Rate this post

Latest 1z0-1104-23 Exam Real Tests Free Updated Today

1z0-1104-23 Real Exam Question Answers Updated [May 26, 2024]

Oracle 1z0-1104-23 Exam Syllabus Topics:

Topic Details
Topic 1
  • Discuss core security services offered by OCI
  • Configure security for Oracle Autonomous Database and DB Systems
Topic 2
  • Create and configure Web Application Firewall
  • Implement security monitoring and alerting
Topic 3
  • Use threat intelligence to identify rogue users
  • Configure security for OCI storage services
Topic 4
  • Utilize OS Management to manage and monitor updates
  • Understand and implement Security Zones and Security Advisor
Topic 5
  • Understand MFA, Identity Federation, and SSO
  • Describe OCI Shared Security Responsibility Model
Topic 6
  • Configure, deploy and maintain OCI Certificates
  • Implement Network, Platform, and Infrastructure Security
Topic 7
  • Describe key capabilities provided by Data Safe
  • Describe the use case for auditing and review OCI Audit Logs

 

NO.40 What are Virtual Cloud Network (VCN) flow logs record details about traffic that has been accepted or rejected, based on? (Choose the best Answer.)

 
 
 

NO.41 Which Oracle Cloud Service provides restricted accessto target resources?

 
 
 
 

NO.42 Which statement is true about origin management in WAF?
Statement A: Multiple origins can be defined.
Statement B: Only a single origin can be active fora WAF.

 
 
 
 

NO.43 What do the features of OS Management Service do?

 
 
 
 

NO.44 As a cloud network administrator, you have been tasked with defining ingress and egress access rules for microservices deployed as functions in Oracle Functions. In addition to defining some general access rules in the subnet’s security list, you define more fine-grained rules for different functions using Oracle Cloud Infrastructure (OCI) Network Security Groups (NSGs). Once the NSGs are created, where should they be attached in order to apply to a specific deployed function? (Choose the best Answer.)

 
 
 
 

NO.45 Which OCI cloud service lets you centrally manage the encryption keys thatprotect your data and the secret credentials that you use to securely access resources?

 
 
 
 

NO.46 Which statements are CORRECT about Multi-Factor Authentication in OCI ? Select TWO correct answers

 
 
 
 

NO.47 Your company has implemented a new VPN connection policy, three months after you connected your on-premises network to Oracle Cloud Infrastructure (OCI). Your chief security officer has instructed you to edit the IPSec connection and replace the shared secrets with the new ones that he has provided. Where do you edit the shared secrets? (Choose the best Answer.)

 
 
 
 

NO.48 With regard to OCI Audit Log Service, which of the statement is INCORRECT?

 
 
 
 

NO.49 As a Security Admin you want to inspect the metadata and actual data in your Oracle databases to discover sensitive data and provide comprehensive results listing the sensitive columns and related information. Which Data Safe feature will help you to achieve the above requirement ?

 
 
 
 

NO.50 As a solutions architect, you need to assist operations team to write an I AM policy to give users in group-uat1 and group- uat2 access to manage all resources in the compartment Uat. Which is the CORRECT IAM policy
?

 
 
 
 

NO.51 When creating an OCI Vault, which factors may lead to select the Virtual Private Vault? Select TWO correct answers

 
 
 
 

NO.52 A company has OCI tenancy which has mount target associated with two 1 punto File Systems, CG_1 and CG_2. These File Systems are accessed by IPbased clients AB_1 and AB_2 respectively. As a security administrator, how can you provide access to both clients such that CGI has Read only access on AB1 and CG_2 has Read/Write access on AB_2? OR In your Oracle Cloud Infrastructure (OCI) tenancy, you have a mount target that is associated with two file systems, IS A and rs a. These file systems are being accessed by two IP-based clients, CT_A and CT_B respectively. You need to provide access to both clients, such that CT_A has Read and Write access on FS _A and CT_B has Read Only access on FS_B. Which option would you use? (Choose the best Answer.)

 
 
 
 

NO.53 How can you establish private connectivity over two VCN within same OCI region without traversing the traffic over public internet ?

 
 
 
 

NO.54 you are part of security operation of an organization with thousand of your users accessing Oracle cloud infrastructure it was reported that an unknown user action was executedresulting in configuration error you are tasked to quickly identify the details of all users who were active in the last six hours also with any rest API call that were executed. Which oci feature should you use?

 
 
 
 

NO.55 With regard to OCI Audit Log Service, which of the statement is INCORRECT?

 
 
 
 

NO.56 Challenge 4 – Task 2 of 6
Configure Web Application Firewall to Protect Web Server Against XSS Attack Scenario You have to protect web applications hosted on OCI from cross-site scripting (XSS) attacks. You can use the OCI Web Application Firewall (WAF) capabilities to create rules that compare against incoming requests to determine if the request contains an XSS attack payload. If a request is determined to be an attack, WAF should return the HTTP Service Unavailable (503) error.
To ensure that the configured WAF blocks the XSS attack, run the following script: [http://<public- ip-enforcement-point>/index.html?<p style=”background:url(javascript:alert(1))”](http://<public- ip-enforcement-point>/index.html?<p style=”background:url(javascript:alert(1))”>) To complete this deployment, you have to perform the following tasks in the environment provisioned for you:
Configure a Virtual Cloud Network (VCN)
Create a Compute Instance and install the Web Server
Create a Load Balancer and update Security List
Create a WAF policy
Configure Protection Rules against XSS attacks
Verify the created environment against XSS attacks

Note: You are provided with access to an OCI Tenancy, an assigned compartment, and OCI credentials. Throughout your exam, ensure to use the assigned Compartment 99233424-C01 and Region us-ashburn-1.
Complete the following task in the provisioned OCI environment:
Create a Compute Instance with the name IAD-SP-PBT-VM-01, using the Oracle Linux 8 image and VM.Standard2.1 shape.
SSH to the compute instance using Cloud Shell.
Install and configure Apache web server:
a. Install Apache server:
sudo yum -y install httpd
b. Enable Apache and start Apache server:
bash
sudo systemctl enable httpd
sudo systemctl restart httpd
c. Create a firewall rule to enable HTTP connection through port 80 and reload the firewall:
css
sudo firewall-cmd –permanent –add-port=80/tcp
sudo firewall-cmd –reload
d. Create an index file for your web server:
vbnet
sudo bash -c ‘echo You are visiting Web Server 1 >>
/var/www/html/index.html’

NO.57 you want to create a stateless rule forSSH in security list and the ingress role has already been properly configured what combination should you use on the engress role what commination should you use on the egress rule?

 
 
 
 

NO.58 You are the first responder of a security incident for ABC Org. You have identified sever-al IP addresses and URLs in the logs that you suspect may be related to the incident. However, you need more information to confidently determine whether they are indeed malicious or not. Which OCI service can you use to obtain a more refined information and confidence score for these identified indicators? (Choose the best Answer.)

 
 
 
 

NO.59 Your company will transfer a fleet of 12 servers from on-premises to Oracle Cloud Infra-structure (OCI). The fleet will include two webservers. All 12 servers will be in the same sub-net, and share the exact same security permissions, with the only exception being the two web servers. In addition to the same permissions of the other 10 servers, they will have ports 80 and 443 enabled. The security policy must be hardened to ensure that only those two servers have those ports open. What should your configuration actions be for this scenario? (Choose the best Answer.)

 
 
 
 

Latest 1z0-1104-23 Study Guides 2024 – With Test Engine PDF: https://www.actualcollection.com/1z0-1104-23-exam-questions.html

Related Links: myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt