Free Oracle Oracle Cloud Infrastructure 2020 Architect Associate Exam Questions (page: 4)

Which of the following statements is true about the Oracle Cloud Infrastructure (OCI) Object Storage server- side encryption?

  1. Encryption of data encryption keys with a master encryption key is optional.
  2. Customer-provided encryption keys are always stored in OCI Vault service.
  3. Encryption is enabled by default and cannot be turned off.
  4. Each object in a bucket is always encrypted with the same data encryption key.

Answer(s): B


Reference:

https://docs.cloud.oracle.com/en-us/iaas/Content/Object/Tasks/usingyourencryptionkeys.htm



You need to set up instance principals so that an application running on an instance can call Oracle Cloud Infrastructure (OCI) public services, without the need to configure user credentials.

A developer in your team has already configured the application built using an OCI SDK to authenticate using the instance principals provider.

Which is NOT a necessary step to complete this set up?

  1. Create a dynamic group with matching rules to specify which instances you want to allow to make API calls against services.
  2. Generate Auth Tokens to enable instances in the dynamic group to authenticate with APIs.
  3. Create a policy granting permissions to the dynamic group to access services in your compartment or tenancy.
  4. Deploy the application and the SDK to all the instances that belong to the dynamic group.

Answer(s): D


Reference:

https://blogs.oracle.com/cloud-infrastructure/announcing-instance-principals-for-identity-and-access-management



You have been asked to create an Identity and Access Management (IAM) user that will authenticate to Oracle Cloud Infrastructure (OCI) API endpoints. This user must not be given credentials that would allow them to log into the OCI console. Which two authentication options can you use? (Choose two.)

  1. SSL certificate
  2. API signing key
  3. SSH key pair
  4. PEM Certificate file
  5. Auth token

Answer(s): B,E


Reference:

https://docs.cloud.oracle.com/en-us/iaas/Content/Identity/Tasks/managingcredentials.htm



You work for a health insurance company that stores a large number of patient health records in an Oracle Cloud Infrastructure (OCI) Object Storage bucket named "HealthRecords".

Each record needs to be securely stored for a period of 5 years for regulatory compliance purposes and cannot be modified, overwritten or deleted during this time period.

What can you do to meet this requirement?

  1. Create an OCI Object Storage Lifecycle Policies rule to archive objects in the HealthRecords bucket for five years.
  2. Create an OCI Object Storage time-bound Retention Rule on the HealthRecords bucket for five years. Enable Retention Rule Lock on this bucket.
  3. Enable encryption on the HealthRecords bucket using your own vault master encryption keys.
  4. Enable versioning on the HealthRecords bucket.

Answer(s): B


Reference:

https://docs.cloud.oracle.com/en-us/iaas/Content/Object/Tasks/usingretentionrules.htm






Post your Comments and Discuss Oracle Oracle Cloud Infrastructure 2020 Architect Associate exam prep with other Community members:

Oracle Cloud Infrastructure 2020 Architect Associate Exam Discussions & Posts