Instructions
This standalone assessment is designed to test your knowledge of Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) across all 18 topics in the series.
Work through the scenario questions in Section 1 first without scrolling down. Once completed, compare your answers with the comprehensive Answer Key and Detailed Rationale in Section 2 at the bottom of this article.
Section 1: Scenario Questions
Topic 1: Tenancies, Compartments, and Resource Hierarchy
Question 1
An enterprise architect is designing an OCI compartment structure for 4 main departments. Each department needs nested sub-compartments for Dev, Test, Stage, and Prod. The Security Team requests adding 3 additional nested child levels inside Prod for microservice isolation. Will OCI support this hierarchy depth?
- A) Yes, OCI supports unlimited compartment nesting depth under the Root Tenancy.
- B) No, OCI limits compartment nesting to a maximum of 6 levels deep below the Root Tenancy.
- C) No, OCI only allows a flat compartment structure with 1 level of child compartments.
- D) Yes, but only if the tenancy is upgraded to Enterprise Premium Tier.
Question 2
You need to move an active, running Autonomous Database from Compartment-A to Compartment-B using the OCI Web Console. What impact does this move have on the active database workload?
- A) The database is stopped, moved to the new compartment, and automatically restarted.
- B) The database experiences 15 minutes of read-only failover downtime while IP addresses update.
- C) The database remains active and operational with zero downtime; only its IAM policy boundary changes.
- D) OCI denies moving database resources across compartments.
Question 3
An administrator attempts to delete a child compartment named Dev-Sandbox using the OCI Web Console. The compartment currently contains an empty, unused Virtual Cloud Network (VCN) and a stopped Compute instance. What will happen when the administrator clicks “Delete Compartment”?
- A) OCI automatically terminates the instance, deletes the VCN, and deletes the compartment.
- B) OCI blocks the compartment deletion until all contained resources are terminated or moved out first.
- C) OCI moves the VCN and Compute instance to the Root Tenancy and deletes the compartment.
- D) The compartment is marked as hidden, but remains active in the background.
Question 4
Which statement accurately describes the geographical scope of an OCI Compartment?
- A) A compartment is tied to a specific Availability Domain within a region.
- B) A compartment is tied to a single OCI Region and cannot contain resources from other regions.
- C) A compartment is a global construct that exists across all Availability Domains and OCI Regions in a tenancy.
- D) A compartment only exists in the home region of the tenancy.
Topic 2: Identity Domains, Policies, and Verbs
Question 5
A security policy statement is written as follows:
Allow group SecOps to use instance-family in compartment Production
What specific action is a user in the SecOps group CANNOT perform based on this policy?
- A) Start a stopped compute instance in
Production. - B) Reboot a running compute instance in
Production. - C) Terminate (delete) an existing compute instance in
Production. - D) Stop a running compute instance in
Production.
Question 6
An engineer wants to grant a group permissions to view compute instance details without allowing them to launch, stop, or delete instances. Which OCI policy verb should be used?
- A)
inspect - B)
read - C)
use - D)
manage
Question 7
A policy is attached to the Root Tenancy:
Allow group Auditing to read all-resources in tenancy
Sub-Compartment-B is nested 3 levels deep inside Parent-Compartment-A. What permissions does the Auditing group have in Sub-Compartment-B?
- A) None, because policies do not inherit down nested compartment trees automatically.
- B) Full administrative access (
manage), because root policies auto-escalate. - C) Read permissions for all resources, because root tenancy policies inherit down all nested compartments.
- D) Read permissions only if an explicit policy is also attached to
Sub-Compartment-B.
Question 8
An organization has an OCI tenancy with a Free tier Identity Domain and wants to create 5 separate secondary Identity Domains for different business units. What restriction applies?
- A) Secondary Identity Domains can only be created in
PremiumorExternal UserIdentity Domain types. - B) Free tier tenancies support up to 50 secondary Identity Domains out of the box.
- C) Secondary Identity Domains can only contain up to 5 users total.
- D) Secondary Identity Domains require setting up dedicated physical hardware servers.
Question 9
Which statement accurately differentiates the all-resources resource family from individual resource types in an OCI policy?
- A)
all-resourcesgrants access only to compute instances and block volumes. - B)
all-resourcesgrants administrative access across every existing and future OCI service type in the target compartment. - C)
all-resourcesis only valid when combined with theinspectverb. - D)
all-resourcescan only be applied at the Root Tenancy level.
Topic 3: Dynamic Groups, Instance Principals, and Network Sources
Question 10
An application running on an OCI Compute VM needs to read files from an OCI Object Storage bucket. Which mechanism allows the VM to authenticate without storing long-lived API keys or credentials on the disk?
- A) Assigning an IAM User password to the compute instance host OS.
- B) Configuring a Dynamic Group with a matching rule for the VM, and granting the Dynamic Group policy access via Instance Principals.
- C) Creating an SSH Key pair and saving the private key in
/etc/oci/keys. - D) Binding a GCP-style Service Account JSON key file to the virtual network interface.
Question 11
Which matching rule syntax correctly defines a Dynamic Group that includes all compute instances located in a compartment with OCID ocid1.compartment.oc1..abc12345?
- A)
All {instance.id = 'ocid1.compartment.oc1..abc12345'} - B)
Any {instance.compartment.id = 'ocid1.compartment.oc1..abc12345'} - C)
Include compartment 'ocid1.compartment.oc1..abc12345' - D)
Select instances where compartment == 'ocid1.compartment.oc1..abc12345'
Question 12
An administrator wants to restrict API access so that members of the Database-Admins group can only perform database management actions when connected from the corporate office public IP range (203.0.113.0/24). Which OCI IAM feature should be combined with an IAM policy?
- A) Security Lists
- B) Network Sources
- C) Network Security Groups (NSGs)
- D) Route Tables
Question 13
An OCI Function needs to write logs to an OCI Object Storage bucket. Which principal type should be referenced in the IAM policy statement?
- A) Instance Principal
- B) Resource Principal
- C) User Principal
- D) Service Account Principal
Topic 4: Identity Federation, Tagging, Security Zones, and Authentication
Question 14
An enterprise integrates Microsoft Entra ID (Azure AD) with OCI Identity Domains via SAML 2.0. When an external user logs in for the first time, their group membership in Entra ID must grant them access to OCI resources. What configuration is required inside the OCI Console?
- A) Creating duplicate local users manually in OCI before SSO will function.
- B) Mapping the external Entra ID group claim to an OCI Identity Domain Group.
- C) Assigning an API signing key to the SAML IdP metadata file.
- D) Disabling Multi-Factor Authentication on the root tenancy.
Question 15
An administrator wants to enforce tag-based governance so that developers can only manage compute instances tagged with Environment = Dev. Which policy condition syntax correctly implements this rule?
- A)
where target.resource.tag.Operations.Environment = 'Dev' - B)
where request.tag.Environment == 'Dev' - C)
if resource.hasTag('Dev') - D)
where compartment.tag = 'Dev'
Question 16
An architect creates a Security Zone compartment in OCI. A developer with full manage all-resources permissions attempts to create a public Object Storage bucket in that Security Zone. What will happen?
- A) The bucket is created as public, and a warning email is sent to Security.
- B) The security zone guardrail policy overrides IAM permissions and blocks the creation of the public bucket.
- C) The bucket is created as private, but automatically converts to public after 24 hours.
- D) The developer’s IAM account is immediately suspended.
Question 17
A developer needs to configure automated CLI scripts to interact with OCI APIs headlessly. Which credential type must be generated in the user profile inside the OCI Web Console?
- A) Auth Token
- B) API Signing Key (RSA 2048-bit public key)
- C) SMTP Credentials
- D) OAuth Password Grant
Question 18
An engineer needs to push container images to Oracle Cloud Infrastructure Registry (OCIR) via the Docker CLI (docker login). Which credential type generated in the OCI Console is required as the password?
- A) API Signing Key
- B) Auth Token
- C) Customer Secret Key
- D) Console Login Password
Topic 5: Cross-Tenancy Access and Audit Governance
Question 19
To grant Group-A in Tenancy-Source permission to manage object storage buckets in Tenancy-Destination, how many policy statements are required in total across both tenancies?
- A) 1 statement in
Tenancy-Sourceonly. - B) 2 statements: 1 in
Tenancy-Sourceand 1 inTenancy-Destination. - C) 3 statements:
DefineandEndorseinTenancy-Source, andDefineandAdmitinTenancy-Destination. - D) Cross-tenancy access is not supported in OCI.
Question 20
An auditor needs to review all administrative policy modification events that occurred across the tenancy over the past 90 days. Which OCI service automatically records these raw API calls?
- A) OCI Cloud Guard
- B) OCI Audit Service (
com.oraclecloud.iam.*events) - C) OCI Vulnerability Scanning Service
- D) OCI Logging Analytics
Question 21
An administrator creates a Network Source named CorpNetwork specifying a VCN private subnet CIDR (10.0.1.0/24). A user attempts to run OCI CLI commands from a VM inside that subnet, but the policy condition where request.networkSource.name = 'CorpNetwork' denies the request. What is the most likely cause?
- A) Network Sources only support public IP addresses, not private VCN subnets.
- B) Private VCN network sources require defining the VCN OCID alongside the subnet CIDR in the Network Source configuration.
- C) The user’s VM is missing an API signing key.
- D) Network sources cannot be used in policies attached to child compartments.
Section 2: Answer Key and Detailed Rationales
(Do not review this section until you have attempted all questions in Section 1 above.)
Answer Key
| Question # | Correct Answer | Topic |
|---|---|---|
| Question 1 | B | Tenancies & Compartments |
| Question 2 | C | Tenancies & Compartments |
| Question 3 | B | Tenancies & Compartments |
| Question 4 | C | Tenancies & Compartments |
| Question 5 | C | Policies & Verbs |
| Question 6 | B | Policies & Verbs |
| Question 7 | C | Policies & Verbs |
| Question 8 | A | Identity Domains |
| Question 9 | B | Policies & Resource Families |
| Question 10 | B | Dynamic Groups & Instance Principals |
| Question 11 | B | Dynamic Groups & Instance Principals |
| Question 12 | B | Network Sources |
| Question 13 | B | Resource Principals |
| Question 14 | B | Identity Federation |
| Question 15 | A | Tag-Based Access Control (TBAC) |
| Question 16 | B | Security Zones & Guardrails |
| Question 17 | B | Programmatic Authentication |
| Question 18 | B | Programmatic Authentication |
| Question 19 | C | Cross-Tenancy Access |
| Question 20 | B | Audit & Security Posture |
| Question 21 | B | Network Sources |
Detailed Rationales
Question 1 Rationale
- Correct Answer: B
- Explanation: OCI enforces a platform constraint of 6 levels of nested compartments below the root tenancy. A hierarchy requiring 7 or more nested child levels will be rejected by the OCI API.
Question 2 Rationale
- Correct Answer: C
- Explanation: Moving a resource between compartments updates the logical pointer in the OCI Control Plane. It does NOT interrupt database execution, change IP addresses, or disconnect active client connections.
Question 3 Rationale
- Correct Answer: B
- Explanation: OCI blocks compartment deletion if the compartment contains any active cloud resources. All resources must be terminated or moved out before OCI allows the compartment to be deleted.
Question 4 Rationale
- Correct Answer: C
- Explanation: Compartments are global administrative boundaries. A single compartment spans all Availability Domains and OCI Regions within a tenancy.
Question 5 Rationale
- Correct Answer: C
- Explanation: The
useverb allows users to work with existing resources (start, stop, reboot VMs), but does NOT grant permission to create or delete (terminate) resources. Creating or deleting resources requires themanageverb.
Question 6 Rationale
- Correct Answer: B
- Explanation: The
readverb includesinspectrights plus the ability to view detailed configuration metadata. It does not allow modifying, starting, stopping, or deleting the resource (which requiresuseormanage).
Question 7 Rationale
- Correct Answer: C
- Explanation: IAM policies attached at higher levels in the hierarchy (such as the Root Tenancy) automatically inherit down all nested child compartments in the tree.
Question 8 Rationale
- Correct Answer: A
- Explanation: OCI Identity Domain types dictate feature availability. Creating custom secondary identity domains for advanced user partitioning requires upgrading to
PremiumorExternal Useridentity domain types.
Question 9 Rationale
- Correct Answer: B
- Explanation:
all-resourcesis the universal resource family covering every OCI service type. Grantingmanage all-resourcesprovides full administrative control over all current and future resources in the target compartment.
Question 10 Rationale
- Correct Answer: B
- Explanation: OCI uses Dynamic Groups and Instance Principals to authenticate compute workloads. VMs obtain short-lived cryptographic tokens directly from the local Instance Metadata Service (IMDSv2), eliminating on-disk API keys.
Question 11 Rationale
- Correct Answer: B
- Explanation: The correct OCI rule syntax for grouping instances by compartment is
Any {instance.compartment.id = 'ocid1.compartment.oc1...'}.
Question 12 Rationale
- Correct Answer: B
- Explanation: Network Sources allow administrators to define a set of public or private IP addresses and reference them in IAM policy
whereclauses (where request.networkSource.name = 'CorpNetwork').
Question 13 Rationale
- Correct Answer: B
- Explanation: Serverless services like OCI Functions, Cloud Shell, and OKE Pods authenticate via Resource Principals, which issue temporary JWT session tokens directly to the executing runtime.
Question 14 Rationale
- Correct Answer: B
- Explanation: In SAML 2.0 federation, external IdP group claims (e.g., Entra ID groups) must be mapped to OCI Identity Domain Groups inside the Console so federated users inherit the appropriate OCI policy permissions upon login.
Question 15 Rationale
- Correct Answer: A
- Explanation: Tag-Based Access Control requires specifying the tag namespace and key in the policy condition:
where target.resource.tag.<Namespace>.<Key> = 'Value'.
Question 16 Rationale
- Correct Answer: B
- Explanation: OCI Security Zones enforce strict kernel-level security recipes (e.g., preventing public storage buckets or unencrypted volumes). Security Zone guardrails override standard IAM policies, blocking any non-compliant action regardless of user privileges.
Question 17 Rationale
- Correct Answer: B
- Explanation: OCI CLI and SDK automated scripts require uploading an API Signing Key (RSA 2048-bit public key) to the user’s OCI Profile for request signing.
Question 18 Rationale
- Correct Answer: B
- Explanation: Authenticating with Oracle Cloud Infrastructure Registry (OCIR) via Third-Party tools (like Docker CLI or Helm) requires using an Auth Token generated in the user profile as the login password.
Question 19 Rationale
- Correct Answer: C
- Explanation: Cross-tenancy access requires explicit statements in both tenancies:
Define tenancyandEndorse groupin the source tenancy, andDefine tenancy,Define group, andAdmit groupin the destination tenancy.
Question 20 Rationale
- Correct Answer: B
- Explanation: The OCI Audit Service automatically logs all raw API calls, console actions, and IAM policy changes across the tenancy, retaining events under the
com.oraclecloud.iam.*namespace.
Question 21 Rationale
- Correct Answer: B
- Explanation: When defining a Network Source for private VCN subnets, OCI requires specifying both the VCN OCID and the subnet CIDR block; specifying only the CIDR block causes policy evaluation failure for private VCN traffic.

