nerdexam
Oracle

1Z0-997-20 · Question #26

Your company will soon start moving critical systems Into Oracle Cloud Infrastructure (OCI) platform. These systems will reside in the us-phoenix-1and us-ashburn 1 regions. As part of the migration…

The correct answer is B. When you create a new block volume through OCI console, select Encrypt using Key Management D. When you create a new OCI Object Storage bucket through OCI console, you need to choose. Block Volume Encryption By default all volumes and their backups are encrypted using the Oracle-provided encryption keys. Each time a volume is cloned or restored from a backup the volume is assigned a new unique encryption key. You have the option to encrypt all of your…

Design for Security

Question

Your company will soon start moving critical systems Into Oracle Cloud Infrastructure (OCI) platform. These systems will reside in the us-phoenix-1and us-ashburn 1 regions. As part of the migration planning, you are reviewing the company's existing security policies and written guidelines for the OCI platform usage within the company. you have to work with the company managed key. Which two options ensure compliance with this policy?

Exhibit

1Z0-997-20 question #26 exhibit

Options

  • AWhen you create a new compute instance through OCI console, you use the default options for
  • BWhen you create a new block volume through OCI console, select Encrypt using Key Management
  • CWhen you create a new compute instance through OCI console, you use the default shape to
  • DWhen you create a new OCI Object Storage bucket through OCI console, you need to choose
  • EYou do not need to perform any additional actions because the OCI Block Volume service always

How the community answered

(38 responses)
  • A
    16% (6)
  • B
    71% (27)
  • C
    5% (2)
  • E
    8% (3)

Explanation

Block Volume Encryption By default all volumes and their backups are encrypted using the Oracle-provided encryption keys. Each time a volume is cloned or restored from a backup the volume is assigned a new unique encryption key. You have the option to encrypt all of your volumes and their backups using the keys that you own and manage using the Vault service.If you do not configure a volume to use the Vault service or unassign a key from the volume, the Block Volume service uses the Oracle-provided encryption This applies to both encryption at-rest and in-transit encryption. Object Storage Encryption Object Storage employs 256-bit Advanced Encryption Standard (AES-256) to encrypt object data on the server. Each object is encrypted with its own data encryption key. Data encryption keys are always encrypted with a master encryption key that is assigned to the bucket. Encryption is enabled by default and cannot be turned off. By default, Oracle manages the master encryption key. However, you can optionally configure a bucket so that it's assigned an Oracle Cloud Infrastructure Vault master encryption key that you control and rotate on your own schedule. Encryption: Buckets are encrypted with keys managed by Oracle by default, but you can optionally encrypt the data in this bucket using your own Vault encryption key. To use Vault for your encryption needs, select Encrypt Using Customer-Managed Keys. Then, select the Vault Compartment and Vault that contain the master encryption key you want to use. Also select the Master Encryption Key Compartment and Master Encryption Key.

Topics

#customer-managed keys#Key Management Service#block volume encryption#compliance

Community Discussion

No community discussion yet for this question.

Full 1Z0-997-20 Practice