1z0-1104-23 Dumps Special Discount for limited time Try FOR FREE [Q91-Q108]

Share

1z0-1104-23 Dumps Special Discount for limited time Try FOR FREE

1z0-1104-23 Dumps for success in Actual Exam Apr-2024]


Oracle 1z0-1104-23 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Create and configure Web Application Firewall
  • Implement security monitoring and alerting
Topic 2
  • Configure, deploy and maintain OCI Certificates
  • Implement Network, Platform, and Infrastructure Security
Topic 3
  • Utilize OS Management to manage and monitor updates
  • Understand and implement Security Zones and Security Advisor
Topic 4
  • Configure and secure load balancers to ensure high availability
  • Design a scalable authorization model with users, groups, and policies
Topic 5
  • Use threat intelligence to identify rogue users
  • Configure security for OCI storage services
Topic 6
  • Describe key capabilities provided by Data Safe
  • Describe the use case for auditing and review OCI Audit Logs
Topic 7
  • Discuss core security services offered by OCI
  • Configure security for Oracle Autonomous Database and DB Systems
Topic 8
  • Implement conditional and advanced policies
  • Configure Dynamic Groups, Network Sources, and Tag-Based Access Control

 

NEW QUESTION # 91
Which two reasons would a crytpo admin have to select the Virtual Private Vault option when creating an Oracle Cloud Infrastructure Vault? (Choose two.)

  • A. to scale to over 10,000 keys
  • B. ability to back up and restore the Vault for redundancy.
  • C. ability to export keys from the vault
  • D. more isolation for encryption keys with a dedicated HSM partition
  • E. banking requirements, including chip card reloading and PIN Processing

Answer: B,D


NEW QUESTION # 92
Which resources can be used to create and manage from Vault Service ? Select TWO correct answers

  • A. Keys
  • B. Cloud Guard
  • C. IAM
  • D. Secret

Answer: A,D

Explanation:


NEW QUESTION # 93
A company, ABC, is planning to launch a new web application on OCI. Based on past experiences, they expect a significant surge in traffic after the launch. You are responsible for ensuring that the application is highly available. Which step would you perform to achieve this goal? (Choose the best Answer.)

  • A. Use a Virtual Cloud Network (VCN) with subnets, security lists, and routing rules to isolate the web application from the Internet and other resources.
  • B. Implement security controls, such as web application firewalls, to protect against com-mon attack vectors.
  • C. Configure Cloud Guard to prevent large amounts of traffic from reaching the web application.
  • D. Use a load balancer to distribute incoming traffic evenly across multiple instances of the web application.

Answer: D


NEW QUESTION # 94
Which is true regarding importing a symmetric key into Vault (Bring your own key)? (Choose the best Answer.)

  • A. The user must use the Command Line Interface (CLI) for importing the key into the Vault.
  • B. The user performing the import must have the 'import' permission via an IAM Policy.
  • C. The key must be 1024 bits.
  • D. The key must be wrapped using a RSA asymmetric key provided by the Vault.

Answer: B


NEW QUESTION # 95
Which parameters customers need to configure while reading secrets by name using CL1 or API? Select TWO correct answers.

  • A. Vault Id
  • B. Secret Name
  • C. ASCII Value
  • D. Certificates

Answer: A,B

Explanation:
Explanation
Graphical user interface, text, application, email Description automatically generated


NEW QUESTION # 96
What are the security recommendations and best practices for Oracle Functions?

  • A. Grant privileges to UID and GID 1000, such that the functions running within a container acquire the default rootcapabilities.
  • B. Add applications to network security groups for fine-grained ingress/egress rules.
  • C. Define a policy statement that enables access to functions for requests coming from multiple IP addresses.
  • D. Ensure that functions in a VCN have restricted access to resources and services.

Answer: B

Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/securitylists.htm


NEW QUESTION # 97
Where are logs stored?

  • A. OCI Block Storage
  • B. OCI Object Storage
  • C. OCI File Storage
  • D. Cloud Agent

Answer: B

Explanation:
Explanation
You can collect log data continuously from Oracle CloudInfrastructure (OCI) Object Storage. To enable the log collection, create ObjectCollectionRule resource using REST API or CLI. After the successful creation of this resource and having the required IAM policies, the log collection will be initiated.
https://docs.oracle.com/en-us/iaas/logging-analytics/doc/collect-logs-your-oci-object-storage-bucket.html


NEW QUESTION # 98
A http web server hosted on an Oracle cloud infrastructure compute instance in a public subnet of the vcsl virtual cloudnetwork has a stateless security ingress rule for port 80 access through internet gateway stateful network security group notification for port 80 how will the Oci vcn handle request response traffic to the compute instance for a web page from the http server with port 80?

  • A. network security group would supersede the security utility list and allow both inbound and outbound traffic
  • B. the union of both configuration would happen and allow both inbound and outbound traffic
  • C. due to the conflict in security configuration inbound request traffic would not be allowed
  • D. Because there is no Egress ruled defined in Security List, The Response would not pass through Internet Gateway.

Answer: B

Explanation:
In OCI, if there's a stateless rule in the security list and a stateful rule in the network security group, both rules are evaluated. The union of both configurations would happen, allowing both inbound and outbound traffic. This means that if an incoming packet is allowed by either the security lists or the network security groups, then it's allowed into the instance. Similarly, if an outgoing packet is allowed by either, then it's allowed out of the instance


NEW QUESTION # 99
An HTTP Web Server hosted on an Oracle Cloud Infrastructure (OCI) compute instance in a public subnet of the VCN1 Virtual Cloud Network has a: * Stateless security ingress rule for port 80 access through Internet Gateway * Stateful Network Security Group notification for port 80 How will the OCI VCN handle request/response traffic to the compute instance for a web page from the HTTP server with port 80? (Choose the best Answer.)

  • A. Network Security Group would supersede the Security List and allow both inbound and outbound traffic.
  • B. Because there is no egress rule defined in Security List, the response would not pass through Internet Gateway.
  • C. Due to the conflict in security configuration, inbound request traffic would not be al-lowed.
  • D. The union of both configurations would happen and allow both inbound and outbound traffic.

Answer: B


NEW QUESTION # 100
Cloud Guard detected a risk score of zeroin the dashboard, what does this mean ?

  • A. LOW or MINOR issues
  • B. No problem detected for any resource
  • C. Larger number of problems that have high risk levels ( HIGH or CRITICAL )
  • D. Risk score doesn't say anything. These are just numbers

Answer: B

Explanation:
Explanation
Graphical user interface, text, application Description automatically generated


NEW QUESTION # 101
A company has OCI tenancy which has mount target associated with two File Systems, CG_1 and CG_2. These FileSystems are accessed by IP-based clients AB_1 and AB_2 respectively. As a security administrator, how can you provide access to both clients such that CGI has Read only access on AB1 and CG_2 has Read/Write access on AB_2?

  • A. Vault
  • B. NFS v3 Unix Security
  • C. NFS Export Option
  • D. Access Control Lists

Answer: B,C

Explanation:


NEW QUESTION # 102
What information do youget by using the Network Visualizer tool?

  • A. Routes defined between subnets and gateways
  • B. Interconnectivity of VCNs
  • C. State of subnets in a VCN
  • D. Organization of subnets and VLANs across availability domains

Answer: B

Explanation:
Explanation
https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/network_visualizer.htm You can view and understand the following from this diagram:
How VCNs are inter-connected
How on-premises networks are connected (using FastConnect or Site-to-Site VPN) Which routing entities (DRGs and so on) control trafficrouting How your transit routing is configured


NEW QUESTION # 103
Which VCNconfiguration is CORRECT with regard to VCN peering within a same region ?

  • A. 12.0.0.0/16 and 194.168.0.0/16
  • B. 194.168.0.0/24 and 194.168.0.0/16
  • C. 12.0.0.0/16 and 12.0.0.0/16C 194.168.0.0/24 and 194.168.0.0/24

Answer: A

Explanation:
When setting up VCN peering within the same region, the VCNs must have non-overlapping CIDRs12. In this case, the CIDR blocks 12.0.0.0/16 and 194.168.0.0/16 are different and do not overlap, making them suitable for VCN peering


NEW QUESTION # 104
A customer has multiple virtual machines in a subnet that require access to the public Internet. They want to implement URL filtering to restrict access to certain websites. They have identified the following requirements: All virtual machines should be able to access educational websites. Some virtual machines should not be able to access gaming websites. Some virtual machines should not be able to access social media websites. Which is the best method to implement these requirements? (Choose the best Answer.)

  • A. Create separate subnets for each group of virtual machines with different access requirements and apply different security lists to each subnet.
  • B. Create a single security list for the subnet and apply URL filtering rules based on the requirements.
  • C. Use routing rules to direct traffic to different Internet gateways based on the virtual machines' access requirements.
  • D. Use the network firewall to generate URL lists based on the access requirements of the virtual machines, and then configure security rules to filter traffic accordingly.

Answer: A


NEW QUESTION # 105
Challenge 4 - Task 3 of 6
Configure Web Application Firewall to Protect Web Server Against XSS Attack Scenario You have to protect web applications hosted on OCI from cross-site scripting (XSS) attacks. You can use the OCI Web Application Firewall (WAF) capabilities to create rules that compare against incoming requests to determine if the request contains an XSS attack payload. If a request is determined to be an attack, WAF should return the HTTP Service Unavailable (503) error.
To ensure that the configured WAF blocks the XSS attack, run the following script: [http://<public- ip-enforcement-point>/index.html?<p style="background:url(javascript:alert(1))"](http://<public- ip-enforcement-point>/index.html?<p style="background:url(javascript:alert(1))">) To complete this deployment, you have to perform the following tasks in the environment provisioned for you:
Configure a Virtual Cloud Network (VCN)
Create a Compute Instance and install the Web Server
Create a Load Balancer and update Security List
Create a WAF policy
Configure Protection Rules against XSS attacks
Verify the created environment against XSS attacks

Note: You are provided with access to an OCI Tenancy, an assigned compartment, and OCI credentials. Throughout your exam, ensure to use the assigned Compartment 99233424-C01 and Region us-ashburn-1.
Complete the following task in the provisioned OCI environment:
Go to the VCN IAD-WAF-PBT-VCN-01.
Create a Security List with the name IAD-SP-PBT-LB-SL-01.
Create a Public subnet named LB-Subnet-IAD-SP-PBT-SNET-02 and attach the above-created security list.
Create a Load Balancer with the name IAD-SP-PBT-LB-01.
Create a Listener Name with the name IAD_SP_PBT_LB_LISN_01.
Add appropriate Ingress and Egress rules to IAD-SP-PBT-LB-SL-01, to allow http traffic to the Load Balancer subnet.

Answer:

Explanation:
See the solution below in Explanation
Explanation:
SOLUTION:
From the navigation menu, select Networking and then click Virtual Cloud Network.
In the left navigation pane, under List Scope, select <your assigned compartment> from the drop-down menu.
Click IAD-WAF-PBT-VCN-01 from the list of VCNs.
In the left navigation pane, under Resources, click Security Lists.
Click Create Security List.
In the Create Security List dialogue box, enter the following: a) Name: IAD-SP-PBT-LB-SL-01 b) Do not add any ingress or egress rules. c) Click Create Security List.
In the left navigation pane, under Resources, click Subnets.
Click Create Subnet.
In the Create Subnet dialogue box, enter the following: a) Name: LB-Subnet-IAD-SP-PBT-SNET-02 b) Create in Compartment: <your working compartment name> c) Subnet Type: Regional d) IPv4 CIDR Block: 10.0.4.0/24 e) Security List: From the drop-down menu, select the Security List you had created earlier, IAD-SP-PBT-LB-SL-01.
Click Create Subnet.
You now see that the subnet has been created successfully.
Note: You are provided with access to an OCI Tenancy, an assigned compartment, and OCI credentials. Throughout your exam, ensure to use the assigned Compartment 99233424-C01 and Region us-ashburn-1.


NEW QUESTION # 106
On which option do you set Oracle Cloud Infrastructure Budget?

  • A. Free-form tags
  • B. Compartments
  • C. Instances
  • D. Tenancy

Answer: B

Explanation:
Explanation
How Budgets Work
Budgets are set on cost-tracking tags or on compartments (including theroot compartment) to track all spending in that cost-tracking tag or for that compartment and its children.
https://docs.oracle.com/en-us/iaas/Content/Billing/Concepts/budgetsoverview.htm


NEW QUESTION # 107
You create a new compartment, "apps," to host some production apps and you create an apps_group and added users to it.
What would you do to ensure the users have access to the apps compartment?

  • A. No action is required.
  • B. Add an IAM policy for the individual users to access the apps compartment.
  • C. Add an lAM policy to attach tenancy to the apps group.
  • D. Add an IAM policy for apps_group granting access to the apps compartment.

Answer: D

Explanation:
In Oracle Cloud Infrastructure, you can ensure that users have access to a specific compartment by adding an IAM policy for the group those users belong to, granting access to that compartment45.


NEW QUESTION # 108
......

Accurate 1z0-1104-23 Answers 365 Days Free Updates: https://www.dumpsactual.com/1z0-1104-23-actualtests-dumps.html

Realistic 1z0-1104-23 100% Pass Guaranteed Download  Exam Q&A: https://drive.google.com/open?id=1LvMo5MMvnvonPFG5RyDkH6M2s4ODvmnp