[Jun 10, 2024] Fully Updated Oracle Cloud (1z0-1104-23) Certification Sample Questions
Latest Oracle 1z0-1104-23 Real Exam Dumps PDF
Oracle 1z0-1104-23 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION # 12
An automobile company needs to configure Bastion Managed SSH session to a compute instance in a private subnet. What are the TWO prerequisites to configure successfully?
- A. There is no need for any gateway in private subnet
- B. Route rule to a NAT or Service Gateway should be associated with the subnet of the route table
- C. SSH port forwarding should be enabled
- D. NAT or Service Gateway should be attached to the private subnet
Answer: B,D
Explanation:
For a Bastion Managed SSH session to a compute instance in a private subnet, the instance must have access to the internet, which can be provided by a NAT Gateway or a Service Gateway34. Additionally, a route rule directing traffic to the NAT or Service Gateway should be associated with the subnet's route table34.
NEW QUESTION # 13
You have configured Management Agent on an Oracle Cloud Infrastructure (OCI) Linux instance for log Ingestion purposes. OR When using Management Agent to collect logs continuously. Which is required configuration for OCI Logging Analytics service to collect data from multiple logs of this Instance? (Choose the best Answer.)
- A. Log Group-Source Association
- B. Source-Entity Association
- C. Log-Log Group Association
- D. Entity Log Association
Answer: B
NEW QUESTION # 14
A company needs to have somebuckets as public in the compartment. You want Cloud Guard to ignore the problem associated with public bucket. Select TWO correct answers
- A. Make the bucket private so that Cloud Guard won't detectit
- B. First make the bucket private and after few days make the bucket public again
- C. Configure Conditional groups for the detector to fix base line
- D. Dismiss the issues associated with these resources
Answer: C,D
Explanation:
Dismissing the issues associated with these resources in Cloud Guard will prevent these issues from being flagged again. This is because Cloud Guard allows you to dismiss problems that you don't want to address, and once dismissed, Cloud Guard does not raise the problem again unless there is a change in the resource that is associated with the problem. You can find more details about this in the Oracle Cloud Infrastructure documentation.
Configuring Conditional groups for the detector to fix base line will allow Cloud Guard to understand what is normal for your infrastructure and not flag these public buckets as issues. Conditional groups in Cloud Guard allow you to modify how detectors evaluate resources by specifying conditions that a resource must meet for a detector to evaluate it. You can find more details about this in the Oracle Cloud Infrastructure documentation
NEW QUESTION # 15
In which two ways can you improve data durability in Oracle Cloud Infrastructure Object Storage?
- A. Setup volumes in a RAID1 configuration
- B. Enable Versioning
- C. Enable server-sideencryption
- D. Limit delete permissions
- E. Enable client-side encryption
Answer: B,D
Explanation:
Enabling versioning can improve data durability in OCI Object Storage by keeping multiple versions of an object in the same bucket5.
Limiting delete permissions can also improve data durability by preventing unauthorized users from deleting data
NEW QUESTION # 16
Which type of software do you use to centrally distributeand monitor the patch level of systems throughout the enterprise?
- A. Web Application Firewall
- B. Recovery Manager software
- C. Patch Management software
- D. Network Monitor software
Answer: C
Explanation:
https://docs.oracle.com/cd/E11857_01/em.111/e18710/T531901T535649.htm
NEW QUESTION # 17
Which Oracle Data Safe feature minimizes the amount of personal data and allows internal test, development, and analytics teams to operate with reduced risk?
- A. security assessment
- B. data auditing
- C. data discovery
- D. data encryption
- E. data masking
Answer: E
Explanation:
Data masking in Oracle Data Safe minimizes the amount of personal data and allows internal test, development, and analytics teams to operate with reduced risk91011. It replaces sensitive or confidential information in non-production databases with realistic and fully functional data with similar characteristics as the original data
NEW QUESTION # 18
An automobile company needs to configure Bastion Managed SSH session to a compute instance in a private subnet. What are the TWO prerequisites to configure successfully?
- A. There is no need for any gateway in private subnet
- B. Route rule to a NAT or Service Gateway should be associated with the subnet of the route table
- C. SSH port forwarding should be enabled
- D. NAT or Service Gateway should be attached to the private subnet
Answer: B,D
Explanation:
Explanation
For a Bastion Managed SSH session to a compute instance in a private subnet, the instance must have access to the internet, which can be provided by a NAT Gateway or a Service Gateway34. Additionally, a route rule directing traffic to the NAT or Service Gateway should be associated with the subnet's route table34.
NEW QUESTION # 19
You want software that can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm.
Which software must you use?
- A. SecurityEvent Management (SEM)
- B. Security Integration Management (SIM)
- C. Security Information and Event Management (SIEM)
- D. Security Information Management (SIM)
Answer: C
Explanation:
Explanation
SIEM software can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm23.
NEW QUESTION # 20
Which OCI service canindex, enrich, aggregate, explore, search, analyze, correlate, visualize and monitor data?
- A. Data Guard
- B. WAF
- C. Logging Analytics
- D. Data Safe
Answer: C
Explanation:
Explanation
NEW QUESTION # 21
For how long are API calls audited and available?
- A. 30days
- B. 365 days
- C. 90 days
- D. 60 days
Answer: B
Explanation:
Explanation
https://docs.public.oneportal.content.oci.oraclecloud.com/en-us/iaas/Content/Audit/Tasks/settingretentionperiod.
NEW QUESTION # 22
Which type of firewalls are designed to protect against web application attacks, such as SQL injection and cross-site scripting?
- A. Stateful inspection firewall
- B. Web Application Firewall
- C. Incident firewall
- D. Packet filtering firewall
Answer: B
Explanation:
Explanation
SQL injections. Cross-site scripting. Distributed denial of service(DDoS) attacks. Botnets. These are just some of the cyber-weapons increasingly being used by malicious actors to target web applications, cause data breaches, and expose sensitive business information.
Oracle WAF uses a multilayered approach to protect web applications from a host of cyberthreats including malicious bots, application layer (L7) DDoS attacks, cross-site scripting, SQL injection, and vulnerabilities defined by the Open Web Application Security Project (OWASP). When a threat is identified, Oracle WAF automatically blocks it and alerts security operations teams so they can investigate further.
https://www.oracle.com/a/ocom/docs/security/oci-web-application-firewall.pdf
NEW QUESTION # 23
How do you enable server-side encryption in an Oracle Cloud Infrastructure (OCI) Object Storage bucket? (Choose the best Answer.)
- A. By updating the buckets metadata value for encrypted_bucket to "true"
- B. By default, server-side encryption is enabled and requires no user action.
- C. By uploading your encryption key to OCI Vault and associating it with the bucket you want to encrypt.
- D. By uploading encrypted objects will enable the encryption in the objects.
Answer: B
NEW QUESTION # 24
You want software that can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm.
Which software must you use?
- A. SecurityEvent Management (SEM)
- B. Security Integration Management (SIM)
- C. Security Information and Event Management (SIEM)
- D. Security Information Management (SIM)
Answer: C
Explanation:
SIEM software can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm23.
NEW QUESTION # 25
As a security architect, how can you preventunwanted bots while desirable bots are allowed to enter?
- A. Data Guard
- B. Web Application Firewall (WAF)
- C. Vault
- D. Compartments
Answer: B
Explanation:
The Web Application Firewall (WAF) in OCI provides you with the ability to create and manage rules for internet threats5. Unwanted bots can be mitigated while tactically allowing desirable bots to enter5. Access rules can be limited based on geography or the signature of the request5.
NEW QUESTION # 26
Which of these protects customer data at rest and in transit in a way that allows customers to meet their security and compliance requirements forcryptographic algorithms and key management?
- A. Identity Federation
- B. Security controls
- C. Data encryption
- D. Customer isolation
Answer: C
Explanation:
Explanation
DATA ENCRYPTION
Protect customer data at-rest and in-transit in a way that allows customers to meet their security and compliance requirements for cryptographic algorithms and key management.
https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm
NEW QUESTION # 27
......
Oracle 1z0-1104-23 Dumps - Secret To Pass in First Attempt: https://www.vceengine.com/1z0-1104-23-vce-test-engine.html
1z0-1104-23 Practice Test Questions Updated 172 Questions: https://drive.google.com/open?id=1oyIlEA5VThe848pZ6QFcQL22Rw5Ch08l
