Pay attention to our Valid and Useful Exam Reviews and take our Exam Torrent as your Study Material. With little time and energy investment, you have a High Efficiency Study experience. Pass your Actual Test with the help of our Actual Reviews.

[Aug 15, 2022] Fully Updated Free Actual Oracle 1z0-1104-21 Exam Questions [Q39-Q61]

Share

[Aug 15, 2022] Fully Updated Free Actual Oracle 1z0-1104-21 Exam Questions

Free 1z0-1104-21 Questions for Oracle 1z0-1104-21 Exam [Aug-2022]


Oracle 1z0-1104-21 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Configure and manage Secrets in OCI Vault
  • Secure connectivity of hybrid networks (Site-to-Site VPN, FastConnect)
Topic 2
  • Describe OCI Shared Security Responsibility Model
  • Understand MFA, Identity Federation, and SSO
Topic 3
  • Create and configure Web Application Firewall
  • Configure Network Security Groups (NSGs) and Security Lists
Topic 4
  • Design a scalable authorization model with users, groups, and policies
  • Implement conditional and advanced policies
Topic 5
  • Implement security monitoring and alerting
  • Secure connectivity of virtual networks (DRG v2, Peering)
Topic 6
  • Design and implement a logging and logging analytics solution
  • Configure Dynamic Groups, Network Sources, and Tag-Based Access Control
Topic 7
  • Describe use case for Penetration and Vulnerability Testing
  • Cloud Security Business Drivers and Challenges
Topic 8
  • Configure security for Oracle Autonomous Database and DB Systems
  • Configure security for OKE and Oracle Functions

 

NEW QUESTION 39
A number of malicious requests for a web application is coming from a set of IP addresses originating from Antartic a.
Which of the following statement will help to reduce these types of unauthorized requests ?

  • A. Change your home region in which your resources are currently deployed
  • B. Use WAF policy using Access Control Rules
  • C. List specific set of IP addresses then deny rules in Virtual Cloud Network Security Lists
  • D. Delete NAT Gateway from Virtual Cloud Network

Answer: B

 

NEW QUESTION 40
Which Oracle Data Safe feature minimizes the amount of personal data and allows internal test, development, and analytics teams to operate with reduced risk?

  • A. data masking
  • B. data encryption
  • C. security assessment
  • D. data auditing
  • E. data discovery

Answer: A

 

NEW QUESTION 41
Which statements are CORRECT about Multi-Factor Authentication in OCI ? Select TWO correct answers

  • A. Users cannot enable MFA for themselves
  • B. A user can register multiple devices to use for MFA.
  • C. Members of the Administrators group cannot enable MFA for another user
  • D. Members of the Administrators group can disable MFA for other users

Answer: C,D

Explanation:

 

NEW QUESTION 42
As a security architect, how can you prevent unwanted bots while desirable bots are allowed to enter?

  • A. Vault
  • B. Data Guard
  • C. Web Application Firewall (WAF)
  • D. Compartments

Answer: C

 

NEW QUESTION 43
How can you convert a fixed load balancer to a flexible load balancer?

  • A. There is no way to covert the load balancer.
  • B. Use Update Shape workflows.
  • C. Delete the fixed load balancer and create a new one.
  • D. Using the Edit Listener option.

Answer: B

 

NEW QUESTION 44
A member of operations team has set Pre-Authenticated Request (PAR) associated with a bucket to an incorrect date and now wants to edit the PAR request. How can this be achieved?

  • A. Delete both PAR as well as the bucket then recreate both
  • B. Delete the bucket associated with PAR and recreate it
  • C. Delete the PAR and recreate it with the required date
  • D. Don't set an expiration time for PAR

Answer: C

Explanation:

 

NEW QUESTION 45
Which security issues can be identified by Oracle Vulnerability Scanning Service? Select TWO correct answers

  • A. Distributed Denial of Service (DDoS)
  • B. SQL Injection
  • C. Ports that are unintentionally left open can be a potential attack vector for cloud resources
  • D. CIS published Industry-standard benchmarks

Answer: C,D

Explanation:

 

NEW QUESTION 46
You want software that can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm.
Which software must you use?

  • A. Security Information Management (SIM)
  • B. Security Information and Event Management (SIEM)
  • C. Security Integration Management (SIM)
  • D. Security Event Management (SEM)

Answer: B

 

NEW QUESTION 47
Bot Management in OCI provides which of the features? Select TWO correct answers.

  • A. Bad Bot Denylist
  • B. CAPTCHA Challenge
  • C. Good Bot Allowlist
  • D. IP Prefix Steering

Answer: B,C

Explanation:

 

NEW QUESTION 48
Which IAM policy should be created to give XYZ the ability to list contents of a resource excluding the f needs to authenticate in prod compartment ? Principle of least priviledge should be used.

  • A. Allow group XYZ to read all resources in tenancy where target.compartment.name != prod
  • B. Allow group XYZ to manage all resources in compartment != prod
  • C. Allow group XYZ to use all resources in compartment != prod
  • D. Allow group XYZ to inspect all resources in tenancy where target.compartment.name != prod

Answer: D

Explanation:

 

NEW QUESTION 49
Which resources can be used to create and manage from Vault Service ? Select TWO correct answers

  • A. Keys
  • B. Secret
  • C. Cloud Guard
  • D. IAM

Answer: A,B

Explanation:

 

NEW QUESTION 50
Which parameters customers need to configure while reading secrets by name using CL1 or API? Select TWO correct answers.

  • A. Vault Id
  • B. Secret Name
  • C. Certificates
  • D. ASCII Value

Answer: A,B

Explanation:

 

NEW QUESTION 51
Which WAF service component must be configured to allow, block, or log network requests when they meet specified criteria?

  • A. Bot Management
  • B. Web Application Firewall policy
  • C. Origin
  • D. Protection rules

Answer: D

Explanation:
Protection rules
Protection rules can be configured to either allow, block, or log network requests when they meet the specified criteria of a protection rule. The WAF will observe traffic to your web application over time and suggest new rules to apply.
https://www.oracle.com/security/cloud-security/what-is-waf/

 

NEW QUESTION 52
What information do you get by using the Network Visualizer tool?

  • A. Routes defined between subnets and gateways
  • B. Organization of subnets and VLANs across availability domains
  • C. State of subnets in a VCN
  • D. Interconnectivity of VCNs

Answer: D

Explanation:
https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/network_visualizer.htm You can view and understand the following from this diagram:
How VCNs are inter-connected
How on-premises networks are connected (using FastConnect or Site-to-Site VPN) Which routing entities (DRGs and so on) control traffic routing How your transit routing is configured

 

NEW QUESTION 53
VCN Flow log record details about the traffic that has been denied or approved is based on which of the following statements?

  • A. Web Application Firewall (WAF)
  • B. Auth tokens
  • C. Security Lists or Network Security Group Rules
  • D. Configuration of route table

Answer: C

Explanation:

 

NEW QUESTION 54
What is the minimum active storage duration for logs used by Logging Analytics to be archived?

  • A. 15 days
  • B. 10 days
  • C. 60 days
  • D. 30 days

Answer: D

Explanation:
https://docs.oracle.com/en-us/iaas/logging-analytics/doc/manage-storage.html#:~:text=The%20minimum%20Active%20Storage%20Duration,be%20archived%20is%2030%20days.
The minimum Active Storage Duration (Days) for logs before they can be archived is 30 days.

 

NEW QUESTION 55
Which statement is true about standards?

  • A. They may be audited.
  • B. They are methods and instructions on how to maintain or accomplish the directives of the policy.
  • C. They are result of a regulation or contractual requirement or an industry requirement.
  • D. They are the foundation of corporate governance.

Answer: C

 

NEW QUESTION 56
Select the component that encompasses the overall configuration of your WAF service on OCI.

  • A. Bot Management
  • B. Web Application Firewall policy
  • C. Protection rules
  • D. Origin

Answer: B

Explanation:
WAF Policy Management
Provides an overview of web application firewall (WAF) policies, including their creation, updating, and deletion.
WAF policies encompass the overall configuration of your WAF service, including access rules, rate limiting rules, and protection rules.
https://docs.oracle.com/en-us/iaas/Content/WAF/Policies/waf-policy_management.htm

 

NEW QUESTION 57
Which is NOT a compliance document?

  • A. Certificate
  • B. Penetration test report
  • C. Attestation
  • D. Bridge letter

Answer: B

Explanation:
Types of Compliance Documents
When viewing compliance documents, you can filter on the following types:
Attestation. A Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of Compliance document.
Audit. A general audit report.
Bridge Letter (BridgeLetter). A bridge letter. Bridge letters provide compliance information for the period of time between the end date of an SOC report and the date of the release of a new SOC report.
Certificate. A document indicating certification by a particular authority, with regard to certification requirements and examination results conforming to said requirements.
SOC3. A Service Organization Controls 3 audit report that provides information relating to a service organization's internal controls for security, availability, confidentiality, and privacy.
Other. A compliance document that doesn't fit into any of the preceding, more specific categories.
https://docs.oracle.com/en-us/iaas/Content/ComplianceDocuments/Concepts/compliancedocsoverview.htm

 

NEW QUESTION 58
Which component helps move logging data to other services, such as archiving log data in object storage?

  • A. Unified Monitoring Agent
  • B. Service Log Category
  • C. Service Connector Hub
  • D. Agent Configuration

Answer: C

Explanation:
Service Connector Hub
Service Connector Hub moves logging data to other services in Oracle Cloud Infrastructure. For example, use Service Connector Hub to alarm on log data, send log data to databases, and archive log data to Object Storage. For more information, see Service Connector Hub.
https://docs.oracle.com/en-us/iaas/Content/Logging/Concepts/loggingoverview.htm

 

NEW QUESTION 59
With regard to WAF in OCI, which of the following statements are NOT customer's responsibility? Select TWO answers.

  • A. Configure WAF policies for websites
  • B. WAF edge nodes with High Availability
  • C. Configure Bot Management strategies for a website traffic
  • D. Import latest OWASP Core Rule Sets

Answer: B,D

 

NEW QUESTION 60
You create a new compartment, "apps," to host some production apps and you create an apps_group and added users to it.
What would you do to ensure the users have access to the apps compartment?

  • A. No action is required.
  • B. Add an IAM policy for the individual users to access the apps compartment.
  • C. Add an lAM policy to attach tenancy to the apps group.
  • D. Add an IAM policy for apps_group granting access to the apps compartment.

Answer: D

 

NEW QUESTION 61
......

Validate your 1z0-1104-21 Exam Preparation with 1z0-1104-21 Practice Test: https://www.examsreviews.com/1z0-1104-21-pass4sure-exam-review.html