Article 19 – OCI IAM Comprehensive Knowledge Assessment and Scenario Guide

Instructions

This standalone assessment is designed to test your knowledge of Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) across all 18 topics in the series.

Work through the scenario questions in Section 1 first without scrolling down. Once completed, compare your answers with the comprehensive Answer Key and Detailed Rationale in Section 2 at the bottom of this article.

Section 1: Scenario Questions
Topic 1: Tenancies, Compartments, and Resource Hierarchy
Question 1

An enterprise architect is designing an OCI compartment structure for 4 main departments. Each department needs nested sub-compartments for Dev, Test, Stage, and Prod. The Security Team requests adding 3 additional nested child levels inside Prod for microservice isolation. Will OCI support this hierarchy depth?

  • A) Yes, OCI supports unlimited compartment nesting depth under the Root Tenancy.
  • B) No, OCI limits compartment nesting to a maximum of 6 levels deep below the Root Tenancy.
  • C) No, OCI only allows a flat compartment structure with 1 level of child compartments.
  • D) Yes, but only if the tenancy is upgraded to Enterprise Premium Tier.
Question 2

You need to move an active, running Autonomous Database from Compartment-A to Compartment-B using the OCI Web Console. What impact does this move have on the active database workload?

  • A) The database is stopped, moved to the new compartment, and automatically restarted.
  • B) The database experiences 15 minutes of read-only failover downtime while IP addresses update.
  • C) The database remains active and operational with zero downtime; only its IAM policy boundary changes.
  • D) OCI denies moving database resources across compartments.
Question 3

An administrator attempts to delete a child compartment named Dev-Sandbox using the OCI Web Console. The compartment currently contains an empty, unused Virtual Cloud Network (VCN) and a stopped Compute instance. What will happen when the administrator clicks “Delete Compartment”?

  • A) OCI automatically terminates the instance, deletes the VCN, and deletes the compartment.
  • B) OCI blocks the compartment deletion until all contained resources are terminated or moved out first.
  • C) OCI moves the VCN and Compute instance to the Root Tenancy and deletes the compartment.
  • D) The compartment is marked as hidden, but remains active in the background.
Question 4

Which statement accurately describes the geographical scope of an OCI Compartment?

  • A) A compartment is tied to a specific Availability Domain within a region.
  • B) A compartment is tied to a single OCI Region and cannot contain resources from other regions.
  • C) A compartment is a global construct that exists across all Availability Domains and OCI Regions in a tenancy.
  • D) A compartment only exists in the home region of the tenancy.
Topic 2: Identity Domains, Policies, and Verbs
Question 5

A security policy statement is written as follows:
Allow group SecOps to use instance-family in compartment Production

What specific action is a user in the SecOps group CANNOT perform based on this policy?

  • A) Start a stopped compute instance in Production.
  • B) Reboot a running compute instance in Production.
  • C) Terminate (delete) an existing compute instance in Production.
  • D) Stop a running compute instance in Production.
Question 6

An engineer wants to grant a group permissions to view compute instance details without allowing them to launch, stop, or delete instances. Which OCI policy verb should be used?

  • A) inspect
  • B) read
  • C) use
  • D) manage
Question 7

A policy is attached to the Root Tenancy:
Allow group Auditing to read all-resources in tenancy

Sub-Compartment-B is nested 3 levels deep inside Parent-Compartment-A. What permissions does the Auditing group have in Sub-Compartment-B?

  • A) None, because policies do not inherit down nested compartment trees automatically.
  • B) Full administrative access (manage), because root policies auto-escalate.
  • C) Read permissions for all resources, because root tenancy policies inherit down all nested compartments.
  • D) Read permissions only if an explicit policy is also attached to Sub-Compartment-B.
Question 8

An organization has an OCI tenancy with a Free tier Identity Domain and wants to create 5 separate secondary Identity Domains for different business units. What restriction applies?

  • A) Secondary Identity Domains can only be created in Premium or External User Identity Domain types.
  • B) Free tier tenancies support up to 50 secondary Identity Domains out of the box.
  • C) Secondary Identity Domains can only contain up to 5 users total.
  • D) Secondary Identity Domains require setting up dedicated physical hardware servers.
Question 9

Which statement accurately differentiates the all-resources resource family from individual resource types in an OCI policy?

  • A) all-resources grants access only to compute instances and block volumes.
  • B) all-resources grants administrative access across every existing and future OCI service type in the target compartment.
  • C) all-resources is only valid when combined with the inspect verb.
  • D) all-resources can only be applied at the Root Tenancy level.
Topic 3: Dynamic Groups, Instance Principals, and Network Sources
Question 10

An application running on an OCI Compute VM needs to read files from an OCI Object Storage bucket. Which mechanism allows the VM to authenticate without storing long-lived API keys or credentials on the disk?

  • A) Assigning an IAM User password to the compute instance host OS.
  • B) Configuring a Dynamic Group with a matching rule for the VM, and granting the Dynamic Group policy access via Instance Principals.
  • C) Creating an SSH Key pair and saving the private key in /etc/oci/keys.
  • D) Binding a GCP-style Service Account JSON key file to the virtual network interface.
Question 11

Which matching rule syntax correctly defines a Dynamic Group that includes all compute instances located in a compartment with OCID ocid1.compartment.oc1..abc12345?

  • A) All {instance.id = 'ocid1.compartment.oc1..abc12345'}
  • B) Any {instance.compartment.id = 'ocid1.compartment.oc1..abc12345'}
  • C) Include compartment 'ocid1.compartment.oc1..abc12345'
  • D) Select instances where compartment == 'ocid1.compartment.oc1..abc12345'
Question 12

An administrator wants to restrict API access so that members of the Database-Admins group can only perform database management actions when connected from the corporate office public IP range (203.0.113.0/24). Which OCI IAM feature should be combined with an IAM policy?

  • A) Security Lists
  • B) Network Sources
  • C) Network Security Groups (NSGs)
  • D) Route Tables
Question 13

An OCI Function needs to write logs to an OCI Object Storage bucket. Which principal type should be referenced in the IAM policy statement?

  • A) Instance Principal
  • B) Resource Principal
  • C) User Principal
  • D) Service Account Principal
Topic 4: Identity Federation, Tagging, Security Zones, and Authentication
Question 14

An enterprise integrates Microsoft Entra ID (Azure AD) with OCI Identity Domains via SAML 2.0. When an external user logs in for the first time, their group membership in Entra ID must grant them access to OCI resources. What configuration is required inside the OCI Console?

  • A) Creating duplicate local users manually in OCI before SSO will function.
  • B) Mapping the external Entra ID group claim to an OCI Identity Domain Group.
  • C) Assigning an API signing key to the SAML IdP metadata file.
  • D) Disabling Multi-Factor Authentication on the root tenancy.
Question 15

An administrator wants to enforce tag-based governance so that developers can only manage compute instances tagged with Environment = Dev. Which policy condition syntax correctly implements this rule?

  • A) where target.resource.tag.Operations.Environment = 'Dev'
  • B) where request.tag.Environment == 'Dev'
  • C) if resource.hasTag('Dev')
  • D) where compartment.tag = 'Dev'
Question 16

An architect creates a Security Zone compartment in OCI. A developer with full manage all-resources permissions attempts to create a public Object Storage bucket in that Security Zone. What will happen?

  • A) The bucket is created as public, and a warning email is sent to Security.
  • B) The security zone guardrail policy overrides IAM permissions and blocks the creation of the public bucket.
  • C) The bucket is created as private, but automatically converts to public after 24 hours.
  • D) The developer’s IAM account is immediately suspended.
Question 17

A developer needs to configure automated CLI scripts to interact with OCI APIs headlessly. Which credential type must be generated in the user profile inside the OCI Web Console?

  • A) Auth Token
  • B) API Signing Key (RSA 2048-bit public key)
  • C) SMTP Credentials
  • D) OAuth Password Grant
Question 18

An engineer needs to push container images to Oracle Cloud Infrastructure Registry (OCIR) via the Docker CLI (docker login). Which credential type generated in the OCI Console is required as the password?

  • A) API Signing Key
  • B) Auth Token
  • C) Customer Secret Key
  • D) Console Login Password
Topic 5: Cross-Tenancy Access and Audit Governance
Question 19

To grant Group-A in Tenancy-Source permission to manage object storage buckets in Tenancy-Destination, how many policy statements are required in total across both tenancies?

  • A) 1 statement in Tenancy-Source only.
  • B) 2 statements: 1 in Tenancy-Source and 1 in Tenancy-Destination.
  • C) 3 statements: Define and Endorse in Tenancy-Source, and Define and Admit in Tenancy-Destination.
  • D) Cross-tenancy access is not supported in OCI.
Question 20

An auditor needs to review all administrative policy modification events that occurred across the tenancy over the past 90 days. Which OCI service automatically records these raw API calls?

  • A) OCI Cloud Guard
  • B) OCI Audit Service (com.oraclecloud.iam.* events)
  • C) OCI Vulnerability Scanning Service
  • D) OCI Logging Analytics
Question 21

An administrator creates a Network Source named CorpNetwork specifying a VCN private subnet CIDR (10.0.1.0/24). A user attempts to run OCI CLI commands from a VM inside that subnet, but the policy condition where request.networkSource.name = 'CorpNetwork' denies the request. What is the most likely cause?

  • A) Network Sources only support public IP addresses, not private VCN subnets.
  • B) Private VCN network sources require defining the VCN OCID alongside the subnet CIDR in the Network Source configuration.
  • C) The user’s VM is missing an API signing key.
  • D) Network sources cannot be used in policies attached to child compartments.
Section 2: Answer Key and Detailed Rationales

(Do not review this section until you have attempted all questions in Section 1 above.)

Answer Key
Question #Correct AnswerTopic
Question 1BTenancies & Compartments
Question 2CTenancies & Compartments
Question 3BTenancies & Compartments
Question 4CTenancies & Compartments
Question 5CPolicies & Verbs
Question 6BPolicies & Verbs
Question 7CPolicies & Verbs
Question 8AIdentity Domains
Question 9BPolicies & Resource Families
Question 10BDynamic Groups & Instance Principals
Question 11BDynamic Groups & Instance Principals
Question 12BNetwork Sources
Question 13BResource Principals
Question 14BIdentity Federation
Question 15ATag-Based Access Control (TBAC)
Question 16BSecurity Zones & Guardrails
Question 17BProgrammatic Authentication
Question 18BProgrammatic Authentication
Question 19CCross-Tenancy Access
Question 20BAudit & Security Posture
Question 21BNetwork Sources
Detailed Rationales
Question 1 Rationale
  • Correct Answer: B
  • Explanation: OCI enforces a platform constraint of 6 levels of nested compartments below the root tenancy. A hierarchy requiring 7 or more nested child levels will be rejected by the OCI API.
Question 2 Rationale
  • Correct Answer: C
  • Explanation: Moving a resource between compartments updates the logical pointer in the OCI Control Plane. It does NOT interrupt database execution, change IP addresses, or disconnect active client connections.
Question 3 Rationale
  • Correct Answer: B
  • Explanation: OCI blocks compartment deletion if the compartment contains any active cloud resources. All resources must be terminated or moved out before OCI allows the compartment to be deleted.
Question 4 Rationale
  • Correct Answer: C
  • Explanation: Compartments are global administrative boundaries. A single compartment spans all Availability Domains and OCI Regions within a tenancy.
Question 5 Rationale
  • Correct Answer: C
  • Explanation: The use verb allows users to work with existing resources (start, stop, reboot VMs), but does NOT grant permission to create or delete (terminate) resources. Creating or deleting resources requires the manage verb.
Question 6 Rationale
  • Correct Answer: B
  • Explanation: The read verb includes inspect rights plus the ability to view detailed configuration metadata. It does not allow modifying, starting, stopping, or deleting the resource (which requires use or manage).
Question 7 Rationale
  • Correct Answer: C
  • Explanation: IAM policies attached at higher levels in the hierarchy (such as the Root Tenancy) automatically inherit down all nested child compartments in the tree.
Question 8 Rationale
  • Correct Answer: A
  • Explanation: OCI Identity Domain types dictate feature availability. Creating custom secondary identity domains for advanced user partitioning requires upgrading to Premium or External User identity domain types.
Question 9 Rationale
  • Correct Answer: B
  • Explanation: all-resources is the universal resource family covering every OCI service type. Granting manage all-resources provides full administrative control over all current and future resources in the target compartment.
Question 10 Rationale
  • Correct Answer: B
  • Explanation: OCI uses Dynamic Groups and Instance Principals to authenticate compute workloads. VMs obtain short-lived cryptographic tokens directly from the local Instance Metadata Service (IMDSv2), eliminating on-disk API keys.
Question 11 Rationale
  • Correct Answer: B
  • Explanation: The correct OCI rule syntax for grouping instances by compartment is Any {instance.compartment.id = 'ocid1.compartment.oc1...'}.
Question 12 Rationale
  • Correct Answer: B
  • Explanation: Network Sources allow administrators to define a set of public or private IP addresses and reference them in IAM policy where clauses (where request.networkSource.name = 'CorpNetwork').
Question 13 Rationale
  • Correct Answer: B
  • Explanation: Serverless services like OCI Functions, Cloud Shell, and OKE Pods authenticate via Resource Principals, which issue temporary JWT session tokens directly to the executing runtime.
Question 14 Rationale
  • Correct Answer: B
  • Explanation: In SAML 2.0 federation, external IdP group claims (e.g., Entra ID groups) must be mapped to OCI Identity Domain Groups inside the Console so federated users inherit the appropriate OCI policy permissions upon login.
Question 15 Rationale
  • Correct Answer: A
  • Explanation: Tag-Based Access Control requires specifying the tag namespace and key in the policy condition: where target.resource.tag.<Namespace>.<Key> = 'Value'.
Question 16 Rationale
  • Correct Answer: B
  • Explanation: OCI Security Zones enforce strict kernel-level security recipes (e.g., preventing public storage buckets or unencrypted volumes). Security Zone guardrails override standard IAM policies, blocking any non-compliant action regardless of user privileges.
Question 17 Rationale
  • Correct Answer: B
  • Explanation: OCI CLI and SDK automated scripts require uploading an API Signing Key (RSA 2048-bit public key) to the user’s OCI Profile for request signing.
Question 18 Rationale
  • Correct Answer: B
  • Explanation: Authenticating with Oracle Cloud Infrastructure Registry (OCIR) via Third-Party tools (like Docker CLI or Helm) requires using an Auth Token generated in the user profile as the login password.
Question 19 Rationale
  • Correct Answer: C
  • Explanation: Cross-tenancy access requires explicit statements in both tenancies: Define tenancy and Endorse group in the source tenancy, and Define tenancy, Define group, and Admit group in the destination tenancy.
Question 20 Rationale
  • Correct Answer: B
  • Explanation: The OCI Audit Service automatically logs all raw API calls, console actions, and IAM policy changes across the tenancy, retaining events under the com.oraclecloud.iam.* namespace.
Question 21 Rationale
  • Correct Answer: B
  • Explanation: When defining a Network Source for private VCN subnets, OCI requires specifying both the VCN OCID and the subnet CIDR block; specifying only the CIDR block causes policy evaluation failure for private VCN traffic.