Courseiva

1Z0-997-26 · topic practice

Security practice questions

Practise Oracle Cloud Infrastructure 2026 Architect Professional (1Z0-997-26) (1Z0-997-26) Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Security

What the exam tests

What to know about Security

Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Security questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full Security explanation →

Your security team has discovered that an application running in OCI is susceptible to Cross-Site Scripting (XSS) and SQL injection attacks at the edge. Which OCI service and configuration should you implement to protect the web application without rewriting the core application code?

Question 2easymultiple choice
Read the full Security explanation →

An administrator needs to encrypt sensitive database passwords stored in OCI Object Storage. The company policy requires customer-managed keys with strict rotation schedules. Which service should the administrator use?

Question 3mediummultiple choice
Read the full Security explanation →

Your security architecture requires segregating production workloads from development workloads using distinct VCNs. However, certain microservices in the development VCN must communicate securely with a database in the production VCN without exposing traffic to the internet. What is the recommended networking construct?

Question 4hardmultiple choice
Review the full subnetting walkthrough →

An application tier in a private VCN subnet needs to securely access an Oracle Autonomous Database without traversing the public internet. Which OCI networking feature provides the most secure and performant connection?

Question 5hardmultiple choice
Read the full Security explanation →

An auditor requests evidence that all API activities across your OCI tenancy are being captured, tamper-proofed, and retained for compliance. Which OCI feature should you configure?

Question 6easymultiple choice
Read the full Security explanation →

Which OCI service continuously monitors your cloud resources for security misconfigurations and risky operational behaviors, providing a unified security score for your tenancy?

Question 7mediummultiple choice
Read the full Security explanation →

An enterprise customer is designing a multi-tenancy Oracle Cloud Infrastructure (OCI) environment. They need to ensure that dynamic groups can properly authenticate workloads across different compartments without granting overly broad permissions. Which approach aligns with OCI IAM best practices?

Question 8mediummultiple choice
Read the full Security explanation →

Your organization requires all newly created compartments to automatically enforce security best practices, such as prohibiting public Object Storage buckets and ensuring audit logs are never disabled. Which OCI feature is best suited to achieve this?

Question 9hardmultiple choice
Read the full Security explanation →

An organization has strict regulatory requirements to ensure that encryption keys used to protect sensitive database volumes are stored outside of Oracle's managed infrastructure and can be immediately revoked if a security breach is suspected. Which OCI Key Management configuration satisfies this?

Question 10easymultiple choice
Read the full Security explanation →

Which OCI service checks compute instances and container images for known software vulnerabilities and malware?

Question 11mediummultiple choice
Review the full subnetting walkthrough →

Your development team needs to perform routine maintenance on database compute instances located in a private subnet without exposing SSH ports to the internet or corporate network. Which OCI service should you deploy?

Question 12mediummultiple choice
Review the full subnetting walkthrough →

A security administrator wants to ensure that all virtual machine instances in a specific subnet reject all inbound traffic by default, except for explicitly permitted administrative traffic. Where should this rule be enforced?

Question 13easymultiple choice
Read the full Security explanation →

You need to grant a third-party auditor read-only access to view resources in a specific compartment without allowing them to modify anything or access other compartments. Which IAM policy statement achieves this?

Question 14hardmultiple choice
Read the full Security explanation →

An enterprise application running on OCI requires multi-factor authentication (MFA) for all administrators accessing the tenancy console, but developers should be authenticated using an enterprise identity provider (IdP) via SAML 2.0. How should you architect this in OCI IAM?

Question 15mediummultiple choice
Read the full Security explanation →

Your company operates a multi-region OCI deployment. Security policies dictate that encryption keys must never leave their respective home regions. How should you design your OCI Vault deployment?

Question 16hardmultiple choice
Read the full Security explanation →

An incident response team needs to automatically isolate a compromised compute instance in OCI by revoking its network access while preserving its storage volumes for forensic analysis. Which sequence of actions should be automated using OCI Events and Functions?

Question 17hardmultiple choice
Read the full Security explanation →

An internal security audit reveals that database credentials are being passed insecurely in environment variables within OCI Functions. What is the recommended secure pattern to manage these secrets?

Question 18mediummultiple choice
Read the full Security explanation →

You need to ensure that database backups stored in OCI Object Storage are protected against accidental deletion or ransomware encryption by administrators. Which feature should you enable on the bucket?

Question 19easymultiple choice
Read the full Security explanation →

Which OCI identity component allows you to group users who share the same job function and require the same set of security permissions?

Question 20easymultiple choice
Read the full Security explanation →

Which OCI security feature provides a centralized view of security recommendations and allows you to remediate misconfigurations with a single click?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security sessions

Start a Security only practice session

Every question in these sessions is drawn from the Security domain — nothing else.

Related practice questions

Related 1Z0-997-26 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 1Z0-997-26 exam test about Security?
Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 1Z0-997-26 topics?
Use the topic links above to move to related areas, or go back to the 1Z0-997-26 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 1Z0-997-26 exam covers. They are not copied from any real exam or dump site.