1Z0-1104-23 Exam Guide: OCI 2023 Security Professional Preparation and Scheduling
1Z0-1104-23 validates security knowledge and practical OCI security capability through multiple-choice questions and hands-on challenges in a provided OCI environment. Oracle positions the certification for security professionals and solution architects who secure OCI workloads and applications. This guide helps you decide whether your experience matches the intended audience, which skills to practise first, how to use Oracle’s learning path, and what to verify before buying or scheduling an attempt. It also separates confirmed Oracle requirements from sensible preparation recommendations.
What 1Z0-1104-23 validates
1Z0-1104-23 is Oracle’s Oracle Cloud Infrastructure 2023 Security Professional exam. Its assessment model combines multiple-choice questions with a hands-on performance section, so preparation must cover both service decisions and the ability to configure or secure resources in OCI rather than relying on terminology recall alone.
Oracle’s certification catalog describes the performance section as two hands-on challenges completed in a provided OCI environment. That detail changes the preparation decision: a candidate who can explain security concepts but cannot navigate OCI controls, interpret configuration dependencies, or recover from an incorrect setting has an important skills gap to address.
The exam belongs to the 2023 version of the OCI Security Professional certification. Oracle’s later 1Z0-1104-25 page does not establish a retirement date for 1Z0-1104-23, so candidates should confirm the current listing and availability in Oracle MyLearn before purchasing an attempt.
Who should take this exam
The intended candidate is an experienced OCI security practitioner, not someone approaching cloud security with no operational background. Oracle identifies security professionals responsible for OCI environments and solution architects who use core OCI security services to build secure environments for applications and resources.
The catalog states that the target candidate should have 2+ years of experience designing and implementing security solutions and 6 months or more of hands-on experience securing workloads on OCI. These are stated target-candidate expectations, not a claim that every candidate must submit a prerequisite approval before scheduling.
Use the experience guidance as a readiness test. If you have designed identity boundaries, protected network paths, secured data services, investigated activity, or automated security controls in OCI, the exam’s applied format is likely relevant. If your experience is limited to reading service descriptions, build practical exposure before treating an exam booking as the next step.
Solution architects should pay particular attention to the security consequences of architecture choices. Security specialists should avoid narrowing their preparation to one control area: the published skill list spans identity and access management, data and database workload protection, network security, secure applications, security operations, monitoring, logging, alerting, and compliance frameworks.
Which skills to study first
Start with the security control areas that determine how OCI resources are trusted, reached, protected, and observed. Oracle’s published skill list includes OCI security services, Identity and Access Management, mechanisms for securing data and database workloads, network security, secure applications, security operations, monitoring, logging, alerting, and compliance frameworks.
A practical sequence is to establish identity and tenancy structure first, then secure network exposure, then protect data and applications, and finally test monitoring and operational response. This sequence is a preparation recommendation, not an official weighting of the exam domains; the supplied Oracle research does not provide blueprint percentages or a domain-by-domain question allocation.
For each topic, study the decision it supports rather than memorizing an isolated feature name. Ask who should be allowed to act, which resource should be reachable, how sensitive data should be protected, what evidence should be collected, and how a team would detect or respond to a suspicious change.
Keep a service-to-purpose matrix. For every security service or control you review, record the problem it addresses, the resource scope where it applies, the permissions or configuration it depends on, the evidence it produces, and one failure mode. This turns passive reading into a tool for answering scenario questions.
Identity and access management
Practise reasoning about least privilege, administrative boundaries, group or policy design, and the difference between a user’s authority and a workload’s authority. In a lab, create a small role model and verify both the intended access and a deliberately denied action.
Do not study policy syntax as if it were independent of tenancy design. A correct-looking statement can still be unsuitable if it is attached to the wrong compartment, group, dynamic identity, or resource scope. When reviewing a configuration, explain why the permission is needed and what would become exposed if its scope were widened.
Network security
Review how security decisions affect ingress, egress, segmentation, and service reachability. Build a simple workload path on paper before touching the console: identify the client, public or private entry point, subnet placement, security controls, destination, and logging requirement.
A frequent mistake is to treat a connectivity failure as proof that a single rule is wrong. Check the complete path and the interaction between routing, subnet-level controls, host-level controls, service endpoints, and identity authorization. Your notes should distinguish a network denial from an authentication or authorization failure.
Data, database, and application protection
Study protection as a lifecycle: classify what needs protection, control access, protect it in transit and at rest, manage keys or secrets appropriately, and monitor use. Relate those choices to the workload rather than reciting security features without explaining their purpose.
For application scenarios, trace trust boundaries between users, services, databases, and external dependencies. Practise identifying where an application should obtain credentials, which identity should call an OCI service, and what evidence an operator would need after a suspected compromise.
Security operations and observability
Monitoring, logging, and alerting are operational controls, not merely reporting features. Practise selecting useful events, sending them to an appropriate destination, defining an actionable signal, and describing what an analyst would investigate next.
A weak study pattern is to configure a log source and stop. A stronger exercise asks whether the event is enabled, retained, searchable, protected from unauthorized alteration, and connected to a response process. Link each alert to a concrete action such as validating a policy change, isolating a workload, or reviewing access activity.
What the hands-on format changes
The hands-on section means you should rehearse configuration and diagnosis, not only read explanations. Oracle states that the 2023 exam includes two hands-on challenges in a provided OCI environment. The official material supplied here does not state the exam’s total duration, interface workflow, scoring split, or exact task subjects.
Practise in short, repeatable scenarios. Begin from a written requirement, identify the minimum controls needed, implement them, verify the result, and record how you would undo or amend the configuration. This method is more useful than copying a finished configuration because it develops judgment when a requirement changes.
Use a verification checklist after every exercise: resource scope, identity, network path, encryption or secret handling, logs, alerts, and negative testing. Negative testing means confirming that an unauthorized action fails for the expected reason. It helps separate a genuinely secure configuration from one that works only because access is broader than intended.
Do not infer that training-lab mechanics are the same as examination mechanics. Oracle’s Learn page describes an Oracle training lab workflow, while the catalog describes the exam as a performance-based assessment. Treat lab access instructions as course-environment information unless Oracle’s current exam instructions say otherwise.
How to use Oracle’s learning path
Oracle’s official OCI 2023 Security Professional learning-path listing reports 80 lessons, 45 demos, 20 hands-on labs, and a duration of 27 hours and 18 minutes. Use those figures to estimate the size of the official study resource, not as a promise that completing it alone establishes exam readiness.
Do not consume the path in one uninterrupted pass. First work through the lessons to identify unfamiliar services and concepts. Next revisit the demos by predicting the required configuration before watching. Then perform the hands-on labs without copying the sequence until you can explain each control and verification step.
After each module, write a small scenario answer: the requirement, the chosen control, its scope, the expected evidence, and one alternative that would be weaker or inappropriate. This creates revision material aligned with the exam’s applied nature while avoiding unsupported claims about the exact questions Oracle will ask.
If your access to the learning path or lab is restricted, use the official Oracle page to check enrollment and support options. Do not publish or share lab credentials, and do not treat a temporary training environment as a source of live exam content.
A practical four-stage study roadmap
A staged plan is more reliable than repeatedly rereading service pages. Move from coverage to configuration, then from configuration to diagnosis, and finally to readiness checks. Adjust the pace to your existing OCI experience; the stages below are recommendations, not an Oracle-mandated schedule.
Stage one: map the scope
List every skill named in Oracle’s catalog and mark it as familiar, partly understood, or untested. Build a dependency map showing how identity affects access to security services, how network placement affects workload exposure, and how monitoring supports operations.
At this stage, do not spend most of your time on the topics you already know. Select one concrete gap from each broad area and define what evidence would prove improvement. For example, “understand logging” is too vague; “enable the relevant event source, route it, and explain the alert response” is testable.
Stage two: build controlled configurations
Use the official demos and hands-on labs as prompts for deliberate practice. Recreate a secure compartment or workload design, apply the narrowest practical access, protect the relevant data path, and configure monitoring. Keep a change log so you can identify which setting caused a result.
After each task, perform both positive and negative checks. Confirm that the intended principal can complete the required action and that an unrelated principal cannot. Then explain the result in plain language, because scenario questions often test the reason for a control rather than the label of the control.
Stage three: troubleshoot and explain
Introduce faults deliberately: remove a required permission, change a resource scope, block a network path, disable an observation source, or point an alert at the wrong destination. Diagnose from evidence instead of immediately rebuilding the environment.
For every fault, record symptoms, likely causes, checks in priority order, corrective action, and prevention. This develops the habit needed for hands-on challenges, where an efficient diagnosis can matter as much as knowing the final configuration.
Stage four: perform a readiness review
Before scheduling, explain each published skill without opening notes, then demonstrate the central workflows in a clean environment. Pay special attention to tasks that you can describe but cannot complete quickly or verify confidently.
Review your notes for untested assumptions. Replace statements such as “this should be secure” with evidence: the access test passed or failed, the route was confirmed, the data protection setting was checked, or the expected event appeared in the monitoring workflow. Schedule only after the remaining gaps are specific enough to address.
How to decide whether to schedule now
Schedule when you can combine conceptual explanation with independent OCI execution. If you still need step-by-step instructions for basic identity, network, data-protection, or monitoring tasks, delay the booking and use targeted lab practice. The exam’s mixed format rewards breadth plus reliable application, not last-minute memorization.
Oracle’s certification process says candidates buy an exam attempt, choose a date, and have six months to take the exam. Confirm that rule and the currently available appointment options in Oracle MyLearn before purchase, because booking availability and current program information can change.
A sensible decision checklist is: your experience is close to Oracle’s intended profile; every published skill has been reviewed; you have completed relevant hands-on work; you can troubleshoot without copying a solution; and you have checked the current exam listing. If one answer is no, identify the missing evidence rather than buying an attempt to create urgency.
Scheduling, price, and cancellation decisions
Verify transaction details directly before paying. Oracle directs candidates to buy an exam attempt and schedule through Oracle MyLearn, while its guidelines say candidates should check Pearson VUE for the price and accepted currency for the selected exam. The supplied sources do not provide a fixed price for 1Z0-1104-23.
Currency may differ between Oracle University and the test vendor. Oracle explains that candidates may purchase a voucher through Oracle University in the currency offered there or purchase directly from the test vendor in the vendor’s offered currency, where those options apply. Annual currency reviews and daily exchange-rate changes can also affect the local equivalent.
If you need to cancel or reschedule, Oracle’s policy requires action at least 24 hours before the appointment time. Missing that window risks forfeiting the exam attempt. Record the appointment time and the cancellation deadline as soon as you book; do not rely on a reminder created at the last moment.
Budget for more than the exam transaction itself. Oracle states that expenses beyond the cost of the exam are the candidate’s responsibility, including costs such as travel, equipment, and lost wages. Check the current delivery instructions and technical requirements before committing to a date.
Delivery and technical preparation
The confirmed exam format is hands-on challenges plus multiple-choice questions, but the supplied evidence does not establish whether this specific exam is currently delivered online, at a test center, or through both routes. Check Oracle’s current scheduling and exam-preparation instructions for the available delivery method and its requirements.
Do not transfer training-lab requirements to the exam without confirmation. The Learn page describes a training environment with system guidance for Windows 10 and macOS Catalina and Big Sur, supported browsers, an unshared internet connection, and audio equipment. Those details support preparation for that Oracle training environment; they are not evidence of the 1Z0-1104-23 examination requirements.
If you use the Oracle training lab, follow the published access workflow: schedule the lab, check back at the stated pre-lab point for credentials, and use Oracle’s support route for technical issues. The page also warns users not to share lab credentials in community posts. Treat credentials as confidential.
Before the exam, verify your Oracle account identity, appointment details, identification requirements, delivery location or system requirements, and any permitted materials in the official instructions. Because these details can change, use the current Oracle and testing-vendor pages rather than an old preparation article.
Common preparation mistakes
Most avoidable mistakes come from studying the wrong evidence. Candidates often memorize service names, practise only a single successful path, ignore operational visibility, or assume that a training lab’s instructions describe the exam. Correct those habits by requiring a reason, a configuration, a verification step, and a recovery step for every major topic.
Relying on dumps or recalled questions
Exam dumps, leaked questions, or memorized answer lists are not a safe preparation method and do not guarantee a pass. They can be inaccurate, violate certification rules, and leave you unable to complete the hands-on portion. Use Oracle’s published learning path, documented skills, and legitimate lab practice instead.
Confusing feature recognition with secure design
Recognizing the name of a security service is not the same as selecting it correctly. For each service, practise the boundaries: what it protects, who operates it, how it interacts with identity and networking, what evidence it generates, and what it cannot solve.
Skipping negative tests
A configuration that permits the desired action may still be over-permissive. Test an unauthorized identity, an unintended network path, or an improperly scoped resource. Record the expected denial and investigate if the action succeeds. This exposes policy and segmentation errors early.
Ignoring version context
The exam code identifies the 2023 Security Professional exam, while Oracle also publishes later OCI Security Professional material. Do not assume that a later exam page defines the 2023 exam. Confirm the active listing and use version-appropriate Oracle learning material before relying on a feature or policy detail.
Booking before checking logistics
Candidates sometimes focus on study content and overlook the appointment deadline, currency, account details, or delivery requirements. Check those items before purchase, and keep the official cancellation and rescheduling rule visible in your calendar.
How to review without an official percentage blueprint
The supplied official research does not include domain percentages, question counts, a passing score, or a scoring split for 1Z0-1104-23. Do not create a pseudo-blueprint from unsupported numbers. Instead, use the named skill areas and the two-part assessment format to allocate study time according to your demonstrated gaps.
Give additional practice to a domain only when your own evidence shows weakness there. For example, if identity exercises are reliable but network troubleshooting repeatedly stalls, shift time toward network paths and verification rather than claiming that network security carries a larger official share.
Use a coverage table with three columns: published skill, practical task completed, and explanation you can give without notes. Add a fourth column for the last failed check. This produces a defensible study priority without presenting personal prioritization as Oracle’s exam weighting.
What to do after a result
After passing, use Oracle’s certification verification tools to confirm and share the credential through the channels described in its certification guidelines. After failing, treat the result as a reason to diagnose gaps rather than repeatedly booking attempts without changing preparation.
Oracle’s guidelines state that a failed exam retake may be scheduled for the earliest appointment date from the failed exam appointment date, and that a passed exam may not be retaken. Check the current policy and appointment availability before making a retake plan.
Do not infer a universal validity period from unrelated Oracle credentials. The supplied catalog record shows an expiration date for one issued badge, while Oracle’s general guidelines separately state a 24-month validity period for Oracle Cloud Infrastructure certifications. Confirm the current status and validity information attached to your own credential in Oracle’s official records.
If an examination or account issue requires a formal inquiry, use Oracle’s certification support and inquiry process. Keep appointment information, transaction records, and relevant correspondence, and describe the issue precisely rather than relying on informal third-party advice.
Your next preparation actions
Open the current Oracle MyLearn entry for 1Z0-1104-23 and confirm that it is the exam version you intend to take. Then compare your experience with Oracle’s target profile, map the published skills, and choose one hands-on exercise for each major control area. Do not purchase until the listing, price, currency, and delivery details are clear.
Next, work through the official learning path in an active-practice sequence: lesson for context, demo for prediction, lab for execution, and a written explanation for review. Build a small troubleshooting log and include negative tests. Finish with a clean-environment rehearsal that covers identity, network, data or workload protection, and monitoring operations.
Finally, schedule only when your remaining weaknesses are concrete and manageable. Record the appointment and the 24-hour cancellation or rescheduling requirement, follow the current official delivery instructions, and keep this guide as a planning aid rather than a substitute for Oracle’s live exam policies.
Conclusion
1Z0-1104-23 calls for more than familiarity with OCI security terminology. The evidence supports a preparation plan built around the published skill areas, independent lab execution, troubleshooting, and careful verification of current scheduling information. Use Oracle’s official materials to confirm availability and logistics, avoid unsupported claims about scores or weights, and make the booking decision only when you can explain and apply the controls that secure an OCI workload.
Related exams
- 1z0-1067-24 exam — Oracle Cloud Infrastructure 2024 Cloud Operations Professional
- 1z0-1067-25 exam — Oracle Cloud Infrastructure 2026 Cloud Ops Professional
- 1z0-1084-25 exam — Oracle Cloud Infrastructure 2026 Developer Professional
- 1z0-1085-24 exam — Oracle Cloud Infrastructure 2024 Foundations Associate
- 1z0-1085-25 exam — Oracle Cloud Infrastructure 2026 Foundations Associate
- 1z0-1104-25 exam — Oracle Cloud Infrastructure 2026 Security Professional