Courseiva

1Z0-997-26 · domain

Security

Practise Oracle Cloud Infrastructure 2026 Architect Professional (1Z0-997-26) (1Z0-997-26) Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

52 questions10 easy21 medium21 hard

Focused practice

Practice Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security

Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security questions (52)

Click any question to see the full explanation, or start a practice session above.

1

You need to ensure that database backups stored in OCI Object Storage are protected against accidental deletion or ransomware encryption by administrators. Which feature should you enable on the bucket?

Medium
2

An OCI Security Administrator is designing a multi-tenancy IAM architecture using compartments and dynamic groups. Which TWO best practices should be implemented to ensure least-privilege access and scalable policy management?

Hard
3

You are hardening an OCI environment where applications running inside Oracle Kubernetes Engine (OKE) pods require access to OCI Object Storage. To adhere to security best practices, you must avoid storing long-lived user credentials or API keys inside the cluster. What is the recommended solution?

Hard
4

Which THREE actions can be performed using OCI Cloud Guard to improve your cloud security posture? (Choose three.)

Medium
5

You are configuring a Remote Peering Connection (RPC) between two Dynamic Routing Gateways (DRGs) in different OCI regions. What is required to ensure secure, private data transmission between the two VCNs?

Hard
6

An enterprise security architect is designing a defense-in-depth strategy for an OCI environment hosting sensitive financial data. Which TWO architectural practices should be implemented to ensure robust network and data security? (Choose two.)

Hard
7

An administrator needs to configure dynamic groups to authenticate OCI compute instances so they can read secrets from OCI Vault. Which TWO components must be properly configured? (Choose two.)

Hard
8

An auditor requests evidence that all API activities across your OCI tenancy are being captured, tamper-proofed, and retained for compliance. Which OCI feature should you configure?

Hard
9

You need to grant a third-party auditor read-only access to view resources in a specific compartment without allowing them to modify anything or access other compartments. Which IAM policy statement achieves this?

Easy
10

An enterprise application running on OCI requires multi-factor authentication (MFA) for all administrators accessing the tenancy console, but developers should be authenticated using an enterprise identity provider (IdP) via SAML 2.0. How should you architect this in OCI IAM?

Hard
11

Which OCI identity component allows you to group users who share the same job function and require the same set of security permissions?

Easy
12

Which THREE features are part of OCI Web Application Firewall (WAF) capabilities? (Choose three.)

Medium
13

An administrator needs to implement secure, administrative access to private OCI compute instances without exposing them to the public internet. Which TWO methods can be utilized?

Medium
14

An administrator needs to encrypt sensitive database passwords stored in OCI Object Storage. The company policy requires customer-managed keys with strict rotation schedules. Which service should the administrator use?

Easy
15

Your development team needs to perform routine maintenance on database compute instances located in a private subnet without exposing SSH ports to the internet or corporate network. Which OCI service should you deploy?

Medium
16

An enterprise customer wants to restrict OCI API access so that developers can only invoke management APIs from corporate office public IP addresses. Which OCI feature implements this restriction?

Medium
17

Which THREE practices are recommended when hardening OCI VCN network security? (Choose three.)

Medium
18

A security administrator wants to ensure that all virtual machine instances in a specific subnet reject all inbound traffic by default, except for explicitly permitted administrative traffic. Where should this rule be enforced?

Medium
19

Your organization uses an external identity provider (IdP), such as Microsoft Entra ID (Azure AD), to authenticate users. You need to map IdP group memberships to OCI IAM groups so that users inherit the correct permissions upon login. How is this integration achieved?

Medium
20

When designing IAM policies at scale in a large OCI enterprise tenancy, which THREE best practices should be followed? (Choose three.)

Medium
21

Which THREE capabilities are provided by OCI Vault for cryptographic key management? (Choose three.)

Medium
22

You are designing a defense-in-depth network architecture for a multi-tier application on OCI. Database servers must reside in a private subnet and accept traffic ONLY from application servers running in a separate private subnet within the same VCN. No external traffic should reach the database. How should you configure security controls?

Medium
23

Your organization mandates that any newly created compartment must automatically enforce rigid security baselines (such as blocking public buckets and disallowing open security list rules). Which OCI feature should you configure to enforce these guardrails at creation time?

Hard
24

An administrator needs to track who deleted a critical database instance in OCI last week. Which service provides the exact API event history needed for this forensic investigation?

Medium
25

Which THREE methods can be used to establish secure, private connectivity from an on-premises datacenter to an OCI VCN without traversing the public internet? (Choose three.)

Medium
26

An internal security audit reveals that database credentials are being passed insecurely in environment variables within OCI Functions. What is the recommended secure pattern to manage these secrets?

Hard
27

Your security architecture requires segregating production workloads from development workloads using distinct VCNs. However, certain microservices in the development VCN must communicate securely with a database in the production VCN without exposing traffic to the internet. What is the recommended networking construct?

Medium
28

Your security team requires that all data stored in OCI Object Storage must adhere to strict compliance frameworks preventing accidental or malicious deletion. Which TWO features should be configured? (Choose two.)

Hard
29

Your company operates a multi-region OCI deployment. Security policies dictate that encryption keys must never leave their respective home regions. How should you design your OCI Vault deployment?

Medium
30

An enterprise customer needs to restrict access to an OCI Object Storage bucket so that only requests originating from a specific Virtual Cloud Network (VCN) via a Service Gateway can read objects. Which combination of Identity and Access Management (IAM) and network policies should be implemented?

Medium
31

What is the primary function of OCI Network Security Groups (NSGs)?

Easy
32

Your development team needs to deploy applications into an OCI Security Zone. They attempt to create a compute instance with a public IP address attached, but the operation fails. Why did this happen?

Medium
33

An incident response team needs to automatically isolate a compromised compute instance in OCI by revoking its network access while preserving its storage volumes for forensic analysis. Which sequence of actions should be automated using OCI Events and Functions?

Hard
34

An enterprise customer is designing a multi-tenancy Oracle Cloud Infrastructure (OCI) environment. They need to ensure that dynamic groups can properly authenticate workloads across different compartments without granting overly broad permissions. Which approach aligns with OCI IAM best practices?

Medium
35

What is the purpose of OCI IAM federation with an external identity provider (IdP)?

Easy
36

Which OCI service checks compute instances and container images for known software vulnerabilities and malware?

Easy
37

Which OCI service continuously monitors your cloud resources for security misconfigurations and risky operational behaviors, providing a unified security score for your tenancy?

Easy
38

An organization requires high security for its cryptographic keys stored in OCI Vault. Which THREE architectural practices must be enforced when configuring and using Master Encryption Keys (MEKs)?

Hard
39

Your organization requires all newly created compartments to automatically enforce security best practices, such as prohibiting public Object Storage buckets and ensuring audit logs are never disabled. Which OCI feature is best suited to achieve this?

Medium
40

Which TWO mechanisms are used to secure data in transit across OCI networking components? (Choose two.)

Hard
41

An application tier in a private VCN subnet needs to securely access an Oracle Autonomous Database without traversing the public internet. Which OCI networking feature provides the most secure and performant connection?

Hard
42

Your security team wants to continuously monitor OCI resources for misconfigurations and automatically remediate security violations without manual intervention. Which OCI native service should you configure?

Easy
43

Which OCI security feature provides a centralized view of security recommendations and allows you to remediate misconfigurations with a single click?

Easy
44

You are configuring a site-to-site IPSec VPN between your on-premises datacenter and an OCI VCN. To ensure data confidentiality and integrity across the public internet, which encryption algorithms should you mandate in the IPSec configuration?

Medium
45

An organization has multiple child compartments under a parent compartment. A security architect needs to write an IAM policy that allows a specific developer group to manage compute instances across all child compartments without granting permissions at the root tenancy level. How should this policy be structured?

Hard
46

Your security team mandates that all traffic entering your OCI VCN from the internet must be inspected by a next-generation firewall before reaching backend web servers. How should you design this architecture?

Hard
47

You are designing a secure zero-trust architecture for database access in OCI. Developers must authenticate using short-lived tokens rather than long-term database passwords. Which OCI and database feature combination supports token-based authentication?

Hard
48

An auditor requests a log of all administrative API actions, console logins, and resource modifications performed across your OCI tenancy over the past 365 days. Which OCI service provides this native auditing capability?

Easy
49

Your security team has discovered that an application running in OCI is susceptible to Cross-Site Scripting (XSS) and SQL injection attacks at the edge. Which OCI service and configuration should you implement to protect the web application without rewriting the core application code?

Hard
50

When configuring OCI Security Zones, which TWO restrictions are automatically enforced on resources within that zone? (Choose two.)

Hard
51

Which TWO logging and monitoring features in OCI are essential for maintaining comprehensive security audit trails and threat detection? (Choose two.)

Hard
52

An organization has strict regulatory requirements to ensure that encryption keys used to protect sensitive database volumes are stored outside of Oracle's managed infrastructure and can be immediately revoked if a security breach is suspected. Which OCI Key Management configuration satisfies this?

Hard

Frequently asked questions

What does the Security domain cover on the 1Z0-997-26 exam?
Security questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 52 Security questions in the 1Z0-997-26 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Oracle Cloud Infrastructure 2026 Architect Professional (1Z0-997-26) (1Z0-997-26) Security Practice Questions