Oracle 1z0-1104-23 Practice Test Pdf Exam Material
1z0-1104-23 Answers 1z0-1104-23 Free Demo Are Based On The Real Exam
NEW QUESTION # 30
Which type of firewalls are designed to protect against web application attacks, such as SQL injection and cross-site scripting?
- A. Incident firewall
- B. Web Application Firewall
- C. Stateful inspection firewall
- D. Packet filtering firewall
Answer: B
Explanation:
Explanation
SQL injections. Cross-site scripting. Distributed denial of service(DDoS) attacks. Botnets. These are just some of the cyber-weapons increasingly being used by malicious actors to target web applications, cause data breaches, and expose sensitive business information.
Oracle WAF uses a multilayered approach to protect web applications from a host of cyberthreats including malicious bots, application layer (L7) DDoS attacks, cross-site scripting, SQL injection, and vulnerabilities defined by the Open Web Application Security Project (OWASP). When a threat is identified, Oracle WAF automatically blocks it and alerts security operations teams so they can investigate further.
https://www.oracle.com/a/ocom/docs/security/oci-web-application-firewall.pdf
NEW QUESTION # 31
Which tasks can you perform on a dedicated virtual machine host?
- A. Instance configurations
- B. Manual scaling
- C. Creating instance pools
- D. Capacity reservations
Answer: B
Explanation:
Explanation
Supported features: Most of the Compute features for VM instances are supported for instances running on dedicated virtual machine hosts. However, the following features arenot supported:
Autoscaling
Capacity reservations
Instance configurations
Instance pools
Burstable instances
Reboot migration. You can use manual migration instead
https://docs.oracle.com/en-us/iaas/Content/Compute/Concepts/dedicatedvmhosts.htm#Dedicated_Virtual_Machi
NEW QUESTION # 32
As a security architect, how can you preventunwanted bots while desirable bots are allowed to enter?
- A. Web Application Firewall (WAF)
- B. Compartments
- C. Data Guard
- D. Vault
Answer: A
Explanation:
Explanation
The Web Application Firewall (WAF) in OCI provides you with the ability to create and manage rules for internet threats5. Unwanted bots can be mitigated while tactically allowing desirable bots to enter5. Access rules can be limited based on geography or the signature of the request5.
NEW QUESTION # 33
Which IAM policy should be created to give XYZ the ability to list contents of a resource excluding the fneeds to authenticatein prod compartment ? Principle of least priviledge should be used.
- A. Allow group XYZ to inspect all resources in tenancy where target.compartment.name != prod
- B. Allow group XYZ to manage all resources in compartment != prod
- C. Allow group XYZ to use all resources in compartment != prod
- D. Allow group XYZ to read all resources in tenancy where target.compartment.name != prod
Answer: A
Explanation:
Explanation
Graphical user interface, text, application Description automatically generated
NEW QUESTION # 34
Which architecture is based on the principle of "never trust, always verify"?
- A. Fluidperimeter
- B. Zero trust
- C. Federated identity
- D. Defense in depth
Answer: B
Explanation:
Explanation
Enterprise Interest in Zero Trust is GrowingRansomware and breaches are top of the news cycle and a major concern for organizations big and small. So, many are now looking at the Zero Trust architecture and its primary principle "never trust, always verify" to provide greater protection.
According to Report Linker, the Zero Trust security market is projected to grow from USD 15.6 billion in
2019 to USD 38.6 billion by 2024 and that sounds right based on the large number of companies pitching their Zero Trustwares at RSA 2020.
The enterprise was well represented at the conference and there was a tremendous amount of interest in Zero Trust. Interestingly, even though Zero Trust environments are often made up of several solutions from multiple vendors it hasn'tprevented each of the vendors from evangelizing their flavors of Zero Trust. This left the thousands of attendees to attempt to cut through the Zero Trust buzz and noise and make their own conclusions to the best approach.
https://blogs.oracle.com/cloudsecurity/post/rsa-2020-recap-cloud-security-moves-to-the-front
NEW QUESTION # 35
With regard to WAF in OCI, which of the following statements are NOT customer's responsibility? Select TWO answers.
- A. WAF edge nodes with High Availability
- B. Configure Bot Managementstrategies for a website traffic
- C. Import latest OWASP Core Rule Sets
- D. Configure WAF policies for websites
Answer: A,C
Explanation:
Explanation
The management of WAF edge nodes and the importation of the latest OWASP Core Rule Sets are handled by Oracle, not the customer. The customer is responsible for configuring WAF policies and Bot Management strategies for their website traffic
NEW QUESTION # 36
A company has OCI tenancy which has mount target associated with two File Systems, CG_1 and CG_2.
These FileSystems are accessed by IP-based clients AB_1 and AB_2 respectively. As a security administrator, how can you provide access to both clients such that CGI has Read only access on AB1 and CG_2 has Read/Write access on AB_2?
- A. NFS v3 Unix Security
- B. Access Control Lists
- C. Vault
- D. NFS Export Option
Answer: A,D
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
NEW QUESTION # 37
which two responsibilities will be oracle when you move your it infrastructure to oracle cloud infrastructure?
- A. Strong IAM Framework
- B. Strong Isolation
- C. MAINTAINING CUSTOMER DATA
- D. PROVIDING STRONG SECURITY LIST
- E. ACCOUNT ACCESS MANAGEMENT
Answer: A,B
Explanation:
Oracle is responsible for providing a strong Identity and Access Management (IAM) framework in OCI.
The IAM service lets you control who has access to your cloud resources, what type of access they have, and to which specific resources. You can find more details about this in the Oracle Cloud Infrastructure documentation.
Oracle also ensures strong isolation in its cloud infrastructure, which means that your resources are isolated from other tenants and from Oracle staff. This isolation extends from physical separation of hardware all the way up to access controls on APIs. You can find more details about this in the Oracle Cloud Infrastructure documentation.
NEW QUESTION # 38
Which OCI cloud service lets you centrally manage the encryption keys thatprotect your data and the secret credentials that you use to securely access resources?
- A. Vault
- B. Cloud Guard
- C. Data Guard
- D. Data Safe
Answer: A
Explanation:
Explanation
Oracle Cloud Infrastructure Vault is a managed service that lets you centrally manage the encryption keysthat protect your data and the secret credentials that you use to securely access resources. Vaults securely store master encryption keys and secrets that you might otherwise store in configuration files or in code.
Specifically, depending on the protection mode, keys are either stored on the server or they are stored on highly available and durable hardware security modules (HSM) that meet Federal Information Processing Standards (FIPS) 140-2 Security Level 3 security certification.
https://docs.oracle.com/en-us/iaas/Content/KeyManagement/Concepts/keyoverview.htm
NEW QUESTION # 39
What do the features of OS Management Service do?
- A. Provide paid service and support to OCI subscribers for fixes on priority.
- B. Increase security and reliability by regular bug fixes.
- C. Encourage manual setup to avoid machine-induced errors.
- D. Add complexity in using multiple tools tomanage mixed-OS environments.
Answer: B
Explanation:
Explanation
https://docs.oracle.com/en/solutions/oci-best-practices/manage-your-operating-systems1.html
NEW QUESTION # 40
As a security administrator, you want to create cloud resources that alignwith Oracle's security principles and best practices. Which security service should you use?
- A. Cloud Guard
- B. Security Advisor
- C. Web Application Firewall (WAF)
- D. Identity and Access Management
Answer: B
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
NEW QUESTION # 41
With regard to vulnerability and cloud penetration testing, which rules of engagement apply? Select TWO correct answers.
- A. Physical penetration and vulnerability testing of Oraclefacilities is prohibited
- B. Any port scanning must be performed in an aggressive mode
- C. Testing should target any other subscription or any other Oracle Cloud customer resources
- D. You are responsible for any damages to Oracle Cloud customers that are caused by your testing activities
Answer: A,D
Explanation:
Explanation
Graphical user interface, text, application Description automatically generated
NEW QUESTION # 42
You have configured the Management Agent on an Oracle Cloud Infrastructure (OCI) Linux instance for log ingestion purposes.
Which is a required configuration for OCI Logging Analytics service to collect data from multiple logs of this Instance?
- A. Source - Entity Association
- B. Log Group - Source Association
- C. Entity - Log Association
- D. Log - Log Group Association
Answer: A
Explanation:
For OCI Logging Analytics service to collect data from multiple logs of an instance, a Source - Entity Association is required1. A source in Logging Analytics defines the metadata about the log data you want to collect, and an entity represents the source of the log data1. You associate sources with entities, and these associations instruct the Management Agent on your instance what log data to collect1.
NEW QUESTION # 43
You subscribe to a PaaS service that follows the Shared Responsibility model.
Which type of security is your responsibility?
- A. Guest OS
- B. Network
- C. Infrastructure
- D. Data
Answer: D
Explanation:
Explanation
https://www.oracle.com/a/ocom/docs/cloud/oracle-ctr-2020-shared-responsibility.pdf
NEW QUESTION # 44
Oracle Object Storage achieves data durability by which of the mechanisms ? Select TWO correct answers
- A. Redundant Storage across availability domains
- B. Service Gateway
- C. Redundant Array of IndependentDisks
- D. Object Versioning
Answer: A,D
Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated
NEW QUESTION # 45
You are using a custom application with third-party APIs to manage application and data hosted in an Oracle Cloud Infrastructure(OCI) tenancy. Although your third-party APIs don't support OCI's signature-based authentication, you want them to communicate with OCI resources. Which authentication option must you use to ensure this?
- A. OCI username and Password
- B. API Signing Key
- C. Auth Token
- D. SSH Key Pair with 2048-bit algorithm
Answer: C
Explanation:
Explanation
An auth token in OCI is an Oracle-generated token that you can use to authenticate with third-party APIs78. This can be useful when the third-party APIs do not support OCI's signature-based authentication
NEW QUESTION # 46
What information do youget by using the Network Visualizer tool?
- A. Interconnectivity of VCNs
- B. State of subnets in a VCN
- C. Organization of subnets and VLANs across availability domains
- D. Routes defined between subnets and gateways
Answer: A
Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/network_visualizer.htm You can view and understand the following from this diagram:
How VCNs are inter-connected
How on-premises networks are connected (using FastConnect or Site-to-Site VPN) Which routing entities (DRGs and so on) control trafficrouting How your transit routing is configured
NEW QUESTION # 47
which three resources are required to encrypt a block volume with the customer managed key?
- A. SYMMETRIC MASTER KEY ENCRYPTlON KEY
- B. MAXIMUM SECURITY ZONE
- C. Secrets
- D. OCI VAIRT
- E. IAM Policy Allowing Block Storage to Use Keys
- F. BLOCK KEY
Answer: C,D,E
Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/SecurityAdvisor/Tasks/creatingsecureblockvolume.htm
NEW QUESTION # 48
......
1z0-1104-23 [Oct-2023] Newly Released] Exam Questions For You To Pass: https://www.examdumpsvce.com/1z0-1104-23-valid-exam-dumps.html
Oracle 1z0-1104-23 Exam: Basic Questions With Answers: https://drive.google.com/open?id=1S5jVEf2E-wV-kV87aU4ZKMUYg5vZJbRv
