nerdexam
Oracle

1Z0-1067 · Question #47

You deployment platform within Oracle Cloud Infrastructure (OCI) leverages a compute instance with multiple block volumes attached. There are multiple teams that use the same compute instance and…

The correct answer is D. VOLUME_DELETE, VOLUME_ATTACHMENT_DELETE, VOLUME_BACKUP_DELETE. To minimize loss of data due to inadvertent deletes by an authorized user or malicious deletes, Oracle VOLUME_ATTACHMENT_DELETE VOLUME_BACKUP_DELETE permissions to a minimum possible set of IAM users and groups. DELETE permissions should be given only to tenancy and compartment…

Implement OCI Tagging and Governance

Question

You deployment platform within Oracle Cloud Infrastructure (OCI) leverages a compute instance with multiple block volumes attached. There are multiple teams that use the same compute instance and have access to these block volumes. You want to ensure that no one accidentally deletes of these block volumes. You have started to construct the following IAM policy but need to determine which permissions should be used.

Options

  • AERASE_VOLUME, ERASE_VOLUME_ATTACHMENT, ERASE_VOLUME_BACKUP
  • BDELETE.VOLUME, DELETE_VOLUME_ATTACHMENT, DELETE_VOLUME_BACKUP
  • CVOLUME_ERASE, VOLUME_ATTACHMENT_ERASE, VOLUME_BACKUP_ERASE
  • DVOLUME_DELETE, VOLUME_ATTACHMENT_DELETE, VOLUME_BACKUP_DELETE

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    7% (2)
  • C
    7% (2)
  • D
    72% (21)

Explanation

To minimize loss of data due to inadvertent deletes by an authorized user or malicious deletes, Oracle VOLUME_ATTACHMENT_DELETE VOLUME_BACKUP_DELETE permissions to a minimum possible set of IAM users and groups. DELETE permissions should be given only to tenancy and compartment administrators

Topics

#IAM policies#block volume#VOLUME_DELETE#access control

Community Discussion

No community discussion yet for this question.

Full 1Z0-1067 Practice