nerdexam
Oracle

1Z0-083 · Question #19

Which three are true? (Choose three.)

The correct answer is B. Application-common TSDP policies are always container specific. D. Application-common Oracle Label Security (OLS) policies cannot be created in an application root G. Unified auditing can be automatically synchronized to all application PDBs in an application. B, D, and G reflect three distinct behavioral constraints in Oracle Multitenant Application Containers. B is correct because Transparent Sensitive Data Protection (TSDP) policies, even when defined as application-common, are always container-specific in enforcement - they…

Security

Question

Which three are true? (Choose three.)

Options

  • AVirtual Private Database (VPD) policies on objects in an application root are automatically
  • BApplication-common TSDP policies are always container specific.
  • CApplication-common Transparent Security Data Protection (TSDP) policies can be created only
  • DApplication-common Oracle Label Security (OLS) policies cannot be created in an application root
  • EFine-grained auditing (FGA) policies in an application root are automatically synchronized to all
  • FApplication-common OLS policies can be created in an application root inside an install/patch
  • GUnified auditing can be automatically synchronized to all application PDBs in an application

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    84% (26)
  • C
    3% (1)
  • F
    10% (3)

Explanation

B, D, and G reflect three distinct behavioral constraints in Oracle Multitenant Application Containers.

B is correct because Transparent Sensitive Data Protection (TSDP) policies, even when defined as application-common, are always container-specific in enforcement - they cannot propagate automatically across application PDBs. D is correct because Oracle Label Security (OLS) has a hard architectural restriction preventing application-common policies from being created in an application root under any context, including install/patch scripts (making F a trap). G is correct because Unified Auditing is the one auditing mechanism designed for container-wide automation - its policies in an application root can be automatically synchronized to all application PDBs via APP SYNC.

The distractors fail as follows: A and E both claim "automatic synchronization" for VPD and FGA respectively, but neither supports automatic propagation - both require explicit synchronization steps. C makes an incorrect claim about where TSDP policies can be created. F is the mirror-trap of D, falsely asserting OLS policies become valid if placed inside an install/patch script.

Memory tip: Use BDG = "Blocked, Denied, Goes everywhere" - TSDP is Blocked to its own container, OLS is Denied from the root entirely, and Unified Auditing Goes everywhere automatically.

Topics

#Multitenant Policy Behavior#TSDP/OLS/Unified Auditing#Policy Synchronization#Application PDBs

Community Discussion

No community discussion yet for this question.

Full 1Z0-083 Practice