exam questions

Exam 1z0-1072-20 All Questions

View all questions & answers for the 1z0-1072-20 exam

Exam 1z0-1072-20 topic 1 question 6 discussion

Actual exam question from Oracle's 1z0-1072-20
Question #: 6
Topic #: 1
[All 1z0-1072-20 Questions]

You need to set up instance principals so that an application running on an instance can call Oracle Cloud Infrastructure (OCI) public services, without the need to configure user credentials.
A developer in your team has already configured the application built using an OCI SDK to authenticate using the instance principals provider.
Which is NOT a necessary step to complete this set up?

  • A. Create a dynamic group with matching rules to specify which instances you want to allow to make API calls against services.
  • B. Generate Auth Tokens to enable instances in the dynamic group to authenticate with APIs.
  • C. Create a policy granting permissions to the dynamic group to access services in your compartment or tenancy.
  • D. Deploy the application and the SDK to all the instances that belong to the dynamic group.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
alfonso_223
Highly Voted 4 years, 5 months ago
The correct answer is B Create a dynamic group. In the dynamic group definition, you provide the matching rules to specify which instances you want to allow to make API calls against services. Create a policy granting permissions to the dynamic group to access services in your tenancy (or compartment). A developer in your organization configures the application built using the Oracle Cloud Infrastructure SDK to authenticate using the instance principals provider. The developer deploys the application and the SDK to all the instances that belong to the dynamic group. https://docs.cloud.oracle.com/en-us/iaas/Content/Identity/Tasks/callingservicesfrominstances.htm
upvoted 26 times
...
SlawekSz
Highly Voted 4 years, 4 months ago
B is correct. See https://blogs.oracle.com/cloud-infrastructure/announcing-instance-principals-for-identity-and-access-management
upvoted 7 times
...
dimplechks
Most Recent 3 years ago
The correct answer is B The following steps summarize the process flow for setting up and using instances as principals. The subsequent sections provide more details. * Create a dynamic group. In the dynamic group definition, you provide the matching rules to specify which instances you want to allow to make API calls against services. * Create a policy granting permissions to the dynamic group to access services in your tenancy (or compartment). * A developer in your organization configures the application built using the Oracle Cloud Infrastructure SDK to authenticate using the instance principals provider. The developer deploys the application and the SDK to all the instances that belong to the dynamic group. * The deployed SDK makes calls to Oracle Cloud Infrastructure APIs as allowed by the policy (without needing to configure API credentials). * For each API call made by an instance, the Audit service logs the event, recording the OCID of the instance as the value of the principal Id in the event log.
upvoted 2 times
...
Mtrx
3 years, 4 months ago
Selected Answer: B
B is correct.
upvoted 1 times
...
30th
3 years, 4 months ago
Selected Answer: B
Auth Tokens are to use, when the usage of dynamic groups and instance authentication in not possible (for example a third-party application).
upvoted 2 times
...
sauka
3 years, 4 months ago
You all are missing the keyword "NOT" from this question
upvoted 2 times
...
MarianoD
3 years, 5 months ago
Steps to Enable Instances to Call Services: FROM: https://docs.oracle.com/en-us/iaas/Content/Identity/Tasks/callingservicesfrominstances.htm 1 - Create a Dynamic Group and Matching Rules 2 - Write Policies for Dynamic Groups 3 - Configure the SDK, CLI, or Terraform dude
upvoted 2 times
...
BKRV
3 years, 6 months ago
Selected Answer: A
From Oracle documentation: Dynamic groups allow you to group Oracle Cloud Infrastructure instances as principal actors, similar to user groups. You can then create policies to permit instances in these groups to make API calls against Oracle Cloud Infrastructure services. https://docs.oracle.com/en-us/iaas/Content/Identity/Tasks/callingservicesfrominstances.htm
upvoted 1 times
EmilioM
3 years, 4 months ago
Q ask "Which is NOT a necessary step..."
upvoted 2 times
...
...
acarugat
3 years, 6 months ago
Sure: "B" is the correct answer! Another WRONG solution !!! (we've reached 5 out of 6 WRONG solutions !!!)
upvoted 2 times
...
GbengaCruz
3 years, 8 months ago
The correct answer is A https://docs.oracle.com/en-us/iaas/Content/Identity/Tasks/managingdynamicgroups.htm
upvoted 1 times
...
Ramesh111
3 years, 11 months ago
the question is "which is not required" So answer may not be B
upvoted 2 times
...
vlad_74
3 years, 11 months ago
you do not have to create any 2FA token for instance principles to work.
upvoted 1 times
...
nxt_RTX5
4 years, 3 months ago
A is the correct answer: Create a dynamic group. In the dynamic group definition, you provide the matching rules to specify which instances you want to allow to make API calls against services. See process overview: https://docs.oracle.com/en-us/iaas/Content/Identity/Tasks/callingservicesfrominstances.htm
upvoted 2 times
nxt_RTX5
4 years, 3 months ago
Sorry, it is B!
upvoted 4 times
...
...
omid25
4 years, 4 months ago
B is correct
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago