Three full-length practice tests for the Oracle Cloud Infrastructure Security Professional (1Z0-1104-26) certification exam - 50 questions per test, 90 minutes, 68% to pass, unlimited retakes.
Every question is grounded in Oracle's official exam objectives and product documentation - written fresh for this course, not recycled from public dumps.
What you'll be tested on
- Identity and Access Management: policies, dynamic groups, and federation
- Network security: security lists, NSGs, WAF, and DDoS protection
- OS and workload protection: Bastion, vulnerability scanning, and OS Management
- Data security: Vault, encryption keys, and Data Safe
- Security monitoring: Cloud Guard, Security Zones, and Logging Analytics
- Compliance, governance, and incident response on OCI
Where candidates lose points
This exam is scenario- and configuration-heavy rather than a pure recall test, so the domains where candidates lose the most ground are the ones with the most moving parts to configure correctly: dynamic group matching rules and policy statements in IAM, and Vault key management (customer-managed versus Oracle-managed keys, rotation, and how Data Safe interacts with encrypted data). Cloud Guard responder recipes and Security Zone policies are the other common gap, since they require understanding how detection rules translate into automated remediation, not just what the service does.
Sample question
A dynamic group needs to match all compute instances in a specific compartment that also carry a defined freeform tag. Which matching rule correctly combines both conditions?
- A.
Any {instance.compartment.id = '<compartment_ocid>', tag.namespace.tagkey.value = '<value>'} - B.
All {instance.compartment.id = '<compartment_ocid>', tag.namespace.tagkey.value = '<value>'} - C.
instance.compartment.id = '<compartment_ocid>' OR tag.namespace.tagkey.value = '<value>' - D. A single rule cannot combine a compartment condition with a tag condition; two separate dynamic groups are required
Full explanations and 149 more questions like this are in the practice tests.
How long to prepare
Given the exam's hands-on, performance-based framing, 3-5 weeks of study that includes actually configuring IAM policies, Vault keys, and a Cloud Guard target is a reasonable target for someone with general OCI experience. Reading service documentation alone, without building anything, is unlikely to be enough at the 68% pass mark.

