1Z0-1104-25 Oracle Cloud Infrastructure 2025 Security Professional Exam Guide
The 1Z0-1104-25 exam validates practical knowledge of using OCI core security services to build and maintain secure cloud environments. Oracle identifies security professionals, solution architects, IT administrators, cloud engineers, and other OCI security practitioners as its audience. This guide helps you decide whether your current IAM, network, workload, data-protection, and security-posture knowledge is ready for structured preparation, hands-on practice, and an exam appointment.
What does 1Z0-1104-25 validate?
1Z0-1104-25 is Oracle’s Oracle Cloud Infrastructure 2025 Security Professional exam. Its purpose is to assess security capability across the OCI services and practices used to protect applications and resources, rather than simply testing isolated product definitions.
Oracle announced the OCI 2025 Security Professional certification and course on March 17, 2025. The certification is aimed at people who design, administer, operate, or secure OCI environments. That makes the credential relevant to both hands-on cloud practitioners and architects who must select and explain appropriate security controls.
The exam’s subject matter reflects a security lifecycle: establish identity and access controls, protect network paths, secure operating systems and workloads, protect data, and monitor or improve the overall security posture. A candidate should therefore prepare to reason about control placement and operational consequences, not only memorize service names.
Who should consider this certification?
The strongest candidates are professionals who already understand OCI foundations and can connect security requirements to OCI implementation choices. Oracle names security professionals, solution architects, IT administrators, cloud engineers, and others responsible for securing OCI environments as the intended audience.
Oracle’s associated learning path lists foundational OCI understanding plus basic cloud-computing and security knowledge as prerequisites. These are preparation expectations rather than a separate prerequisite approval process stated for the exam. If you cannot yet explain compartments, policies, virtual cloud networks, compute resources, and common cloud-security principles, begin with those fundamentals before moving into specialist services.
Use your job responsibilities to decide how deeply to study each area. An administrator may need repeated console and policy practice; an architect may need more scenario comparison; a security specialist may need to connect identity, network, workload, data, and posture controls into a defensible design.
Which skills should your study plan cover?
Oracle describes the 2025 course as structured around five key domains. The learning path identifies those areas as IAM, network security, OS and workload protection, data protection, and maintaining security posture. These five labels should become the backbone of your notes and readiness checks.
IAM includes the identity and access decisions that determine who or what can act on OCI resources. Study policy interpretation, resource scope, least privilege, and the distinction between human access and workload access. Oracle’s 2025 updates specifically include IAM Optimization and Object IAM, so do not limit preparation to older policy examples.
Network security concerns how traffic is allowed, restricted, inspected, and routed. Oracle lists Zero Trust Packet Routing among the 2025 course updates. Study network controls as a chain: source, destination, route, security rule, inspection point, and application requirement. When troubleshooting, change one control at a time and record the expected traffic path.
OS and workload protection covers securing the systems and workloads that run applications. Oracle identifies OS Management Hub as a 2025 course update. Prepare to reason about patching, host administration, workload exposure, and the relationship between infrastructure configuration and application risk.
Data protection focuses on protecting sensitive information through appropriate security services and access controls. Include secrets, certificates, encryption-related responsibilities, and access to stored data in your study map. The preparation course specifically provides walkthroughs for OCI Certificates and Vault Secret.
Maintaining security posture requires visibility, review, and remediation. Oracle lists troubleshooting OCI security issues as part of the 2025 updates. Practice moving from a finding or symptom to evidence, likely cause, corrective control, and verification step rather than treating posture management as a static checklist.
How should you use the five domains?
Create one page for each official domain and add four columns: objective, OCI service or feature, implementation action, and failure symptom. This format forces you to connect terminology with a security decision. Do not assign invented percentages to the domains; the supplied official research confirms the five-domain structure but does not provide domain weights.
What official preparation resources are available?
Oracle’s Become a Cloud Security Professional (2025) learning path is the main structured preparation option in the supplied research. Oracle lists 22+ hours of expert training, 18 skill checks, and an Oracle University lab in that path. Oracle also states that the learning path will be archived on September 30, 2026, so check its current availability before building a long study schedule.
The path covers IAM, network security, OS and workload protection, data protection, and maintaining security posture. Use it as a sequence, not as background reading to complete passively. After each lesson, write a short explanation of the control, configure the relevant behavior where the lab allows it, and record what evidence would show that the control works.
Oracle’s preparation course includes HPE preparation, walkthroughs for Network Source, Network Firewall, OCI Certificates, Bastion, Vault Secret, WAF, and Custom Security Zone, plus sample questions. Those walkthroughs are useful because they expose configuration relationships that flashcards often conceal. Treat sample questions as reasoning practice, not as a source of live exam content.
Oracle also provides an associated practice exam. The supplied official information says it requires a score of 80% or higher to pass and includes three sample hands-on performance challenges: Security Zone, Certificates, and Network Firewall. Because the practice exam is a readiness tool rather than a guarantee of the certification result, review every missed answer and repeat the relevant configuration or explanation.
What should you record while studying?
Keep a decision log rather than a glossary alone. For each service, record the security problem, prerequisites, configuration location, intended effect, possible over-permission or exposure, and the test you would perform afterward. This turns study time into reusable troubleshooting knowledge and exposes gaps before you schedule the exam.
How should you sequence preparation?
Start with OCI and security fundamentals, then progress from identity to network controls, workload protection, data protection, and posture maintenance. This sequence mirrors dependencies: access decisions affect configuration, network controls affect exposure, workload and data controls protect what is deployed, and posture work validates the result.
Phase one is a baseline assessment. Before watching the full learning path, explain in your own words how an OCI identity receives permission, how a network flow is allowed or denied, how a workload is protected, and how a security issue is detected and corrected. Mark each explanation as confident, partial, or unknown. This prevents familiar product names from creating false readiness.
Phase two is domain learning. Work through IAM first and build small policy examples. Then trace network flows and compare the controls that govern them. Move to OS and workload protection, followed by data protection. Finish each domain with a closed-book explanation of one design choice and one troubleshooting path.
Phase three is hands-on reinforcement. Use the Oracle University lab when available and schedule lab time before assuming access is immediate. The official lab instructions say that credentials are provided through the lab environment details and advise checking back before the scheduled lab. Do not post lab credentials in a public forum or community.
Phase four is integration. Design a small secure OCI environment on paper or in the authorized lab: identities, compartments, network boundaries, a protected workload, certificate or secret handling, and a posture-review process. Then deliberately introduce a control error and describe how you would isolate and correct it.
Phase five is readiness review. Take the official practice exam, inspect your errors by domain, revisit weak demonstrations, and repeat the explanation without notes. Schedule the certification attempt only when you can explain why an option is appropriate and why the alternatives create a weaker or mismatched control.
A practical four-stage roadmap
In the first stage, establish the baseline and complete foundational OCI review. In the second, study IAM and network security while producing policy and traffic-flow notes. In the third, complete OS and workload protection, data protection, and security-posture work with lab exercises. In the fourth, use the official practice exam, repair weak areas, verify delivery requirements, and make the scheduling decision.
If you have limited weekly time, preserve the order but reduce the amount studied in each session. A short session should still end with an output: a policy explanation, a traffic diagram, a service comparison, a troubleshooting sequence, or a corrected lab configuration. Passive video completion is not an adequate substitute for being able to apply the concept.
How should you practice IAM?
Begin with authorization logic. For every policy exercise, identify the principal, verb or action, resource, scope, and intended boundary. Test whether the permission is broader than necessary and whether a change affects humans, services, or both. Include IAM Optimization and Object IAM in your review because Oracle specifically names them in the 2025 course updates.
A common mistake is learning policy syntax without learning the security outcome. Correct that by asking what the user or workload can actually do, where the permission applies, and how you would verify or revoke it. Keep separate notes for authentication, authorization, delegation, and resource organization so that similar terms do not blur together.
How should you practice network security?
Draw the requested communication before configuring it. Mark the source, destination, protocol, port, route, subnet or boundary, inspection service, and expected response. Then identify which rule or service should enforce each requirement. Include Zero Trust Packet Routing, Network Firewall, WAF, and Network Source in your review because they appear in Oracle’s 2025 preparation material or course updates.
Do not treat a permitted route as proof of a secure application path. Check whether the exposure is intentional, whether return traffic is possible, whether inspection is bypassed, and whether the rule is more open than the requirement. Troubleshooting should proceed from observed behavior to path analysis, control review, and a narrowly scoped correction.
How should you practice workload and data protection?
For workload protection, connect host state, administration, patching, network exposure, and application placement. Include OS Management Hub in the 2025 update list and practice explaining what operational problem it addresses. For data protection, focus on the handling of certificates and secrets, access boundaries, and the consequences of exposing or misusing sensitive material.
A frequent preparation error is studying certificates, secrets, encryption, and host controls as unrelated product chapters. Instead, follow data through its lifecycle: creation, storage, access, use, rotation, and revocation. Ask which identity needs access, where the secret or certificate is kept, and what evidence confirms that the control is functioning.
What mistakes weaken exam readiness?
The most damaging mistake is using unauthorized dumps or memorizing purported exam questions. Such material does not establish that you understand OCI security, may be inaccurate or outdated, and conflicts with a responsible certification process. Use official training, authorized labs, official sample questions, and your own reasoning notes instead.
Another mistake is confusing completion with competence. Watching a course, collecting screenshots, or recognizing a service name does not prove that you can choose a control in a new scenario. Require yourself to explain the decision, implement it where authorized, and diagnose a deliberate failure.
Studying only the most visible security services is also risky. The official learning path spans five domains, and Oracle’s updates include IAM Optimization and Object IAM, Zero Trust Packet Routing, OS Management Hub, and troubleshooting OCI security issues. A narrow service list can leave gaps in the connections between controls.
Finally, do not schedule before checking the current official exam page and delivery instructions. The supplied sources include both Oracle University exam-preparation requirements and a note that those details are not valid for exams scheduled and delivered by Pearson VUE. Confirm which delivery route applies to your appointment.
How can you identify a real knowledge gap?
A real gap appears when you cannot answer one of four questions: what risk is present, which OCI control addresses it, how the control should be configured or scoped, and how you would verify the result. Flag the gap, return to the relevant official lesson or lab, and retest yourself without copying the original explanation.
What delivery checks apply to an Oracle University exam?
The supplied Oracle University preparation page lists technical and identification requirements for Oracle University-delivered proctored exams. These requirements do not automatically describe every possible delivery route, so first confirm whether your appointment is Oracle University-delivered or Pearson VUE-delivered.
For an Oracle University delivery, Oracle says the computer should use the latest Chrome or Edge on Windows 11, Windows 10, or Mac OS X 13 or later, with administrator rights. iOS, Windows CE, Windows RT, Android, Chrome OS, and Linux are not supported. Developer mode must be turned off, and the device must use a single display.
Oracle lists a consistent connection of at least 3 mb/sec upload and download with a ping of less than 100 ms, advises against mobile hotspots and tethering, and requires proxy and VPN connections to be disabled and disconnected. It also lists minimum OS RAM of 8 GB or more.
The webcam must have a minimum resolution of 640x490 at 10 fps. Oracle requires a working webcam, audio, and microphone, an English QWERTY keyboard, and closed applications and browsers before the exam begins. The supplied page says only the MyLearn Exam page tab should remain open and that incognito mode must be disabled.
Government-issued identification is required for an Oracle University certification exam. The first and last name must exactly match the registration name, and the identification must be valid, government issued, and include a recent recognizable photo. Check the accepted and unacceptable ID categories on the official page before appointment day.
Oracle states that proctored exams require check-in at least 30 minutes before the scheduled start time. Candidates who try to check in after the scheduled exam time may not be admitted. Use the readiness check and the official preparation video when available rather than waiting until the appointment to discover a device or identity problem.
Pen and paper are not allowed during the exam, but Oracle says a digital whiteboard is available in the exam delivery platform. Plan your note-taking approach around that rule and remove unapproved physical materials from the testing area.
How should you schedule and budget responsibly?
Verify the current price, currency, delivery vendor, and appointment rules in Oracle’s official systems before purchase. Oracle stated on August 6, 2025 that attempts for non-foundational core OCI certifications, including OCI Security Professional, cost US$245, while the learning path and practice tests were free. That statement is time-sensitive; do not assume it remains unchanged.
Oracle’s pricing guidance says currency conversions are reviewed and updated annually and that daily exchange-rate fluctuations can prevent a USD amount from mapping exactly to a local-currency price. Where Oracle University and Pearson VUE accept different currencies, the exam price is provided in the currency offered by Oracle University; candidates should check Pearson VUE for the vendor’s accepted currency when applicable.
For an Oracle appointment, cancellation and rescheduling must occur at least 24 hours before the appointment time. Missing that window may put the exam attempt at risk. Make the appointment only after your equipment check, identity check, study review, and practical readiness assessment are complete.
OCI certifications are valid for 24 months from the date the credential is earned, according to Oracle’s certification guidelines. Treat that as a credential-policy fact, not as a reason to rush. Check the current recertification policy later because certification programs and exam versions can change.
What should you do after a practice result or failed attempt?
Use the result diagnostically. Sort missed questions or tasks into IAM, network security, OS and workload protection, data protection, or maintaining security posture. For each error, write the mistaken assumption, the correct control relationship, and a verification step. Do not respond to a weak result by repeatedly memorizing answer patterns.
Oracle’s associated practice exam uses an 80% or higher passing requirement and includes Security Zone, Certificates, and Network Firewall hands-on challenges. If you miss a challenge, rebuild the configuration from requirements rather than copying the final state. If the lab is unavailable, produce a detailed design and troubleshooting sequence from the official learning material.
If you fail the certification exam, Oracle’s guidelines state that a retake may be scheduled for an earliest appointment date from the failed exam appointment date. Oracle also says a passed exam cannot be retaken. Review the current policy before purchasing another attempt, then use the diagnostic information and your study log to target the failed domains.
What is the best final-week checklist?
In the final week, stop expanding your resource list. Complete one integrated security design, revisit every unresolved decision log entry, take the authorized practice assessment, and confirm the appointment type and current Oracle instructions. Reserve the last study session for concise explanations and equipment checks rather than an exhausting new topic.
Confirm your registration name against your government-issued ID, test the supported computer and browser, verify the connection, webcam, microphone, RAM, single-display setup, keyboard, and browser settings, and remove VPN or proxy use where required. Check in at least 30 minutes early for a proctored Oracle University exam.
For lab preparation, schedule the lab through Oracle University when available and read the access instructions before the session. The supplied lab material says credentials are available through the cloud host details and that a lab environment can have a stated end time or extension process. Treat those times as instructions for the particular lab session, not as certification-exam timing.
Your final decision should be evidence-based: proceed when you can apply controls across all five domains and explain your reasoning; delay when your knowledge is limited to recognition or when your delivery setup is uncertain. A later appointment is safer than paying for an attempt before the practical gaps are understood.
Where should your next action begin?
Start with Oracle’s MyLearn page for 1Z0-1104-25 to confirm the exam identity, then open the 2025 cloud-security learning path and map its five domains against your baseline. Complete official training and authorized hands-on work, use the official practice exam as a diagnostic, and check Oracle’s current preparation and certification guidelines immediately before scheduling.
Do not use dumps as a substitute for preparation. They cannot demonstrate that you can secure an OCI environment, troubleshoot a control, or make a sound design decision. A study log, domain-based practice, and verified scheduling plan give you a more reliable basis for deciding when to book the exam.
Conclusion
Prepare for 1Z0-1104-25 as an applied OCI security assessment: understand the five domains, connect each service to a risk and verification method, and practise authorized configurations and troubleshooting. Confirm current delivery, identification, pricing, cancellation, and recertification information with Oracle before making a purchase. Schedule only when your evidence shows integrated understanding rather than recognition of isolated terms.
Related exams
- 1z0-1067-24 exam — Oracle Cloud Infrastructure 2024 Cloud Operations Professional
- 1z0-1067-25 exam — Oracle Cloud Infrastructure 2026 Cloud Ops Professional
- 1z0-1084-25 exam — Oracle Cloud Infrastructure 2026 Developer Professional
- 1z0-1085-24 exam — Oracle Cloud Infrastructure 2024 Foundations Associate
- 1z0-1085-25 exam — Oracle Cloud Infrastructure 2026 Foundations Associate
- 1z0-1105-23 exam — Oracle Cloud Data Management 2023 Foundations Associate