2023 Provide Updated Oracle 1z0-1104-22 Dumps as Practice Test and PDF
1z0-1104-22 Dumps are Available for Instant Access
The Oracle 1z0-1104-22 exam, also known as the Oracle Cloud Infrastructure 2022 Security Professional exam, is a certification test that is designed to validate the skills and knowledge of professionals in the field of cloud security. This exam measures the expertise of candidates in implementing security measures in Oracle Cloud Infrastructure (OCI) environments, including identifying security risks, implementing security controls, monitoring and responding to security incidents, and conducting compliance assessments.
NEW QUESTION # 24
Which OCI service can index, enrich, aggregate, explore, search, analyze, correlate, visualize and monitor data?
- A. Logging Analytics
- B. WAF
- C. Data Safe
- D. Data Guard
Answer: A
Explanation:
NEW QUESTION # 25
Which cache rules criterion matches if the concatenation of the requested URL path and query are identical to the contents of the value field?
- A. URL_PART_CONTAINS
- B. URL_STARTS_WITH
- C. URL_IS
- D. URL_PART_ENDS_WITH
Answer: C
Explanation:
URL_IS: Matches if the concatenation of request URL path and query is identical to the contents of the value field. URL must start with a /.
https://docs.oracle.com/en-us/iaas/tools/terraform-provider-oci/4.57.0/docs/d/waas_waas_policy.html
NEW QUESTION # 26
Which statement is true about using custom BYOI instances in Windows Servers that are managed by OS Management Service?
- A. Windows Servers that already has the minimum agent version requires an agent update or installation.
- B. Windows Servers that does not have the minimum agent version does not require an agent update or installation.
- C. Windows Servers that does not have the minimum agent version requires an agent update or installation.
- D. Windows Servers that already has the minimum agent version does not require an agent update or installation.
Answer: C
Explanation:
https://docs.oracle.com/cd/E11857_01/install.111/e15311/agnt_install_windows.htm
NEW QUESTION # 27
Which WAF service component must be configured to allow, block, or log network requests when they meet specified criteria?
- A. Web Application Firewall policy
- B. Protection rules
- C. Origin
- D. Bot Management
Answer: B
Explanation:
Protection rules
Protection rules can be configured to either allow, block, or log network requests when they meet the specified criteria of a protection rule. The WAF will observe traffic to your web application over time and suggest new rules to apply.
https://www.oracle.com/security/cloud-security/what-is-waf/
NEW QUESTION # 28
Which OCI services can encrypt all data-at-rest ? Select TWO correct answers
- A. NAT Gateway
- B. File Storage
- C. Block Volumes
- D. Geolocation Steering
Answer: B,C
Explanation:
NEW QUESTION # 29
Which Oracle Data Safe feature minimizes the amount of personal data and allows internal test, development, and analytics teams to operate with reduced risk?
- A. data masking
- B. security assessment
- C. data discovery
- D. data auditing
- E. data encryption
Answer: A
NEW QUESTION # 30
With regard to WAF in OCI, which of the following statements are NOT customer's responsibility? Select TWO answers.
- A. Configure Bot Management strategies for a website traffic
- B. Import latest OWASP Core Rule Sets
- C. WAF edge nodes with High Availability
- D. Configure WAF policies for websites
Answer: B,C
NEW QUESTION # 31
Logical isolation for resources is provided by which OCI feature?
- A. Compartments
- B. Region
- C. Availability Zone
- D. Tenancy
Answer: A
NEW QUESTION # 32
A number of malicious requests for a web application is coming from a set of IP addresses originating from Antartica.
Which of the following statement will help to reduce these types of unauthorized requests ?
- A. Delete NAT Gateway from Virtual Cloud Network
- B. Use WAF policy using Access Control Rules
- C. List specific set of IP addresses then deny rules in Virtual Cloud Network Security Lists
- D. Change your home region in which your resources are currently deployed
Answer: B
NEW QUESTION # 33
How can you convert a fixed load balancer to a flexible load balancer?
- A. Delete the fixed load balancer and create a new one.
- B. Using the Edit Listener option.
- C. Use Update Shape workflows.
- D. There is no way to covert the load balancer.
Answer: C
NEW QUESTION # 34
Which is NOT a compliance document?
- A. Bridge letter
- B. Attestation
- C. Penetration test report
- D. Certificate
Answer: C
Explanation:
Types of Compliance Documents
When viewing compliance documents, you can filter on the following types:
Attestation. A Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of Compliance document.
Audit. A general audit report.
Bridge Letter (BridgeLetter). A bridge letter. Bridge letters provide compliance information for the period of time between the end date of an SOC report and the date of the release of a new SOC report.
Certificate. A document indicating certification by a particular authority, with regard to certification requirements and examination results conforming to said requirements.
SOC3. A Service Organization Controls 3 audit report that provides information relating to a service organization's internal controls for security, availability, confidentiality, and privacy.
Other. A compliance document that doesn't fit into any of the preceding, more specific categories.
https://docs.oracle.com/en-us/iaas/Content/ComplianceDocuments/Concepts/compliancedocsoverview.htm
NEW QUESTION # 35
As a security administrator, you want to create cloud resources that align with Oracle's security principles and best practices. Which security service should you use?
- A. Cloud Guard
- B. Security Advisor
- C. Identity and Access Management
- D. Web Application Firewall (WAF)
Answer: B
Explanation:
NEW QUESTION # 36
Which statement about Oracle Cloud Infrastructure Multi-Factor Authentication (MFA) is NOT valid?
- A. Users cannot disable MFA for themselves.
- B. Users must install a supported authenticator app on the mobile device they intend to register for MFA.
- C. A user can register only one device to use for MFA.
- D. An administrator can disable MFA for another user.
Answer: A
NEW QUESTION # 37
which three resources are required to encrypt a block volume with the customer managed key?
- A. SYMMETRIC MASTER KEY ENCRYPTlON KEY
- B. BLOCK KEY
- C. MAXIMUM SECURITY ZONE
- D. OCI VAIRT
- E. IAM Policy Allowing Block Storage to Use Keys
- F. Secrets
Answer: D,E,F
Explanation:
https://docs.oracle.com/en-us/iaas/Content/SecurityAdvisor/Tasks/creatingsecureblockvolume.htm
NEW QUESTION # 38
What is the minimum active storage duration for logs used by Logging Analytics to be archived?
- A. 15 days
- B. 10 days
- C. 60 days
- D. 30 days
Answer: D
Explanation:
https://docs.oracle.com/en-us/iaas/logging-analytics/doc/manage-storage.html#:~:text=The%20minimum%20Active%20Storage%20Duration,be%20archived%20is%2030%20days.
The minimum Active Storage Duration (Days) for logs before they can be archived is 30 days.
NEW QUESTION # 39
Which statements are CORRECT about Multi-Factor Authentication in OCI ? Select TWO correct answers
- A. A user can register multiple devices to use for MFA.
- B. Members of the Administrators group can disable MFA for other users
- C. Users cannot enable MFA for themselves
- D. Members of the Administrators group cannot enable MFA for another user
Answer: B,D
Explanation:

NEW QUESTION # 40
When creating an OCI Vault, which factors may lead to select the Virtual Private Vault ? Select TWO correct answers
- A. Greater degree of isolation
- B. Ability to back up the vault
- C. Need for more than 9211 key versions
- D. To mask Pll data for non-production environment
Answer: A,B
Explanation:
NEW QUESTION # 41
you are part of security operation of an organization with thousand of your users accessing Oracle cloud infrastructure it was reported that an unknown user action was executed resulting in configuration error you are tasked to quickly identify the details of all users who were active in the last six hours also with any rest API call that were executed. Which oci feature should you use?
- A. objectcollectionrule
- B. service connector hub
- C. audit analysis dashboard
- D. management agent log integration
Answer: C
NEW QUESTION # 42
With regard to vulnerability and cloud penetration testing, which rules of engagement apply? Select TWO correct answers.
- A. Physical penetration and vulnerability testing of Oracle facilities is prohibited
- B. You are responsible for any damages to Oracle Cloud customers that are caused by your testing activities
- C. Testing should target any other subscription or any other Oracle Cloud customer resources
- D. Any port scanning must be performed in an aggressive mode
Answer: A,B
Explanation:
NEW QUESTION # 43
Which Security Zone policy is NOT valid?
- A. Resources in a security zone should not be accessible from the public internet.
- B. A boot volume can be moved from a security zone to a standard compartment.
- C. Resources in a security zone must be automatically backed up regularly.
- D. A compute instance cannot be moved from a security zone to a standard compartment.
Answer: B
NEW QUESTION # 44
you want to create a stateless rule for SSH in security list and the ingress role has already been properly configured what combination should you use on the engress role what commination should you use on the egress rule?
- A. select tcp for protocol: enter 22 for source port" and 22 for destination port
- B. select tcp for protocol: enter all for source port" and 22 for destination port.
- C. select udp for protocol: enter 22 for source port" and all for destination port
- D. select tcp for protocol: enter 22 for source port" and all for destination port
Answer: B
NEW QUESTION # 45
Which components are a part of the OCI Identity and Access Management service?
- A. VCN
- B. Compute instances
- C. Policies
- D. Regional subnets
Answer: C
Explanation:
https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/overview.htm
NEW QUESTION # 46
......
Updated 1z0-1104-22 Dumps Questions For Oracle Exam: https://www.certkingdompdf.com/1z0-1104-22-latest-certkingdom-dumps.html