nerdexam
Oracle

1Z0-997 · Question #88

An insurance company is storing critical financial data in the OCI block volume. This volume is currently encrypted using oracle managed keys. Due to regulatory compliance, the customer wants to…

The correct answer is C. Create a vault, create a master encryption key in the vault, assign this master encryption key to the block volume D. Create a master encryption key, create a. Explanation/Reference: Oracle Cloud Infrastructure Vault lets you centrally manage the encryption keys that protect your data and the secret credentials that you use to securely access resources. You can use the Vault service to create and manage the following resources: Vaults…

Design for Security

Question

An insurance company is storing critical financial data in the OCI block volume. This volume is currently encrypted using oracle managed keys. Due to regulatory compliance, the customer wants to encrypt the data using the keys that they can control and not the keys which are controlled by Oracle. What of the following series of tasks are required to encrypt the block volume using customer managed keys?

Options

  • ACreate a vault, import your master encryption key into the vault, generate data encryption key, assign data encryption key to the block volume
  • BCreate a master encryption key, create a data encryption key, decrypt the block volume using existing oracle managed keys, encrypt the block volume using
  • CCreate a vault, create a master encryption key in the vault, assign this master encryption key to the block volume D. Create a master encryption key, create a

How the community answered

(28 responses)
  • A
    21% (6)
  • B
    7% (2)
  • C
    71% (20)

Explanation

Explanation/Reference: Oracle Cloud Infrastructure Vault lets you centrally manage the encryption keys that protect your data and the secret credentials that you use to securely access resources. You can use the Vault service to create and manage the following resources: Vaults securely store master encryption keys and secrets that you might otherwise store in configuration files or in code. The Vault service lets you create vaults in your tenancy as containers for encryption keys and secrets. If needed, a virtual private vault provides you with a dedicated partition in a hardware security module (HSM), offering a level of storage isolation for encryption keys that's effectively equivalent to a virtual independent HSM.

Topics

#block volume encryption#customer-managed keys#OCI Vault#KMS

Community Discussion

No community discussion yet for this question.

Full 1Z0-997 Practice