Version currency is printed right on the product: ActualPDF staff check the Oracle Cloud Infrastructure 2025 Security Professional collection daily, and your 2026 purchase includes 365 days of free updates to the 1z0-1104-25 practice questions.
Oracle 1z0-1104-25 Exam Overview:
| Certification Vendor: | Oracle |
|---|---|
| Exam Name: | Oracle Cloud Infrastructure 2025 Security Professional |
| Exam Number: | 1Z0-1104-25 |
| Certificate Validity Period: | 3 years |
| Related Certifications: | Oracle Cloud Infrastructure 2025 Architect Associate Oracle Cloud Infrastructure 2025 Security Architect (related OCI security paths) |
| Exam Duration: | 90 minutes |
| Passing Score: | 65-68% |
| Exam Format: | Multiple Choice Questions, Scenario-based questions, Hands-on Performance-based components (variant-dependent) |
| Real Exam Qty: | 55 (MCQ) + possible hands-on performance tasks depending on delivery variant |
| Available Languages: | English |
| Exam Price: | USD 245 (varies by region) |
| Recommended Training: | Become a Cloud Security Professional (2025) - Oracle Learning Path |
| Exam Registration: | Oracle Certification Registration |
| Sample Questions: | ![]() |
| Exam Way: | Online proctored (OnVUE/Pearson VUE) or authorized test centers depending on region |
| Pre Condition: | Recommended: foundational OCI knowledge and basic cloud security understanding (no strict mandatory prerequisites) |
| Official Syllabus URL: | https://learn.oracle.com/ols/learning-path/become-a-cloud-security-professional-2025/118071/147744 |
Oracle 1z0-1104-25 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Data Protection and Encryption | 20% | - OCI Vault and Key Management
|
| Cloud Security Fundamentals | 20% | - Security principles in OCI
|
| Network Security | 20% | - Network controls in OCI
|
| Security Monitoring and Posture Management | 15% | - Detection and response
|
| Identity and Access Management (IAM) | 25% | - IAM fundamentals
|
Oracle 1z0-1104-25 Exam: FAQ for Serious Candidates
Oracle Cloud Infrastructure 2025 Security Professional is an official Oracle exam, listed under exam code 1z0-1104-25. A passing result earns you the Oracle Cloud Infrastructure 2025 Security Professional certification at the Professional level. It also ties into Oracle Cloud Infrastructure 2025 Architect Associate, Oracle Cloud Infrastructure 2025 Security Architect (related OCI security paths), extending its value across your certification roadmap. Employers read this credential as verified competence, which is why it keeps appearing in job requirements.
Expect 55 (MCQ) + possible hands-on performance tasks depending on delivery variant questions inside 90 minutes on the Oracle Cloud Infrastructure 2025 Security Professional exam. That pace punishes hesitation, so rehearse it: the ActualPDF software engine simulates the real exam scene, reminds you of the questions you got wrong, and pushes you to re-practice them until the clock stops being your enemy.
Passing Oracle Cloud Infrastructure 2025 Security Professional requires 65-68%, and the official registration fee is USD 245 (varies by region). Retakes charge the full USD 245 (varies by region) again, which is why experienced candidates treat preparation as the cheaper exam fee. Verify your readiness with repeated ActualPDF practice scores above the requirement before you commit to a date.
Recommended: foundational OCI knowledge and basic cloud security understanding (no strict mandatory prerequisites)
Requirements evolve, so confirm the current conditions before registering on the official exam page.
Registration for Oracle Cloud Infrastructure 2025 Security Professional goes through the official channels listed here.
When you schedule, note that the exam is delivered Online proctored (OnVUE/Pearson VUE) or authorized test centers depending on region.
Oracle recommends the following training for Oracle Cloud Infrastructure 2025 Security Professional candidates.
Follow any course with the 39 practice questions in the ActualPDF 1z0-1104-25 package; the software engine will even remind you which mistakes need another round.
Yes. ActualPDF provides a free download demo of the Oracle Cloud Infrastructure 2025 Security Professional material, so you can check the content before choosing a version. After purchase, a one-year warranty covers you: the latest version is sent to you as it releases, free for 365 days, and after expiry you can extend the update service at a 50% discount.
Your purchase is covered by a 100% money-back guarantee with clear conditions. Take the Oracle Cloud Infrastructure 2025 Security Professional exam within 60 days of purchase; if you fail, provide your unqualified result by submitting a scanned enrollment slip and the official Score Report PDF within 2 days of the exam, and the full refund is processed within 7 days. The exam must match your product, candidate and payer names must match, and attempts within 3 days of purchase, unused downloads, free materials, and expired orders are not covered. Alternatively, exchange for two other exam products of equal value, free, or wait for updates while keeping your original product's update service.
Delivery is instant: files unlock for download at payment and are emailed within one minute. If nothing arrives within 2 hours, check spam and contact customer service, which works 7/24 and normally replies within two hours. Installation is unlimited across your computers.
The Oracle Cloud Infrastructure 2025 Security Professional syllabus spans 5 domains, led by Network Security (20%), Security Monitoring and Posture Management (15%), and Cloud Security Fundamentals (20%). The complete topic list is published above; candidates who study the map first rarely get lost later.
Oracle Cloud Infrastructure 2025 Security Professional Sample Questions:
Which are the essential components to create a rule for the Oracle Cloud Infrastructure (OCI) Events Service?
- A. Install Key and Service Connector
- B. Install Key and Actions
- C. Rule Conditions and Management Agent Cloud Service
- D. Rule Conditions and Actions
Correct Answer: D 🗳️
Based on the provided diagram, you have a group of critical compute instances in a private subnet that require vulnerability using the Oracle Cloud Infrastructure(OCI) Vulnerability Scanning Service (VSS).
"What additional configuration is required to enable VSS to scan instances in the private subnet
- A. VSS cannot scan private instances. You need to move them to a public subnet for vulnerability scanning.
- B. No additional configuration is needed. VSS can access private instances by default.
- C. Use an OCI Bastion session to establish connectivity and forward scan results from the private instances."
- D. Configure a service gateway in the VCN and a route rule to direct traffic for the VSS service through the gateway.
Correct Answer: D 🗳️
Challenge 2 -Task 1
In deploying a new application, a cloud customer needs to reflect different security postures. If a security zone is enabled with the Maximum Security Zone recipe, the customer will be unable to create or update a resource in the security zone if the action violates the attached Maximum Security Zone policy.
As an application requirement, the customer requires a compute instance in the public subnet. You therefore, need to configure Custom Security Zones that allow the creation of compute instances in the public subnet.
Review the architecture diagram, which outlines the resoures you'll need to address the requirement:
Preconfigured
To complete this requirement, you are provided with the following:
Access to an OCI tenancy, an assigned compartment, and OCI credentials
Required IAM policies
Task 1: Create a Custom Security Zone Recipe
Create a Custom Security Zone Recipe named IAD-SP-PBT-CSP-01 that allows the provisioning of compute instances in the public subnet.
Enter the OCID of the created custom security zone recipe in the text box below.
Correct Answer:
See the solution below in Explanation.
Explanation:
To create a Custom Security Zone Recipe named IAD-SP-PBT-CSP-01 that allows the provisioning of compute instances in a public subnet, we will follow the steps outlined in the Oracle Cloud Infrastructure (OCI) Security Zones documentation. These steps are based on verified procedures from the OCI Security Zone Guide and related resources.
Step-by-Step Solution for Task 1: Create a Custom Security Zone Recipe
* Log in to the OCI Console:
* Use your OCI credentials to log in to the OCI Console (https://console.us-ashburn-1.oraclecloud.
com).
* Ensure you have access to the assigned compartment provided in the tenancy.
* Navigate to Security Zones:
* From the OCI Console, go to the navigation menu (hamburger icon) on the top left.
* UnderGovernance and Administration, selectSecurity Zones.
* Create a New Security Zone Recipe:
* In the Security Zones dashboard, click on theRecipestab.
* Click theCreate Recipebutton.
* Configure the Recipe Details:
* Name:Enter IAD-SP-PBT-CSP-01.
* Description:(Optional) Add a description, e.g., "Custom recipe to allow compute instances in public subnet."
* Leave theCompartmentas the assigned compartment provided.
* Define the Security Zone Policy:
* In the policy editor, start with a base policy. Since the Maximum Security Zone recipe restricts public subnet usage, you need to customize it.
* Add the following policy statement to allow compute instances in a public subnet:
Allow service compute to use virtual-network-family in compartment <compartment-name> where ALL { target.resource.type = 'Instance', target.vcn.cidr_block = '10.0.0.0/16', target.subnet.cidr_block = '10.0.10.0/24'
}
* Replace <compartment-name> with the name of your assigned compartment.
* This policy allows the Compute service to provision instances in the public subnet (10.0.10.0/24) within the VCN (10.0.0.0/16).
* Adjust Restrictions:
* Ensure the recipe does not inherit the Maximum Security Zone recipe's default restrictions that block public subnet usage. Explicitly allow the public subnet by including the subnet CIDR block (10.0.10.0/24) in the policy.
* Remove or modify any conflicting default rules that prohibit public subnet usage (e.g., rules blocking internet access or public IP assignment).
* Save the Recipe:
* ClickCreateto save the custom security zone recipe.
* Once created, note theOCIDof the recipe from the recipe details page. The OCID will be a unique identifier starting with ocid1.securityzonerecipe.
* Verify the Recipe:
* Go to theRecipestab and locate IAD-SP-PBT-CSP-01.
* Ensure the policy reflects the allowance for compute instances in the public subnet by reviewing the policy statement.
OCID of the Created Custom Security Zone Recipe
* The exact OCID will be generated upon creation (e.g., ocid1.securityzonerecipe.oc1..unique_string).
Please enter the OCID displayed in the OCI Console after completing Step 7.
Notes
* Ensure IAM policies are correctly configured to grant you permissions to create and manage security zone recipes in the compartment.
* The policy assumes the public subnet CIDR (10.0.10.0/24) matches the diagram. Adjust if the actual subnet CIDR differs.
* Test the recipe by associating it with a security zone and attempting to launch a compute instance to confirm compliance.
Your organization needs to implement strong password policies for users in OCI.
Which of the following statements is TRUE about password policies in OCI IAM?
- A. The default password policy cannot be modified.
- B. Custom password policies allow for granular control over password complexity.
- C. Only one password policy can be applied to all users in a domain.
- D. Simple password policies are suitable for production environments.
Correct Answer: B 🗳️
PDF Version Demo



