FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • IBM
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • ISC
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • IBM
    IBM
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • ISC
    ISC
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. Oracle Certification
  3. 1z0-1104-23 Exam
  4. Oracle.1z0-1104-23.v2024-05-06.q91 Dumps
  • ««
  • «
  • …
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • …
  • »
  • »»
Download Now

Question 41

On which option do you set Oracle Cloud Infrastructure Budget?

Correct Answer: A
How Budgets Work
Budgets are set on cost-tracking tags or on compartments (including theroot compartment) to track all spending in that cost-tracking tag or for that compartment and its children.
https://docs.oracle.com/en-us/iaas/Content/Billing/Concepts/budgetsoverview.htm
insert code

Question 42

Which components are a part of the OCI Identity and Access Management service?

Correct Answer: A
Explanation
https://docs.oracle.com/en-us/iaas/Content/Identity/Concepts/overview.htm
insert code

Question 43

With regard to OCI Audit Log Service, which of the statement is INCORRECT?

Correct Answer: A
Explanation
The retention period for audit events in OCI Audit Log Service is 365 days and currently, it cannot be modified. The Audit service automatically retains logged events for 365 days (1 year). After that, they're automatically deleted. You can't modify this retention period.
insert code

Question 44

Challenge 4 - Task 5 of 6
Configure Web Application Firewall to Protect Web Server Against XSS Attack Scenario You have to protect web applications hosted on OCI from cross-site scripting (XSS) attacks. You can use the OCI Web Application Firewall (WAF) capabilities to create rules that compare against incoming requests to determine if the request contains an XSS attack payload. If a request is determined to be an attack, WAF should return the HTTP Service Unavailable (503) error.
To ensure that the configured WAF blocks the XSS attack, run the following script: [http://<public- ip-enforcement-point>/index.html?<p style="background:url(javascript:alert(1))"](http://<public- ip-enforcement-point>/index.html?<p style="background:url(javascript:alert(1))">) To complete this deployment, you have to perform the following tasks in the environment provisioned for you:
Configure a Virtual Cloud Network (VCN)
Create a Compute Instance and install the Web Server
Create a Load Balancer and update Security List
Create a WAF policy
Configure Protection Rules against XSS attacks
Verify the created environment against XSS attacks

Note: You are provided with access to an OCI Tenancy, an assigned compartment, and OCI credentials. Throughout your exam, ensure to use the assigned Compartment 99233424-C01 and Region us-ashburn-1.
Complete the following task in the provisioned OCI environment:
1. Create a Protection Rule with name WAF-PBT-XSS-Protection against XSS attack. for protecting web server
2. Create a New Rule Action with name WAF-PBT-XSS-Action where http response code will be 503 (Service Unavailable).

Correct Answer:
See the solution below in Explanation
Explanation:
SOLUTION:
From the navigation menu, select Identity & Security. Navigate to Web Application Firewall and click Policies under it.
In the left navigation pane, under List Scope, select the working compartment from the drop-down menu.
Click the IAD-SP-PBT-WAF-01_99233424-lab.user01 WAF policy to add a protection rule.
On the policy details page, click Protections under Policy.
In the Protection section on the console, click Manage request protection rules.
Click Add Request Protection Rule.
In the Add protection rule dialog box, enter the following details:
a) Name: WAF-PBT-XSS-Protection
b) Conditions: Do not add any condition.
c) Under Rule action - Action name: Select Create New Action from the drop-down menu.
In the Add Action dialog box, enter the following details:
a) Name: WAF-PBT-XSS-Action
b) Type: Return HTTP Response
c) Response code: Select "503 Service unavailable" from the drop-down menu.
d) Response page body: Type "Service Unavailable: Web Server is secured against XSS attacks." e) Click Add action.
Under Protection Capabilities, click Choose protection capabilities.
In the Choose protection capabilities dialog box, complete the following:
a) Filter by tags: Type "xss" and press Enter.
b) Filter by version: Latest
c) Protection list: Check all protections. Select the check box in the header to add all.
d) Click Choose protection capabilities.
e) Review and click Add request protection rule.
f) Click Save Changes in the Manage Request Protection Rules dialog box.
The rule you created appears in the list. The WAF policy will update and get back to Active state.
insert code

Question 45

Which statement is true about origin management in WAF?
Statement A: Multiple origins can be defined.
Statement B: Only a single origin can be active fora WAF.

Correct Answer: D
Statement A: Multiple origins can be defined1. This is true. In Oracle Cloud Infrastructure's Web Application Firewall (WAF), multiple origins can be defined for a WAF policy using Origin Groups1. When at least two origins are configured, load balancing is enabled1.
Statement B: Only a single origin can be active for a WAF2. This is false. In the Origin Settings of the WAF policy, all origins are active under origin groups2.
insert code
  • ««
  • «
  • …
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download Oracle.1z0-1104-23.v2024-05-06.q91 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.