volume is associated with that instanceuntil you terminate the instance. When you terminate the instance, you can preserve the boot volume and its data
https://docs.oracle.com/en-us/iaas/Content/Block/Concepts/bootvolumes.htm
NEW QUESTION # 58
Which storage type is most effective when you want to move some unstructured data, consisting of images and videos, to cloud storage?
- A. Archivestorage
- B. File storage
- C. Standard storage
- D. Block volume
Answer: C
Explanation:
Explanation
Use Oracle Cloud Infrastructure Object Storage for data to which you need fast, immediate, and frequent access. Data accessibility and performance justifies a higher price point to store data in the Object Storage tier.
The Object Storage service can store an unlimited amount of unstructured data of any content type, including analytic data and rich content, like images and videos.
https://docs.oracle.com/en/solutions/learn-migrate-app-data-to-cloud/considerations-object-storage.html#GUID-A
NEW QUESTION # 59
which three resources are required to encrypt a block volume with the customer managed key?
- A. IAM Policy Allowing Block Storage to Use Keys
- B. BLOCK KEY
- C. Secrets
- D. MAXIMUM SECURITY ZONE
- E. OCI VAIRT
- F. SYMMETRIC MASTER KEY ENCRYPTlON KEY
Answer: A,C,E
Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/SecurityAdvisor/Tasks/creatingsecureblockvolume.htm
NEW QUESTION # 60
As a security administrator, you found out that there are users outside your co network who are accessing OCI Object Storage Bucket. How can you prevent these users from accessing OCI resources in corporate network?
- A. Make OCI resources private instead of public
- B. Create an 1AM policy and create WAF rules
- C. Create PAR to restrict access the access
- D. Create an 1AM policy and add a network source
Answer: D
Explanation:
NEW QUESTION # 61
As a Security Admin you want to inspect the metadata and actual data in your Oracle databases to discover sensitive data and provide comprehensive results listing the sensitive columns and related information. Which Data Safe feature will help you to achieve the above requirement ?
- A. Data Discovery
- B. Security Assessment
- C. Data Masking
- D. User Assessment
Answer: A
Explanation:
NEW QUESTION # 62
What are the two items required to create a rule for the Oracle Cloud Infrastructure (OCI) Events Service? (Choose two.)
- A. Install key
- B. Actions
- C. Management Agent Cloud Service
- D. Rule Conditions
- E. Service Connector
Answer: B,D
NEW QUESTION # 63
Challenge 3 - Task 2 of 4
Set Up a Bastion Host to Access the Compute Instance in a Private Subnet Scenario A compute instance is provisioned in a private subnet that is not accessible through the Internet. To access the compute instance resource in a private subnet, you must provide a time-bound SSH session without deploying and maintaining a public subnet and a jump server, which eliminates the hassle and potential attack surface from remote access.
To complete this deployment, you have to perform the following tasks in the environment provisioned for you:
* Configure a Virtual Cloud Network (VCN) and a Private Subnet.
* Provision a Compute Instance in the private subnet and enable Bastion Plugin.
* Create a Bastion and Bastion session.
* Connect to a compute instance using Managed SSH session.
Note: You are provided with access to an OCI Tenancy, an assigned compartment, and OCI credentials. Throughout your exam, ensure to use the assigned Compartment 99233424-C01 and Region us-ashburn-1 Complete the following tasks in the provisioned OCI environment:
Create a Compute Instance with the name PBT-BAS-VM-01, using the "Oracle Linux 8" image and shape "VM.Standard2.1", without SSH key and enable Bastion plugin.
Answer:
Explanation:
See the solution below in Explanation
Explanation:
Solutions:
From the navigation menu, select Compute and then click Instances.
In the left navigation pane, select your working compartment under List Scope from the drop-down menu.
Click Create Instance. In the Create Instance dialogue box, provide the following details:
a. Name: PBT-BAS-VM-01
b. Placement: Select Availability Domain AD.
c. Image: Select the image Oracle Linux 8.
d. Shape: Click Change shape > Select Ampere shape series > Select VM.Standard2.1.
e. Click Select Shape to return to the Create compute instance window.
f. Networking: Pick your PBT-BAS-VCN-01 and Private Subnet.
g. Public IP address: Do not assign a Public IPv4 address.
h. Add SSH keys: Do not add any SSH key.
i. Note: Leave all the other options in their default setting.
j. Click Show Advanced Options.
On the Oracle Cloud Agent tab, select Bastion.
Click Create. (Click Yes, and create an instance on the "No SSH access" prompt) After a few minutes, you can see that the instance has been successfully created, and the state is Running.
Click the Oracle Cloud Agent tab on the instance details page.
Toggle the Enable Plugin switch to Enable for the Bastion plug-in, if the switch is disabled.
It can take 5-10 minutes for the change to take effect. After a few moments, the status of the Running for the Bastion-enabled service will be displayed.
NEW QUESTION # 64
Which statement about Oracle Cloud Infrastructure Multi-Factor Authentication (MFA)is NOT valid?
- A. Users cannot disable MFA for themselves.
- B. Users must install a supported authenticator app on the mobile device they intend to register for MFA.
- C. A user can register only one device to use for MFA.
- D. An administrator can disable MFA for another user.
Answer: A
Explanation:
In Oracle Cloud Infrastructure, users can disable Multi-Factor Authentication (MFA) for themselves456. If a user loses their MFA device or wants to register a new one, they can disable MFA for their account and then set it up again with the new device
NEW QUESTION # 65
As a solutions architect, you need to assist operations team to write an I AM policy to give users in group-uat1 and group- uat2 access to manage all resources in the compartment Uat. Which is the CORRECT IAM policy ?
- A. Allow group /group-uat*/ to manage all resources in compartment Uat
- B. Allow any-user to manage all resources in compartment Uat where request.group=/group-uat/*
- C. Allow any-user to manage all resources in tenancy where target.compartment= Uat
- D. Allow group group-uat1 group-uat2 tomanage all resources in compartment Uat
Answer: A
Explanation:
This policy allows users in groups whose names start with "group-uat" to manage all resources in the compartment named "Uat"12.
NEW QUESTION # 66
What do the features of OS Management Service do?
- A. Provide paid service and support to OCI subscribers for fixes on priority.
- B. Encourage manual setup to avoid machine-induced errors.
- C. Add complexity in using multiple tools tomanage mixed-OS environments.
- D. Increase security and reliability by regular bug fixes.
Answer: D
Explanation:
https://docs.oracle.com/en/solutions/oci-best-practices/manage-your-operating-systems1.html
NEW QUESTION # 67
As a security architect, how can you preventunwanted bots while desirable bots are allowed to enter?
- A. Compartments
- B. Web Application Firewall (WAF)
- C. Vault
- D. Data Guard
Answer: B
Explanation:
Explanation
The Web Application Firewall (WAF) in OCI provides you with the ability to create and manage rules for internet threats5. Unwanted bots can be mitigated while tactically allowing desirable bots to enter5. Access rules can be limited based on geography or the signature of the request5.
NEW QUESTION # 68
You create a new compartment, "apps," to host some production apps and you create an apps_group and added users to it.
What would you do to ensure the users have access to the apps compartment?
- A. Add an IAM policy for the individual users to access the apps compartment.
- B. No action is required.
- C. Add an lAM policy to attach tenancy to the apps group.
- D. Add an IAM policy for apps_group granting access to the apps compartment.
Answer: D
Explanation:
In Oracle Cloud Infrastructure, you can ensure that users have access to a specific compartment by adding an IAM policy for the group those users belong to, granting access to that compartment45.
NEW QUESTION # 69
Which statements are CORRECT about Multi-Factor Authentication in OCI ? Select TWO correct answers
- A. Users cannot enable MFA for themselves
- B. Members of the Administrators group can disable MFA for other users
- C. Members of the Administrators group cannot enable MFA for another user
- D. A user can registermultiple devices to use for MFA.
Answer: B,C
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
Graphical user interface, text, application Description automatically generated
NEW QUESTION # 70
Which statement is not true about Cloud Security Posture?
- A. Problems contain data about the specific type of issue that was found.
- B. Problems are defined by the type of detector that creates them: activity or configuration.
- C. Problems can be resolved, dismissed, or remediated.
- D. Problems are created when Cloud Guard discovers a deviation from a responder rule.
Answer: D
Explanation:
https://www.oracle.com/security/cloud-security/what-is-cspm/
NEW QUESTION # 71
Which component helps move logging data to other services, such as archiving log data in object storage?
- A. Unified Monitoring Agent
- B. Agent Configuration
- C. Service Log Category
- D. Service Connector Hub
Answer: D
Explanation:
Service Connector Hub
Service Connector Hub moves logging data to other services in Oracle Cloud Infrastructure. For example, use Service Connector Hub to alarm on log data, send log data to databases, and archive log data to Object Storage. For more information, see Service Connector Hub.
https://docs.oracle.com/en-us/iaas/Content/Logging/Concepts/loggingoverview.htm
NEW QUESTION # 72
Which is NOT a part of Observability and Management Services?
- A. Logging
- B. Logging Analytics
- C. OCI Management Service
- D. Event Services
Answer: C
Explanation:
https://www.oracle.com/in/manageability/
NEW QUESTION # 73
Which VCNconfiguration is CORRECT with regard to VCN peering within a same region ?
- A. 12.0.0.0/16 and 194.168.0.0/16
- B. 194.168.0.0/24 and 194.168.0.0/16
- C. 12.0.0.0/16 and 12.0.0.0/16C 194.168.0.0/24 and 194.168.0.0/24
Answer: A
Explanation:
When setting up VCN peering within the same region, the VCNs must have non-overlapping CIDRs12. In this case, the CIDR blocks 12.0.0.0/16 and 194.168.0.0/16 are different and do not overlap, making them suitable for VCN peering
NEW QUESTION # 74
......
1z0-1104-23 Dumps - Pass Your Certification Exam: https://www.testkingpass.com/1z0-1104-23-testking-dumps.html
Free Sales Ending Soon - Use Real 1z0-1104-23 PDF Questions: https://drive.google.com/open?id=1hBWMz7VpdoowHCsq_p7wWHNm-DeBvrdD