Authentic 1z0-1104-21 Dumps With 100% Passing Rate Practice Tests Dumps
Oracle 1z0-1104-21 Real Exam Questions Guaranteed Updated Dump from VCE4Plus
NEW QUESTION 31
You have configured the Management Agent on an Oracle Cloud Infrastructure (OCI) Linux instance for log ingestion purposes.
Which is a required configuration for OCI Logging Analytics service to collect data from multiple logs of this Instance?
- A. Entity - Log Association
- B. Source - Entity Association
- C. Log - Log Group Association
- D. Log Group - Source Association
Answer: B
NEW QUESTION 32
Which resources can be used to create and manage from Vault Service ? Select TWO correct answers
- A. IAM
- B. Secret
- C. Cloud Guard
- D. Keys
Answer: B,D
Explanation:
NEW QUESTION 33
what is the use case for Oracle cloud infrastructure logging analytics service?
- A. monitors, aggregates, indexes and analyzes all log data from on-premises.
- B. labels data packets that pass through the internet gateway
- C. automatically create instances to collect logs analysis and send reports
- D. automatically and manage any log based on a subscription model
Answer: A
Explanation:
Oracle Cloud Infrastructure Logging Analytics is a machine learning-based cloud service that monitors, aggregates, indexes, and analyzes all log data from on-premises and multicloud environments. Enabling users to search, explore, and correlate this data to troubleshoot and resolve problems faster and derive insights to make better operational decisions.
https://www.oracle.com/manageability/logging-analytics/
NEW QUESTION 34
Which is NOT a compliance document?
- A. Penetration test report
- B. Certificate
- C. Attestation
- D. Bridge letter
Answer: A
Explanation:
Types of Compliance Documents
When viewing compliance documents, you can filter on the following types:
Attestation. A Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of Compliance document.
Audit. A general audit report.
Bridge Letter (BridgeLetter). A bridge letter. Bridge letters provide compliance information for the period of time between the end date of an SOC report and the date of the release of a new SOC report.
Certificate. A document indicating certification by a particular authority, with regard to certification requirements and examination results conforming to said requirements.
SOC3. A Service Organization Controls 3 audit report that provides information relating to a service organization's internal controls for security, availability, confidentiality, and privacy.
Other. A compliance document that doesn't fit into any of the preceding, more specific categories.
https://docs.oracle.com/en-us/iaas/Content/ComplianceDocuments/Concepts/compliancedocsoverview.htm
NEW QUESTION 35
Which IAM policy should be created to give XYZ the ability to list contents of a resource excluding the f needs to authenticate in prod compartment ? Principle of least priviledge should be used.
- A. Allow group XYZ to inspect all resources in tenancy where target.compartment.name != prod
- B. Allow group XYZ to manage all resources in compartment != prod
- C. Allow group XYZ to read all resources in tenancy where target.compartment.name != prod
- D. Allow group XYZ to use all resources in compartment != prod
Answer: A
Explanation:
NEW QUESTION 36
As a Security Admin you want to inspect the metadata and actual data in your Oracle databases to discover sensitive data and provide comprehensive results listing the sensitive columns and related information. Which Data Safe feature will help you to achieve the above requirement ?
- A. User Assessment
- B. Security Assessment
- C. Data Discovery
- D. Data Masking
Answer: C
Explanation:
NEW QUESTION 37
you are part of security operation of an organization with thousand of your users accessing Oracle cloud infrastructure it was reported that an unknown user action was executed resulting in configuration error you are tasked to quickly identify the details of all users who were active in the last six hours also with any rest API call that were executed. Which oci feature should you use?
- A. audit analysis dashboard
- B. objectcollectionrule
- C. management agent log integration
- D. service connector hub
Answer: D
NEW QUESTION 38
Which is NOT a part of Observability and Management Services?
- A. Logging Analytics
- B. OCI Management Service
- C. Logging
- D. Event Services
Answer: B
Explanation:
https://www.oracle.com/in/manageability/
NEW QUESTION 39
As a solutions architect, you need to assist operations team to write an I AM policy to give users in group-uat1 and group- uat2 access to manage all resources in the compartment Uat. Which is the CORRECT IAM policy ?
- A. Allow any-user to manage all resources in compartment Uat where request.group=/group-uat/*
- B. Allow any-user to manage all resources in tenancy where target.compartment= Uat
- C. Allow group group-uat1 group-uat2 to manage all resources in compartment Uat
- D. Allow group /group-uat*/ to manage all resources in compartment Uat
Answer: C
NEW QUESTION 40
Where are logs stored?
- A. OCI File Storage
- B. OCI Object Storage
- C. OCI Block Storage
- D. Cloud Agent
Answer: B
Explanation:
You can collect log data continuously from Oracle Cloud Infrastructure (OCI) Object Storage. To enable the log collection, create ObjectCollectionRule resource using REST API or CLI. After the successful creation of this resource and having the required IAM policies, the log collection will be initiated.
https://docs.oracle.com/en-us/iaas/logging-analytics/doc/collect-logs-your-oci-object-storage-bucket.html
NEW QUESTION 41
As a lead Security Architect, you have tasked to restrict access to and from the worker nodes in pods running in Oracle Container Engine for Kubernetes?
- A. Security Lists
- B. Identity and Access Management
- C. Cloud Guard
- D. Vulnerability Scanning
Answer: A
Explanation:
NEW QUESTION 42
What is the configuration to avoid publishing messages during the specified time range known as?
- A. Statistic
- B. Resource group
- C. Trigger rule
- D. Suppression
Answer: D
Explanation:
NEW QUESTION 43
Which security issues can be identified by Oracle Vulnerability Scanning Service? Select TWO correct answers
- A. CIS published Industry-standard benchmarks
- B. Distributed Denial of Service (DDoS)
- C. SQL Injection
- D. Ports that are unintentionally left open can be a potential attack vector for cloud resources
Answer: A,D
Explanation:
NEW QUESTION 44
You are using a custom application with third-party APIs to manage application and data hosted in an Oracle Cloud Infrastructure (OCI) tenancy. Although your third-party APIs don't support OCI's signature-based authentication, you want them to communicate with OCI resources. Which authentication option must you use to ensure this?
- A. API Signing Key
- B. SSH Key Pair with 2048-bit algorithm
- C. OCI username and Password
- D. Auth Token
Answer: D
NEW QUESTION 45
You want to make API calls against other OCI services from your instance without configuring user credentials. How would you achieve this?
- A. No configuration is required for making API calls.
- B. Create a dynamic group and add a policy.
- C. Create a group and add a policy.
- D. Create a dynamic group and add your instance.
Answer: B
Explanation:
DYNAMIC GROUP
Dynamic groups allow you to group Oracle Cloud Infrastructure instances as principal actors, similar to user groups. You can then create policies to permit instances in these groups to make API calls against Oracle Cloud Infrastructure services. Membership in the group is determined by a set of criteria you define, called matching rules. https://docs.cloud.oracle.com/en-us/iaas/Content/Identity/Tasks/callingservicesfrominstances.htm
NEW QUESTION 46
As a security administrator, you want to create cloud resources that align with Oracle's security principles and best practices. Which security service should you use?
- A. Identity and Access Management
- B. Security Advisor
- C. Web Application Firewall (WAF)
- D. Cloud Guard
Answer: B
Explanation:
NEW QUESTION 47
Which of these protects customer data at rest and in transit in a way that allows customers to meet their security and compliance requirements for cryptographic algorithms and key management?
- A. Customer isolation
- B. Identity Federation
- C. Data encryption
- D. Security controls
Answer: C
Explanation:
DATA ENCRYPTION
Protect customer data at-rest and in-transit in a way that allows customers to meet their security and compliance requirements for cryptographic algorithms and key management.
https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_overview.htm
NEW QUESTION 48
An automobile company needs to configure Bastion Managed SSH session to a compute instance in a private subnet. What are the TWO prerequisites to configure successfully?
- A. There is no need for any gateway in private subnet
- B. NAT or Service Gateway should be attached to the private subnet
- C. SSH port forwarding should be enabled
- D. Route rule to a NAT or Service Gateway should be associated with the subnet of the route table
Answer: B,D
NEW QUESTION 49
......
Verified Pass 1z0-1104-21 Exam in First Attempt Guaranteed: https://www.vce4plus.com/Oracle/1z0-1104-21-valid-vce-dumps.html