nerdexam
Oracle

1Z0-997-20 · Question #56

An insurance company is storing critical financial data in the OCI block volume. This volume is currently encrypted using oracle managed keys. Due to regulatory compliance, the customer wants to…

The correct answer is C. Create a vault, create a master encryption key in the vault, assign this master encryption key to the. Oracle Cloud Infrastructure Vault lets you centrally manage the encryption keys that protect your the secret credentials that you use to securely access resources. You can use the Vault service manage the following resources: Vaults securely store master encryption keys and…

Design for Security

Question

An insurance company is storing critical financial data in the OCI block volume. This volume is currently encrypted using oracle managed keys. Due to regulatory compliance, the customer wants to encrypt the data using the keys that they can control and not the keys which are controlled by Oracle. What of the following series of tasks are required to encrypt the block volume using customer managed keys?

Options

  • ACreate a vault, import your master encryption key into the vault, generate data encryption key,
  • BCreate a master encryption key, create a data encryption key, decrypt the block volume using
  • CCreate a vault, create a master encryption key in the vault, assign this master encryption key to the
  • DCreate a master encryption key, create a new version of the encryption key, decrypt the block

How the community answered

(65 responses)
  • A
    5% (3)
  • B
    6% (4)
  • C
    72% (47)
  • D
    17% (11)

Explanation

Oracle Cloud Infrastructure Vault lets you centrally manage the encryption keys that protect your the secret credentials that you use to securely access resources. You can use the Vault service manage the following resources: Vaults securely store master encryption keys and secrets that you might otherwise store in configuration files or in code. The Vault service lets you create vaults in your tenancy as containers for encryption keys and secrets. If needed, a virtual private vault provides you with a dedicated partition in a hardware security module (HSM), offering a level of storage isolation for encryption keys that's effectively equivalent to a virtual independent HSM.

Topics

#customer-managed keys#OCI Vault#block volume encryption#KMS workflow

Community Discussion

No community discussion yet for this question.

Full 1Z0-997-20 Practice