Oracle Cloud Security Exam –Verified Questions,
Correct Answers, and Detailed Explanations for
Computer Science Students||Already Graded A+
1. Which OCI service allows you to centrally manage user access to
all Oracle Cloud resources?
A. Oracle Cloud Guard
B. Identity and Access Management (IAM)
C. Oracle Key Management
D. Oracle Vault
IAM provides centralized management for user identities, policies,
groups, and roles across OCI resources.
2. What is the primary function of an OCI Policy?
A. Encrypting data at rest
B. Controlling access to resources based on user/group permissions
C. Monitoring network traffic
D. Managing security keys
OCI policies define who can access which resources and what actions
they can perform.
3. Which OCI feature allows for automatic detection of security
threats across your tenancy?
A. OCI IAM
B. OCI Vault
C. OCI Cloud Guard
D. OCI Bastion
Cloud Guard continuously monitors security configurations and alerts
for potential risks.
,4. Which encryption method does OCI recommend for data at rest?
A. SSL/TLS
B. RSA 1024
C. AES-256
D. MD5
AES-256 provides strong symmetric encryption suitable for protecting
data at rest.
5. What is the function of OCI Vault?
A. Managing IAM users
B. Monitoring network security
C. Storing and managing encryption keys and secrets
D. Configuring security groups
OCI Vault securely stores encryption keys and secrets used by OCI
services.
6. Which OCI component allows secure network access to your
private resources without using the public internet?
A. Internet Gateway
B. Service Gateway
C. NAT Gateway
D. Load Balancer
Service Gateway allows private access to Oracle services (like Object
Storage) without traversing the internet.
7. What is the primary benefit of using OCI Security Zones?
A. Centralized logging
B. Automated patch management
,C. Enforcing security controls at the compartment level
D. Key rotation
Security Zones enforce strict security rules automatically for resources
within a zone.
8. Which OCI service provides audit logs for all user and
administrator actions?
A. OCI Cloud Guard
B. OCI Audit
C. OCI Vault
D. OCI Monitoring
OCI Audit captures detailed logs of all API calls, including user and
system activity.
9. Which authentication method does OCI support for federated
identity management?
A. Local passwords only
B. API keys only
C. SAML 2.0 federation
D. SSH key pairs
SAML 2.0 federation allows users from external identity providers to
access OCI resources.
10. In OCI, what is the purpose of a Security List?
A. Encrypting storage volumes
B. Defining allowed ingress and egress traffic for VCN subnets
C. Controlling IAM policies
D. Managing API keys
Security Lists act as virtual firewall rules controlling subnet traffic.
, 11. What is the recommended OCI practice for managing sensitive
data across environments?
A. Hardcode credentials in code
B. Use OCI Vault to store secrets and encryption keys
C. Share secrets via email
D. Disable encryption for speed
OCI Vault centralizes secure key and secret management, reducing
exposure risks.
12. What is the function of OCI Bastion?
A. Encrypting object storage
B. Providing secure SSH/RDP access to private instances
C. Monitoring network traffic
D. Managing IAM policies
Bastion allows controlled administrative access to private resources
without public exposure.
13. Which OCI service allows you to continuously evaluate your
cloud resources against security best practices?
A. OCI IAM
B. OCI Vault
C. OCI Cloud Guard
D. OCI Audit
Cloud Guard automates security assessments and alerts for policy
violations.
14. Which type of key does OCI Vault use for data encryption?
A. Symmetric and asymmetric keys
Correct Answers, and Detailed Explanations for
Computer Science Students||Already Graded A+
1. Which OCI service allows you to centrally manage user access to
all Oracle Cloud resources?
A. Oracle Cloud Guard
B. Identity and Access Management (IAM)
C. Oracle Key Management
D. Oracle Vault
IAM provides centralized management for user identities, policies,
groups, and roles across OCI resources.
2. What is the primary function of an OCI Policy?
A. Encrypting data at rest
B. Controlling access to resources based on user/group permissions
C. Monitoring network traffic
D. Managing security keys
OCI policies define who can access which resources and what actions
they can perform.
3. Which OCI feature allows for automatic detection of security
threats across your tenancy?
A. OCI IAM
B. OCI Vault
C. OCI Cloud Guard
D. OCI Bastion
Cloud Guard continuously monitors security configurations and alerts
for potential risks.
,4. Which encryption method does OCI recommend for data at rest?
A. SSL/TLS
B. RSA 1024
C. AES-256
D. MD5
AES-256 provides strong symmetric encryption suitable for protecting
data at rest.
5. What is the function of OCI Vault?
A. Managing IAM users
B. Monitoring network security
C. Storing and managing encryption keys and secrets
D. Configuring security groups
OCI Vault securely stores encryption keys and secrets used by OCI
services.
6. Which OCI component allows secure network access to your
private resources without using the public internet?
A. Internet Gateway
B. Service Gateway
C. NAT Gateway
D. Load Balancer
Service Gateway allows private access to Oracle services (like Object
Storage) without traversing the internet.
7. What is the primary benefit of using OCI Security Zones?
A. Centralized logging
B. Automated patch management
,C. Enforcing security controls at the compartment level
D. Key rotation
Security Zones enforce strict security rules automatically for resources
within a zone.
8. Which OCI service provides audit logs for all user and
administrator actions?
A. OCI Cloud Guard
B. OCI Audit
C. OCI Vault
D. OCI Monitoring
OCI Audit captures detailed logs of all API calls, including user and
system activity.
9. Which authentication method does OCI support for federated
identity management?
A. Local passwords only
B. API keys only
C. SAML 2.0 federation
D. SSH key pairs
SAML 2.0 federation allows users from external identity providers to
access OCI resources.
10. In OCI, what is the purpose of a Security List?
A. Encrypting storage volumes
B. Defining allowed ingress and egress traffic for VCN subnets
C. Controlling IAM policies
D. Managing API keys
Security Lists act as virtual firewall rules controlling subnet traffic.
, 11. What is the recommended OCI practice for managing sensitive
data across environments?
A. Hardcode credentials in code
B. Use OCI Vault to store secrets and encryption keys
C. Share secrets via email
D. Disable encryption for speed
OCI Vault centralizes secure key and secret management, reducing
exposure risks.
12. What is the function of OCI Bastion?
A. Encrypting object storage
B. Providing secure SSH/RDP access to private instances
C. Monitoring network traffic
D. Managing IAM policies
Bastion allows controlled administrative access to private resources
without public exposure.
13. Which OCI service allows you to continuously evaluate your
cloud resources against security best practices?
A. OCI IAM
B. OCI Vault
C. OCI Cloud Guard
D. OCI Audit
Cloud Guard automates security assessments and alerts for policy
violations.
14. Which type of key does OCI Vault use for data encryption?
A. Symmetric and asymmetric keys