nerdexam
Oracle

1Z0-1067 · Question #54

You Saw created a group for several auditors. You assign the following policies to the group: What actions are the auditors allowed to perform within your tenancy?

The correct answer is A. Auditors are able to view all resources in the compartment. Let auditors inspect your resources Type of access: Ability to list the resources in all compartments. Be aware that: The operation to list IAM policies includes the contents of the policies themselves The list operations for Networking resource-types return all the information…

Implement OCI Tagging and Governance

Question

You Saw created a group for several auditors. You assign the following policies to the group:

What actions are the auditors allowed to perform within your tenancy?

Options

  • AAuditors are able to view all resources in the compartment.
  • BAuditors are able to create new instances in the tenancy.
  • CThe Auditors can view resources in the tenancy.
  • DThe Auditors are able to delete resources in the tenancy.

How the community answered

(34 responses)
  • A
    79% (27)
  • B
    6% (2)
  • C
    12% (4)
  • D
    3% (1)

Explanation

Let auditors inspect your resources Type of access: Ability to list the resources in all compartments. Be aware that: The operation to list IAM policies includes the contents of the policies themselves The list operations for Networking resource-types return all the information (for example, the contents of security lists and route tables) The operation to list instances requires the read verb instead of inspect, and the contents include the user-provided metadata. The operation to view Audit service events requires the read verb instead of inspect. Where to create the policy: In the tenancy. Because of the concept of policy inheritance, auditors can then inspect both the tenancy and all compartments beneath it. Or you could choose to give auditors access to only specific compartments if they don't need access to the entire tenancy. Allow group Auditors to inspect all-resources in tenancy Allow group Auditors to read instances in tenancy Allow group Auditors to read audit-events in tenancy

Topics

#IAM policies#audit group#read permissions#tenancy access

Community Discussion

No community discussion yet for this question.

Full 1Z0-1067 Practice