Browse Exams — Mock Exams & Practice Tests

1Z0-1104-25 Cheatsheet — OCI Security Professional (IAM, Vault, Cloud Guard)

Last-mile 1Z0-1104-25 review: IAM/policy patterns, compartment scope, Vault/KMS decision rules, network security controls, Cloud Guard posture and response, and audit/logging essentials.

Use this for last‑mile review. Pair it with the Syllabus.


1) Security control map (where each control belongs)

LayerControls to remember
Identitycompartments, policies, dynamic groups, federation (concept-level)
NetworkNSGs/security lists, routing, gateways, segmentation
Dataencryption at rest/in transit, Vault/KMS keys, rotation
DetectionCloud Guard, logging/audit, alerts
Responseresponders, notifications, runbooks, rollback

2) IAM policy patterns (high-yield)

1Allow group <group-name> to <verb> <resource-family> in compartment <compartment-name>

Exam cues

  • Scope to the correct compartment.
  • Choose the minimal verb: read < use < manage.

3) Vault/KMS decision rules

RequirementPrefer
Manage encryption keys, rotate keysVault
Keep secrets out of source codeVault secrets
Compliance requires customer-managed keysVault + CMEK pattern

4) Cloud Guard (detection → problems → response)

    flowchart LR
	  LOG["Audit + Logging"] --> CG["Cloud Guard"]
	  CG --> DET["Detectors"]
	  DET --> PROB["Problems"]
	  PROB --> RESP["Responders"]
	  RESP --> NOTIF["Notifications"]

Rule: security posture is incomplete without logging/audit and an alert path.