Courseiva

CCNA Security Services Questions

8 questions · Security Services · All types, answers revealed

1
MCQeasy

An administrator needs to understand where the boundary of customer responsibility lies when deploying compute instances in Oracle Cloud Infrastructure. According to the OCI shared-responsibility model, which responsibility falls solely on the customer?

A.Guest operating system patching and configuration on the compute instances
B.Hypervisor patching and firmware updates on the physical host
C.Redundancy and cooling of the physical networking hardware
D.Physical security of the data center hosting the compute instances
AnswerA

The customer owns the operating system configuration, updates, and application security.

Why this answer

In the OCI shared-responsibility model, OCI is responsible for security OF the cloud, including the underlying physical infrastructure, virtualization, and global network. The customer is responsible for security IN the cloud, which includes guest OS patching, data classification, firewall configurations, and identity and access management.

2
MCQhard

; You need to access a private database instance in an OCI VCN that has no public IP addresses assigned, without setting up a traditional VPN or an inbound bastion host with an open SSH port. Which service should you configure?

A.Dynamic Routing Gateway
B.OCI Bastion
C.NAT Gateway
D.Site-to-Site VPN
AnswerB

OCI Bastion provides secure, managed, zero-public-IP access to private target resources.

Why this answer

OCI Bastion service provides restricted and time-limited secure access to target resources that do not have public IPs, using ephemeral SSH or port forwarding sessions without maintaining a permanent bastion host.

3
MCQmedium

Your organization has strict compliance requirements and needs to ensure that no compute instance in a specific production compartment can ever have a public IP address attached. Which OCI service should you use to enforce this rule automatically?

A.Security Zones
B.Cloud Guard
C.Web Application Firewall
D.Vault Service
AnswerA

Security Zones use pre-built security recipes to enforce preventive guardrails that block non-compliant resource creation.

Why this answer

OCI Security Zones enforce maximum security policies (recipes) by automatically validating and preventing misconfigurations, such as blocking public IP addresses on compute instances or ensuring buckets are private.

4
MCQmedium

A developer needs to store database connection strings and API tokens securely so that applications can retrieve them dynamically without hardcoding credentials. Which OCI service is designed specifically for this purpose?

A.Object Storage with customer-managed keys
B.Key Management Service Master Keys
C.Vault Secrets
D.Identity and Access Management Dynamic Groups
AnswerC

Vault Secrets allows secure storage and dynamic retrieval of sensitive application configuration data.

Why this answer

OCI Vault provides secrets management capabilities that allow you to securely store, manage, and retrieve secrets such as passwords, database connection strings, and certificates.

5
MCQeasy

A security officer wants to monitor security risks across multiple OCI tenancies and compartments from a single consolidated dashboard. Which OCI service should they configure?

A.OCI Cloud Guard
B.OCI Bastion
C.OCI Web Application Firewall
D.OCI Vault
AnswerA

Cloud Guard aggregates security findings across compartments and tenancies into a single dashboard.

Why this answer

OCI Cloud Guard is a cloud security posture management service that helps customers monitor, assess, identify, and maintain a strong security posture on OCI by detecting misconfigured resources and insecure user activities.

6
MCQhard

An enterprise application deployed on OCI is experiencing frequent Layer 7 HTTP flood attacks and SQL injection attempts. Which OCI service provides comprehensive protection against these web vulnerabilities?

A.Cloud Guard
B.Virtual Cloud Network Security Lists
C.Network Security Groups
D.OCI Web Application Firewall
AnswerD

WAF inspects HTTP/S traffic to protect web applications against Layer 7 application exploits.

Why this answer

OCI Web Application Firewall (WAF) is a cloud-based, PCI-compliant security service that protects applications from malicious internet traffic, including cross-site scripting (XSS), SQL injection, and HTTP floods.

7
MCQeasy

According to the OCI shared-responsibility model, who is responsible for managing user accounts, password policies, and multi-factor authentication (MFA) configurations?

A.Oracle
B.Both Oracle and the customer jointly via shared IAM consoles
C.The customer
D.Third-party identity auditor
AnswerC

Identity management, role assignments, and authentication policies are part of security IN the cloud managed by the customer.

Why this answer

IAM user lifecycle management, password policies, and MFA configurations are the sole responsibility of the customer.

8
MCQmedium

Your security team notices that Cloud Guard has generated numerous 'problems' related to overly permissive IAM policies across multiple compartments. Where do these problems originate from?

A.Detector recipes
B.Vault Master Encryption keys
C.Security Zone recipes
D.Responder recipes
AnswerA

Cloud Guard detector recipes define the rules and checks used to scan OCI resources for security misconfigurations.

Why this answer

Cloud Guard uses detector recipes to continuously analyze resources, including IAM policies, network configurations, and storage buckets, to identify security posture deviations.

Ready to test yourself?

Try a timed practice session using only Security Services questions.