[2023年12月12日]1z0-1104-23試験問題集でOracle練習テスト問題
最新でリアルな1z0-1104-23試験問題集解答
質問 # 21
What are the security recommendations and best practices for Oracle Functions?
- A. Define a policy statement that enables access to functions for requests coming from multiple IP addresses.
- B. Ensure that functions in a VCN have restricted access to resources and services.
- C. Add applications to network security groups for fine-grained ingress/egress rules.
- D. Grant privileges to UID and GID 1000, such that the functions running within a container acquire the default rootcapabilities.
正解:C
解説:
Explanation
https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/securitylists.htm
質問 # 22
which three resources are required to encrypt a block volume with the customer managed key?
- A. Secrets
- B. OCI VAIRT
- C. IAM Policy Allowing Block Storage to Use Keys
- D. MAXIMUM SECURITY ZONE
- E. BLOCK KEY
- F. SYMMETRIC MASTER KEY ENCRYPTlON KEY
正解:A、B、C
解説:
Explanation
https://docs.oracle.com/en-us/iaas/Content/SecurityAdvisor/Tasks/creatingsecureblockvolume.htm
質問 # 23
Which is NOT a part of Observability and Management Services?
- A. Logging Analytics
- B. Event Services
- C. OCI Management Service
- D. Logging
正解:C
解説:
Explanation
https://www.oracle.com/in/manageability/
質問 # 24
Where is sensitive configuration data (like certificates, and credentials) is stored by Kubernetes cluster control plane?
- A. ETCD
- B. Oracle Functions
- C. Block Volume
- D. Boot Volume
正解:A
解説:
Explanation
Graphical user interface, text, application, email Description automatically generated
質問 # 25
Which of the following is necessary step when creating a secret in vault?
- A. Object Storage must be created to run secret service
- B. Digest Hash shouldbe created of the secret value
- C. Shamir's secret sharing algorithm should be used to unseal the vault
- D. Vault-managed key is necessary to encrypt the secret
正解:D
解説:
Explanation
https://docs.oracle.com/en/database/other-databases/essbase/21/essad/create-vault-and-secrets.html
質問 # 26
Which storage type is most effective when you want to move some unstructured data, consisting of images and videos, to cloud storage?
- A. File storage
- B. Archivestorage
- C. Block volume
- D. Standard storage
正解:D
解説:
Explanation
Use Oracle Cloud Infrastructure Object Storage for data to which you need fast, immediate, and frequent access. Data accessibility and performance justifies a higher price point to store data in the Object Storage tier.
The Object Storage service can store an unlimited amount of unstructured data of any content type, including analytic data and rich content, like images and videos.
https://docs.oracle.com/en/solutions/learn-migrate-app-data-to-cloud/considerations-object-storage.html#GUID-A
質問 # 27
Which WAF service component must be configured to allow, block, or log network requests when they meet specified criteria?
- A. Bot Management
- B. Origin
- C. Protection rules
- D. Web ApplicationFirewall policy
正解:C
解説:
Explanation
Protection rules
Protection rules can be configured to either allow, block, or log network requests when they meet the specified criteria of a protection rule. The WAF will observe traffic to your web application over time and suggest new rules to apply.
https://www.oracle.com/security/cloud-security/what-is-waf/
質問 # 28
Which statement is true about standards?
- A. They are methods and instructions on how to maintain or accomplish the directives of the policy.
- B. They are the foundation of corporate governance.
- C. They may be audited.
- D. They are result of a regulation or contractual requirement or an industry requirement.
正解:B
解説:
Explanation
Standards are the foundation of corporate governance as they provide a framework for how a corporation is managed and controlled
質問 # 29
you want to create a stateless rule forSSH in security list and the ingress role has already been properly configured what combination should you use on the engress role what commination should you use on the egress rule?
- A. select tcp for protocol: enter 22 for source port" and all for destinationport
- B. select tcp for protocol: enter all for source port" and 22 for destination port.
- C. select tcp for protocol: enter 22 for source port" and 22 for destination port
- D. select udp for protocol: enter 22 for source port" and all for destination port
正解:B
解説:
Explanation
For SSH traffic, which uses TCP protocol and port 22, you would want to allow all source ports to connect to your destination port 22. This is because the source port for an SSH client can be any available port number.
質問 # 30
For how long are API calls audited and available?
- A. 90 days
- B. 30days
- C. 60 days
- D. 365 days
正解:D
解説:
Explanation
https://docs.public.oneportal.content.oci.oraclecloud.com/en-us/iaas/Content/Audit/Tasks/settingretentionperiod.
質問 # 31
Which securityissues can be identified by Oracle Vulnerability Scanning Service? Select TWO correct answers
- A. SQL Injection
- B. Distributed Denial of Service (DDoS)
- C. CISpublished Industry-standard benchmarks
- D. Ports that are unintentionally left open can be a potential attack vector for cloud resources
正解:C、D
解説:
Explanation
Graphical user interface, text, application, email Description automatically generated
質問 # 32
Logical isolation for resources is provided by which OCI feature?
- A. Tenancy
- B. Availability Zone
- C. Region
- D. Compartments
正解:D
解説:
Explanation
Compartments in Oracle Cloud Infrastructure (OCI) are a fundamental component that allows you to create a heterogeneous collection of resources for organization, security isolation, and access control123. They provide a global logical namespace where policies can be enforced, similar to folders in a file system3. By being global, they stretch out to all OCI regions within a given tenancy3.
質問 # 33
You want software that can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm.
Which software must you use?
- A. Security Integration Management (SIM)
- B. Security Information Management (SIM)
- C. SecurityEvent Management (SEM)
- D. Security Information and Event Management (SIEM)
正解:D
解説:
Explanation
SIEM software can automatically collect and aggregate log data generated throughout your organization's infrastructure, analyze it, and send alerts if it detects a deviation from the norm23.
質問 # 34
As a security administrator, you want to create cloud resources that alignwith Oracle's security principles and best practices. Which security service should you use?
- A. Security Advisor
- B. Web Application Firewall (WAF)
- C. Cloud Guard
- D. Identity and Access Management
正解:A
解説:
Explanation
Graphical user interface, text, application, email Description automatically generated
質問 # 35
Which is NOT a compliance document?
- A. Certificate
- B. Attestation
- C. Bridge letter
- D. Penetration test report
正解:D
解説:
Explanation
Types of Compliance Documents
When viewing compliance documents, you can filter onthe following types:
Attestation. A Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of Compliance document.
Audit. A general audit report.
Bridge Letter (BridgeLetter). A bridge letter. Bridge letters provide compliance information forthe period of time between the end date of an SOC report and the date of the release of a new SOC report.
Certificate. A document indicating certification by a particular authority, with regard to certification requirements and examination results conforming to said requirements.
SOC3. A Service Organization Controls 3 audit report that provides information relating to a service organization's internal controls for security, availability, confidentiality, and privacy.
Other. A compliance document that doesn't fit into any of the preceding, more specific categories.
https://docs.oracle.com/en-us/iaas/Content/ComplianceDocuments/Concepts/compliancedocsoverview.htm
質問 # 36
Which parameters customers need to configure while reading secrets by name using CL1 or API? Select TWO correct answers.
- A. Certificates
- B. Vault Id
- C. Secret Name
- D. ASCII Value
正解:B、C
解説:
Explanation
Graphical user interface, text, application, email Description automatically generated
質問 # 37
An e-commerce company needs to authenticate with third-party API that don't support OCI's signature-based authentication.
What can be the solution for the above scenario?
- A. Asymmetric keys
- B. Auth Token/Swift Password
- C. Security Token
- D. API Key Authentication
正解:B
解説:
Explanation
Graphical user interface, text, application, email Description automatically generated
質問 # 38
On which option do you set Oracle Cloud Infrastructure Budget?
- A. Tenancy
- B. Instances
- C. Free-form tags
- D. Compartments
正解:D
解説:
Explanation
How Budgets Work
Budgets are set on cost-tracking tags or on compartments (including theroot compartment) to track all spending in that cost-tracking tag or for that compartment and its children.
https://docs.oracle.com/en-us/iaas/Content/Billing/Concepts/budgetsoverview.htm
質問 # 39
Which IAM policy should be created to give XYZ the ability to list contents of a resource excluding the fneeds to authenticatein prod compartment ? Principle of least priviledge should be used.
- A. Allow group XYZ to read all resources in tenancy where target.compartment.name != prod
- B. Allow group XYZ to use all resources in compartment != prod
- C. Allow group XYZ to inspect all resources in tenancy where target.compartment.name != prod
- D. Allow group XYZ to manage all resources in compartment != prod
正解:C
解説:
Explanation
Graphical user interface, text, application Description automatically generated
質問 # 40
When doesCloud Guard re-open an issue and update the history?
- A. If it detects an issue for a previously dismissed configuration problem
- B. If it detects an issue for a previously resolved configuration problem
- C. If it detects an issue again for an Open (unresolved) problem
- D. If it detects an issue for a previously resolved/dismissed activity problem
正解:B
解説:
Explanation
If Cloud Guard detects an issue again for:
An Open (unresolved) problem, it updates the problem history, but doesn't create a new problem.
A previouslysolved problem, it reopens the issue and updates the history.
A previously dismissed problem, it updates the history.
https://docs.oracle.com/en-us/iaas/cloud-guard/using/problems-page.htm
質問 # 41
......
あなたを簡単に合格させる1z0-1104-23試験正確なPDF問題:https://jp.fast2test.com/1z0-1104-23-premium-file.html