1Z0-1104-25 Exam Questions & Answers
Oracle Cloud Infrastructure 2025 Security Professional • Oracle
100% money-back guarantee
About 1Z0-1104-25 Exam
The 1Z0-1104-25 Oracle Cloud Infrastructure 2025 Security Professional certification exam is designed for IT security professionals and cloud engineers seeking to validate their expertise in securing Oracle Cloud Infrastructure environments. This comprehensive examination covers critical security domains including identity and access management (IAM), network security, data protection, threat detection, and compliance frameworks. Candidates will demonstrate proficiency in implementing security policies, managing encryption, configuring firewalls, and monitoring cloud infrastructure for vulnerabilities. This certification is ideal for security architects, cloud administrators, and professionals responsible for protecting organizational data in OCI environments.
Preparing for the 1Z0-1104-25 exam requires strategic study methods that combine theoretical knowledge with practical application. Updated exam dumps and practice tests serve as invaluable resources, enabling candidates to familiarize themselves with the exam format, question types, and time management strategies. These preparation tools help identify knowledge gaps, reinforce key concepts, and build confidence before the actual examination. By utilizing comprehensive practice tests alongside official Oracle documentation and hands-on lab experience, candidates significantly increase their chances of passing on their first attempt and earning a credential that validates their ability to implement enterprise-grade security solutions within Oracle Cloud Infrastructure.
Exam Topics & Objectives
4-Week Study Plan for 1Z0-1104-25
Week 1: OCI Security Fundamentals and IAM Foundation
- Study OCI Security Introduction: shared responsibility model, security pillars, and compliance frameworks
- Review OCI IAM core concepts: users, groups, compartments, and policies
- Learn policy language syntax and practice writing basic IAM policies
- Understand authentication methods: username/password, API keys, and auth tokens
- Practice Lab: Create users, groups, and apply compartment-based policies
- Review OCI security best practices documentation
- Complete practice questions on IAM fundamentals
Week 2: Advanced IAM, Network Security, and Infrastructure Protection
- Master dynamic groups and policies for compute instances and functions
- Study IAM roles and least privilege principle implementation
- Learn VCN architecture: subnets, route tables, security lists, and NACLs
- Study network security: public/private subnets, internet gateways, and NAT gateways
- Understand Web Application Firewall (WAF) rules and DDoS protection
- Practice Lab: Design and deploy a secure VCN with layered network controls
- Practice Lab: Configure WAF policies for application protection
- Complete practice questions on network and infrastructure protection
Week 3: OS Security, Workload Protection, and Data Protection
- Study OS hardening: bastion hosts, instance principal authentication, and SSH key management
- Learn OCI Compute security: image management, instance metadata service, and secure boot
- Review container security: Container Registry scanning and image signing
- Study encryption at rest: transparent data encryption (TDE), key management, and key vault
- Understand encryption in transit: TLS, SSL, and certificate management
- Learn about OCI Key Management Service (KMS) and Hardware Security Module (HSM)
- Practice Lab: Implement OS-level security controls on compute instances
- Practice Lab: Set up encryption for databases and object storage
- Complete practice questions on workload and data protection
Week 4: Monitoring, Detection, Remediation, and Exam Preparation
- Study OCI Logging service: audit logs, service logs, and log analytics
- Learn OCI Monitoring: metrics, alarms, and event-based triggers
- Understand threat detection: Cloud Guard rules and anomaly detection
- Study incident response and remediation workflows
- Learn about vulnerability management and patch compliance
- Review security advisors and security assessments
- Practice Lab: Configure Cloud Guard for continuous threat detection
- Practice Lab: Set up monitoring and alerting for security events
- Take full-length practice exams and identify weak areas
- Review all previous weeks' topics with focus on exam-style questions
- Complete final review of OCI security best practices and policy examples
Sample 1Z0-1104-25 Questions
Practice with real exam-style questions. Reveal answers to verify your knowledge.
"You are designing a secure access strategy for compute instances deployed within a private subnet of an OCI Virtual Cloud Network (VCN). Your security policy requires that no compute instances in the private subnet should have direct Internet access, and administrative access should be controlled.
Which statement best describes the role of an OCI Bastion in securing access to these private compute instances?
In Oracle Cloud Infrastructure (OCI), bare metal instances provide customers with direct access to the underlying hardware. To mitigate security risks when a customer terminates a bare metal instance, OCI utilizes Root-of-Trust hardware.
What is the primary function of the Root-of-Trust hardware in this context?
SIMULATION
Task 6: Create Load Balancer and Attach Certificate
Create a Load Balancer with the name PBT-CERT-LB-01 in subnet LB-Subnet-PBT-CERT-SNET-02
Create a Listener for the load balancer, where:
Name: PBT-CERT-LB_LTSN_01
Protocol: HTTPS
Port: 443
Attach the certificate PBT-CERT-01-
Attach the security list PBT-CERT-LB-SL-01 to subnet LB-Subnet-PBT-CERT-SNET-02
You have created a compartment TEST in your subscribed tenancy. Then, you created two groups, test1 and test2, and want the users in these groups to be able to manage all the resources in the TEST compartment.
Which policy would you use to achieve this?
SIMULATION
Challenge 2 -Task 1
In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.
As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.
Review the architecture diagram, which outlines the resoures you'll need to address the requirement:

Preconfigured
To complete this requirement, you are provided with the following:
Access to an OCI tenancy, an assigned compartment, and OCI credentials
Required IAM policies
Task 2: Create a Security Zone
Create a security Zone named IAD_SAP-PBT-CSZ-01 in your assigned compartement and associate it with the Custom Security Zone Recipe (IAD-SAP-PBT-CSP-01) created in the previous task.
Enter the OCID of the created Security zone in the box below.

Get access to all 36 verified questions with detailed answers.
Unlock All 1Z0-1104-25 Questions