問題文
The Azure key vault resources of an estate are registered in an OCI compartment set aside for keys, while the Exadata VM Clusters that will use them sit in another compartment. An engineer is writing the OCI policy for that arrangement. How many statements do the documented prerequisites call for, and what does each of them grant?
選択肢
- One statement, written in the compartment holding the vault resource, letting the resource principal of the cloud VM cluster read the registered vault resource there, because the cluster reads nothing in its own compartment for this flow.
- Two statements, both written in the compartment holding the cluster, of which the first lets the resource principal of the cloud VM cluster read the registered vault resource wherever that resource happens to sit, while the second lets the group of the operators who pick the key in the console read the same resource on their own account.
- Two statements, one in the compartment holding the vault resource and one in the compartment holding the cluster, each letting the resource principal of the cloud VM cluster read the registered vault resource there, a single statement being enough only where the two resources share one compartment.
- Two statements, one letting the resource principal of the cloud VM cluster read the registered vault resource in the compartment of the vault, and one letting the identity connector of the cluster manage keys in that same compartment.