nerdexam
Oracle

1Z0-1085-20 · Question #33

Which Oracle Cloud Infrastructure (OCI) service can be used to protect sensitive and regulated data in OCI database services?

The correct answer is D. Oracle Data Safe. https://docs.cloud.oracle.com/en-us/iaas/data-safe/index.html

Understand OCI Security and Compliance

Question

Which Oracle Cloud Infrastructure (OCI) service can be used to protect sensitive and regulated data in OCI database services?

Options

  • AOracle Data Guard
  • BOCI Audit
  • COCI OS management
  • DOracle Data Safe

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    14% (5)
  • C
    8% (3)
  • D
    76% (28)

Explanation

https://docs.cloud.oracle.com/en-us/iaas/data-safe/index.html

Topics

#Oracle Data Safe#database security#sensitive data#data masking

Community Discussion

6
Prof. SaraProf. SaraMay 11, 2026

The correct answer is D, Oracle Data Safe. Think of it this way: the word "Safe" is right in the name, and that is not an accident. Oracle Data Safe is the purpose-built OCI service for database security, giving you sensitive data discovery, data masking, security assessments, user assessments, and activity auditing all under one roof. The distractors are worth nailing down because the exam loves to test them. Data Guard (A) is your high-availability and disaster recovery tool, not a data-protection or compliance tool. OCI Audit (B) logs API calls across OCI services, which matters for governance, but it does not reach inside a database to identify or mask regulated data. OS Management (C) handles patching and package management at the operating system level, which is a completely different domain. In the 1Z0-1085-20 blueprint, questions like this one sit in the Security domain, and the pattern the blueprint follows is: if the question mentions sensitive data, regulated data, or database-level protection specifically, Oracle Data Safe is almost always the answer. Lock that mapping in and you will not lose points here.

19
Hiroshi T.Hiroshi T.May 22, 2026

Saw this exact question on my sitting last spring and almost talked myself into B because the word "audit" sounds like compliance, but the Oracle documentation for Data Safe explicitly lists sensitive data discovery, data masking, and security assessment for database services as its core functions. Data Guard is replication/DR, OS Management is patching, and Audit is for API call logging, so D is the only one that fits the "protect sensitive and regulated data in database services" definition from the official feature page.

5
Toby R.Toby R.May 23, 2026

Solid breakdown, and worth adding that Data Safe also covers user assessment so you can catch over-privileged accounts, which is another reason it fits the "protect sensitive and regulated data" framing better than anything else on that list.

0
Toby R.Toby R.May 6, 2026

Saw this one and almost second-guessed myself because Data Guard sounds like it would "protect" data, but Data Guard is purely about high availability and disaster recovery, not about sensitive data classification, masking, or auditing for compliance. Data Safe is the one you want here, it covers security assessment, user assessment, data masking, and activity auditing specifically for regulated data in OCI database services.

4
Mateus R.Mateus R.Apr 26, 2026

Data Safe is the security vault for your database, it finds and masks sensitive data.

2
Orla P.Orla P.May 2, 2026

Saw this one on my actual exam back when I was prepping for the cloud foundations track, and I second-guessed myself for a solid minute because OCI Audit sounds like it has something to do with data protection. Once I remembered that Data Safe is the dedicated service for things like data discovery, masking, activity auditing, and user risk assessment across OCI database services, I locked in D and moved on without looking back.

0
Full 1Z0-1085-20 Practice