Browse Exams — Mock Exams & Practice Tests

1Z0-1104-25 Cheatsheet — OCI Security Professional (IAM, Vault, Cloud Guard)

Last-mile 1Z0-1104-25 review: IAM/policy patterns, compartment scope, Vault/KMS decision rules, network security controls, Cloud Guard posture and response, and audit/logging essentials.

Use this for last‑mile review. Pair it with the Syllabus.


1) Security control map (where each control belongs)

Layer Controls to remember
Identity compartments, policies, dynamic groups, federation (concept-level)
Network NSGs/security lists, routing, gateways, segmentation
Data encryption at rest/in transit, Vault/KMS keys, rotation
Detection Cloud Guard, logging/audit, alerts
Response responders, notifications, runbooks, rollback

2) IAM policy patterns (high-yield)

1Allow group <group-name> to <verb> <resource-family> in compartment <compartment-name>

Exam cues

  • Scope to the correct compartment.
  • Choose the minimal verb: read < use < manage.

3) Vault/KMS decision rules

Requirement Prefer
Manage encryption keys, rotate keys Vault
Keep secrets out of source code Vault secrets
Compliance requires customer-managed keys Vault + CMEK pattern

4) Cloud Guard (detection → problems → response)

    flowchart LR
	  LOG["Audit + Logging"] --> CG["Cloud Guard"]
	  CG --> DET["Detectors"]
	  DET --> PROB["Problems"]
	  PROB --> RESP["Responders"]
	  RESP --> NOTIF["Notifications"]

Rule: security posture is incomplete without logging/audit and an alert path.