Questions with Detailed Verified
Answers (100% Correct Answers) |
Already Graded A+
(IAM) You create an Oracle Cloud Infrastructure user account for a new
employee, they are able to log in, but still cannot create any resources.
How do you resolve this? - 🧠ANSWER ✔✔Add the employee to a group
with policies to grant access to relevant resources.
(IAM) What is a policy? - 🧠ANSWER ✔✔A document that specifies who
can access which Oracle Cloud Infrastructure resources that your company
has, and how. Users do not need to do anything, but have to be added to
the group with appropriate policies defined.
(IAM) You want an instance in your compartment to make API calls to other
services within OCI without storing credentials in the configuration file.
What do you need to do? - 🧠ANSWER ✔✔Create appropriate matching
rules in the Dynamic Group to create an instant principle.
COPYRIGHT©PROFFKERRYMARTIN 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE.
1
PRIVACY STATEMENT. ALL RIGHTS RESERVED
,(IAM) How can you provide user access to an existing compartment? -
🧠ANSWER ✔✔By adding users to a group and defining a policy to provide
the group access to the compartment.
(IAM) Which components can you configure in Oracle Infrastructure Identity
and Access Management? - 🧠ANSWER ✔✔Groups, users, compartments,
policies.
(IAM) Which statement is true about Oracle Cloud Identifiers (OCID)? -
🧠ANSWER ✔✔If you delete a user, create a new user with the same
name, the user will be considered a different user because of different
OCIDs.
(IAM) Resource locations - 🧠ANSWER ✔✔Global: IAM, Key Vaults, Keys,
DNS
Availability Domain: Subnet, Compute Instances, Block Volume, DB
Systems, File System (& Mount Target), Ephemeral Public IPs
Regional: Everything else!
(IAM) Which two resources are availability domain constructs? -
🧠ANSWER ✔✔Block Volume, Compute Instance, File Storage Service
Mount Target (FSS)
COPYRIGHT©PROFFKERRYMARTIN 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE.
2
PRIVACY STATEMENT. ALL RIGHTS RESERVED
,(IAM) What's the maximum number of mount targets per an AD is OCI
FSS? - 🧠ANSWER ✔✔2
(IAM) When moving a few applications to Oracle Cloud, asked to design for
both High Availability (HA) and Disaster Recovery (DR). Which two should
you consider while designing OCI architecture? - 🧠ANSWER ✔✔Region,
Availability Domain
(IAM) Responsible for setting up access for all cloud users of a large
enterprise. You log into Phoenix region and create users and policies. You
realize some users might be creating resources in the Ashburn region.
Which steps should you perform to enable those users? - 🧠ANSWER
✔✔IAM users are global. As an administrator, make sure you subscribe to
the Ashburn region.
(IAM) Which two are true for achieving High Availability on Oracle Cloud
Infrastructure? - 🧠ANSWER ✔✔Configure your database to have Data
Guard in another availability domain in sync mode within a region.
Distribute your application servers across all availability domains within a
region.
COPYRIGHT©PROFFKERRYMARTIN 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE.
3
PRIVACY STATEMENT. ALL RIGHTS RESERVED
, (IAM) Which resource is tied to an Availability Domain? - 🧠ANSWER
✔✔Block Volume, Compute Instance
(IAM) Which of the following are Availability Domain specific? - 🧠ANSWER
✔✔Subnets, Block Volume
(IAM) Which identity providers can your administrator federate with Oracle
Cloud Infrastructure? - 🧠ANSWER ✔✔Microsoft Active directory, Oracle
Cloud Identity Servces, Any identity provider that supports Security
Assertion Markup Language (SAML) 2.0 protocol.
(IAM) How do you setup a federation? - 🧠ANSWER ✔✔A trust is setup
between Identity Provider (IdP) and OCI. Any user goes to OCI Console is
prompted with an SSO provided by IdP.The user signs in with
login/password they've setup with IdP and use elsewhere. IdP
authenticates user, user can access OCI resources.Setting up the
relationship with IdP, admin can map each IdP group with a similarly
defined IAM group so company can re-use the IdP group definitions when
authorizing user access to OCI resources.
(IAM) A company uses Microsoft Active Directory as an identity provider.
The company recently purchased OCI to leverage the cloud platform for its
test and development operations. As the administrator, tasked with giving
COPYRIGHT©PROFFKERRYMARTIN 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE.
4
PRIVACY STATEMENT. ALL RIGHTS RESERVED