Three versions, and most candidates end up choosing the APP online test engine — find out why: the Oracle Cloud Infrastructure 2025 Security Professional material at Test4Engine, 39 practice questions for the 1z0-1104-25 exam.
Oracle 1z0-1104-25 Exam Overview:
| Certification Vendor: | Oracle |
|---|---|
| Exam Name: | Oracle Cloud Infrastructure 2025 Security Professional |
| Exam Number: | 1z0-1104-25 |
| Real Exam Qty: | 55 |
| Passing Score: | 68% |
| Exam Price: | USD $245 |
| Certificate Validity Period: | 3 years |
| Available Languages: | English |
| Related Certifications: | Oracle Cloud Infrastructure 2025 Certified Operations Associate Oracle Cloud Infrastructure 2025 Certified Architect |
| Exam Format: | Multiple Choice, Multiple Response, Scenario-based questions |
| Exam Duration: | 90 minutes |
| Recommended Training: | Become a Cloud Security Professional (2025) OCI Security Professional Training |
| Exam Registration: | Oracle University Registration Pearson VUE Scheduling |
| Sample Questions: | ![]() |
| Exam Way: | Online proctored or Onsite at Pearson VUE test centers |
| Pre Condition: | Basic knowledge of cloud computing, OCI fundamentals, security concepts; 6+ months hands-on experience with OCI security recommended |
| Official Syllabus URL: | https://education.oracle.com/oracle-cloud-infrastructure-2024-security-professional/pexam_1Z0-1104-25 |
Oracle 1z0-1104-25 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Data Protection and Encryption | 15% | - Encryption at rest and in transit - OCI Vault: keys and secrets management - OCI Data Safe: data security and assessment |
| Topic 2: OCI Security Concepts and Shared Responsibility Model | 10% | - Core OCI security services overview - Security design principles - Shared Security Responsibility Model |
| Topic 3: Network Security | 25% | - Network Firewall, Web Application Firewall - Certificate management and Load Balancer security - Security Lists, Network Security Groups |
| Topic 4: Security Operations, Monitoring and Compliance | 10% | - Compliance frameworks and governance - Cloud Guard, Security Zones, Security Advisor - Monitoring, Logging, Events and Alerting |
| Topic 5: Workload and OS Protection | 15% | - OS management and automated updates - OCI Bastion for secure access - Vulnerability scanning for hosts and containers |
| Topic 6: Identity and Access Management (IAM) | 25% | - IAM policies and access control - Dynamic Groups, Network Sources, Tag-based access - IAM domains, users, groups, and compartments - Multi-factor Authentication, Sign-on policies, alerts |
Oracle Cloud Infrastructure 2025 Security Professional Exam FAQ — Worry-Free Answers
The Oracle Cloud Infrastructure 2025 Security Professional is Oracle's certification exam for Oracle Cloud Infrastructure 2025 Security Professional, at the Professional level. It's demanding enough to intimidate — timed practice is the cure. Related credentials include Oracle Cloud Infrastructure 2025 Certified Architect, Oracle Cloud Infrastructure 2025 Certified Operations Associate.
Yes:
After any course, build confidence with the 39 practice questions for the Oracle Cloud Infrastructure 2025 Security Professional — every answer expert-verified.
Through the vendor's official registration channels:
The Oracle Cloud Infrastructure 2025 Security Professional is delivered Online proctored or Onsite at Pearson VUE test centers — pick the arrangement that suits you when booking.
90 minutes for 55 questions. The Test4Engine APP engine imitates the real test — set timed exams, mark performance, point out mistakes — so exam day feels rehearsed.
The Oracle Cloud Infrastructure 2025 Security Professional blueprint spans 6 domains — including Data Protection and Encryption (15%), Security Operations, Monitoring and Compliance (10%), Identity and Access Management (IAM) (25%). The complete outline above lists every subtopic; our IT staff keep the material aligned daily.
Basic knowledge of cloud computing, OCI fundamentals, security concepts; 6+ months hands-on experience with OCI security recommended Eligibility rules change over time, so verify the current requirements on the official page (official 1z0-1104-25 exam page) before registering.
USD $245 per attempt, 68% to pass. Retakes cost the full fee — practice whenever you want with the 39 practice questions for the 1z0-1104-25 exam at Test4Engine.
Soon after payment you receive the Oracle Cloud Infrastructure 2025 Security Professional material by automatic email — about a minute, with Credit Card payment and a strict information system keeping money and data safe; our 7*24 service replies within 2 hours, even on official holidays. If you fail the corresponding 1z0-1104-25 exam within 60 days of purchase, we refund in full: send a scanned enrollment slip plus the official Score Report PDF within 2 days of the exam, processed within 7 days. Excluded: exams within 3 days of purchase, candidate names that don't match the payer, and free or expired products. Or exchange for two equal-value products free.
Yes — download the free Oracle Cloud Infrastructure 2025 Security Professional demo and feel the engine before paying. Purchases include 365 days of free updates by email; renew afterward at 50% off.
Oracle Cloud Infrastructure 2025 Security Professional Sample Questions:
Which are the essential components to create a rule for the Oracle Cloud Infrastructure (OCI) Events Service?
- A. Rule Conditions and Management Agent Cloud Service
- B. Rule Conditions and Actions
- C. Install Key and Service Connector
- D. Install Key and Actions
Correct Answer: B 🗳️
Challenge 2 -Task 1
In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.
As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.
Review the architecture diagram, which outlines the resoures you'll need to address the requirement:
Preconfigured
To complete this requirement, you are provided with the following:
Access to an OCI tenancy, an assigned compartment, and OCI credentials
Required IAM policies
Task 4: Create a Public Subnet
Create a public subnet named IAD-SP-PBT-PUBSNET-01, within the VCN IAD-SP-PBT-VCN-01 use a CIDR block of 10.0.1.0/24 and configure the subnet to use the internet Gateway See the solution below in Explanation.
Correct Answer:
To create a public subnet named IAD-SP-PBT-PUBSNET-01 within the VCN IAD-SP-PBT-VCN-01 using a CIDR block of 10.0.1.0/24 and configure it to use the Internet Gateway, follow these steps based on the Oracle Cloud Infrastructure (OCI) Networking documentation.
Step-by-Step Solution for Task 4: Create a Public Subnet
* Log in to the OCI Console:
* Use your OCI credentials to log in to the OCI Console (https://console.us-ashburn-1.oraclecloud.
com).
* Ensure you have access to the assigned compartment.
* Navigate to Virtual Cloud Networks:
* From the OCI Console, click the navigation menu (hamburger icon) on the top left.
* UnderNetworking, selectVirtual Cloud Networks.
* Select the VCN:
* Locate and click on the VCN named IAD-SP-PBT-VCN-01 created in Task 3.
* UnderResources, selectSubnets.
* Create a New Subnet:
* Click theCreate Subnetbutton.
* Configure the Subnet Details:
* Name:Enter IAD-SP-PBT-PUBSNET-01.
* Compartment:Ensure it is set to the assigned compartment.
* Subnet Type:SelectPublic Subnet.
* CIDR Block:Enter 10.0.1.0/24.
* Route Table:Select the default route table associated with the VCN (ensure it includes a route to the Internet Gateway with destination 0.0.0.0/0).
* Subnet Access:SelectPublic Subnetand ensure the Internet Gateway is associated.
* DHCP Options:Leave as default or customize if required.
* Security List:Use the default security list or create a new one with appropriate ingress/egress rules (e.g., allow TCP port 22 for SSH and all egress traffic).
* Associate the Internet Gateway:
* Verify that the subnet is configured to route traffic through the Internet Gateway. This is automatically handled if you selected the public subnet option and the VCN's route table is correctly set (as configured in Task 3).
* If needed, edit the route table for the subnet to ensure a rule exists:
* Destination CIDR Block:0.0.0.0/0
* Target Type:Internet Gateway
* Target:Select the Internet Gateway associated with IAD-SP-PBT-VCN-01.
* Create the Subnet:
* ClickCreateto provision the subnet.
* Once created, the subnet will be listed under the VCN's subnets.
* Verify the Configuration:
* Go to the subnet details page for IAD-SP-PBT-PUBSNET-01.
* Confirm the CIDR block is 10.0.1.0/24 and that it is a public subnet with Internet Gateway access.
Notes
* Ensure the CIDR block 10.0.1.0/24 does not overlap with existing subnets in the VCN (10.0.0.0/16, including 10.0.10.0/24 from Task 3).
* The Internet Gateway association relies on the route table configuration from Task 3. If it's missing, update the route table as described in Step 6.
In Oracle Cloud Infrastructure (OCI), bare metal instances provide customers with direct access to the underlying hardware. To mitigate security risks when a customer terminates a bare metal instance, OCI utilizes Root-of-Trust hardware.
What is the primary function of the Root-of-Trust hardware in this context?
- A. It automatically encrypts data at rest on the bare metal instance.
- B. It guarantees complete isolation between customer workloads on different instances.
- C. It eliminates the need for hypervisors, reducing the potential attack surface.
- D. It ensures all non-volatile memory on the terminated instance is securely wiped before reuse.
Correct Answer: D 🗳️
Task 7: Verify the OCI Certificate with Load Balancer
Verify HTTPS connection to the load balancer by running the following command in Cloud Shell curl -k https://<Public IP of PBT-CERT-LB-01> Enter the following URL in the web browser:
https://<Public IP of PBT-CERT-LB-01>
If prompted with a certificate error, accept the risk and continue.
Verify web page content by ensuring the text, "You are visiting Web Server 1" from the index.html file is displayed in the browser See the solution below in Explanation.
Correct Answer:
Task 7: Verify the OCI Certificate with Load Balancer
Step 1: Obtain the Public IP of the Load Balancer
* Log in to the OCI Console.
* Navigate toNetworking>Load Balancers.
* Click on PBT-CERT-LB-01.
* Note thePublic IP Addressfrom the load balancer details page.
Step 2: Verify HTTPS Connection Using Cloud Shell
* Open the OCI Cloud Shell from the top-right corner of the OCI Console.
* Run the following command, replacing <Public IP of PBT-CERT-LB-01> with the public IP you noted:
curl -k https://<Public IP of PBT-CERT-LB-01>
* Expected output: You should see the text "You are visiting Web Server 1" if the connection is successful. The -k flag ignores certificate validation errors (common during initial testing with self- signed or newly issued certificates).
* If you encounter an error, ensure the load balancer is active, the listener is configured correctly, and the backend server (PBT-CERT-VM-01) is reachable.
Step 3: Verify in a Web Browser
* Open a web browser.
* Enter the following URL, replacing <Public IP of PBT-CERT-LB-01> with the public IP you noted:
https://<Public IP of PBT-CERT-LB-01>
* If prompted with a certificate warning (e.g., due to a self-signed certificate or untrusted CA), accept the risk and proceed (click "Advanced" and "Proceed" or similar, depending on your browser).
* Verify that the web page displays the text "You are visiting Web Server 1" from the index.html file created on PBT-CERT-VM-01.
Step 4: Troubleshoot (if needed)
* If the text is not displayed:
* Check the load balancer health status underBackend Sets>Healthin the OCI Console.
* Ensure the security list PBT-CERT-LB-SL-01 allows port 443 and the compute instance security list allows port 80.
* Verify the Apache service is running on PBT-CERT-VM-01 by SSHing in and running sudo systemctl status httpd.





