Answer: B: Explanation
Answer: B: Explanation
Answer: B: Explanation
Question #:1
Which option lists Virtual Cloud Networks (VCNs) that can be peered?
Answer: B
Question #:2
You have just created an Autonomous Data Warehouse (ADW) and you want to connect to the ADW using
SQL Developer.
What three items are needed to connect to the ADW using SQL Developer? (Choose three.)
Answer: A C E
Explanation
https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/adwc/OBE_Provisioning_Autonomous_Data_Ware
Question #:3
Which two statements are true about data guard service on DB Systems in Oracle Cloud Infrastructure (OCI)?
(Choose two.)
A. Data guard implementation requires two DB Systems, one running the primary database on a virtual
machine and the standby database running on bare metal
B. Data guard configuration on the OCI is limited to one standby database per primary database
C.
1 of 76
Oracle - 1z0-1072
D. Data guard implementation requires two DB Systems, one containing the primary database and one
containing the standby database
Answer: B D An Oracle Data Guard implementation requires two DB systems, one containing the primary database and one containing the standby database. When you
enable Oracle Data Guard for a virtual machine DB system database, a new DB system with the standby database is created and associated with the primary
database. For a bare metal DB system, the DB system with the database that you want to use as the standby must already exist before you enable Oracle
Data Guard.
Explanation
Tip
An Oracle Data Guard configuration on the Oracle Cloud Infrastructure is limited to one standby database for each primary database.
References:
Question #:4
Your application front end consists of several Oracle Cloud Infrastructure compute instances behind a load
balancer. You have configured the load balancer to perform health checks on these instances.
If an instance fails to pass the configured health checks, what will happen?
C. The instance is taken out of the back end set by the load balancer.
Answer: D
Question #:5
Which two use Oracle dynamic routing gateway (DRG) for connectivity? (Choose two.)
D. Oracle Cloud Infrastructure FastConnect public peering To fast connect - OCI to private datacenter
Answer: A B
Explanation
References:
Question #:6
2 of 76
Oracle - 1z0-1072
Which two statements are true about encryption on Oracle Cloud Infrastructure (OCI)? (Choose two.)
D. By default, NVMe drives are encrypted but the block volume service is not.
Server Side Encryption
All data stored in the object storage is encrypted at rest, by default, using the AES 256 encryption algorithm.
Answer: A C The Oracle Cloud Infrastructure Block Volume service always encrypts all block volumes, boot volumes, and volume backups at rest by using the Advanced
Encryption Standard (AES) algorithm with 256-bit encryption. By default all volumes and their backups are encrypted using the Oracle-provided encryption keys.
Explanation All databases created in Oracle Cloud Infrastructure are encrypted using transparent data encryption (TDE)
References: https://cloud.oracle.com/storage/object-storage/features
Question #:7
Which two statements are true about restoring a block volume from a manual or policy-based block volume
backup? (Choose two.)
A. It can be restored as new volumes with different sizes from the backups
C. It must be restored as a new volume to the same availability domain (AD) on which the original block
volume backup resides
Answer: A D
Explanation
A – Backups are encrypted and stored in Oracle Cloud Infrastructure Object Storage, and can be restored as
new volumes to any availability domain within the same region they are stored.
D- You can restore a block volume backup to a larger volume size. To do this, check Custom Block Volume
Size (GB), and then specify the new size. You can only increase the size of the volume, you cannot decrease
the size.
Question #:8
Which two statements are true about Oracle Cloud Infrastructure (OCI) DB Systems?
Always patch a DB system before you patch the databases within that system. The Console displays the
latest DB system patch and the previous patch. You can use either of these patches, but we recommend
A. Customers have no control over database patching. using the latest patch when possible.
3 of 76
Oracle - 1z0-1072
C. Customers can consolidate multiple database homes on a single virtual machine database host.
Answer: B D
Question #:9
Which two are NOT an image source when launching a new compute instance? (Choose two.)
A. boot volume
Answer: A B
Question #:10
Which statement is true about Oracle Cloud Infrastructure Object Storage Service?
A. An Archive Object Storage tier bucket can be upgraded to the Standard Object Storage tier.
B. You cannot directly download an object from an Archive Object Storage bucket.
C. An existing Standard Object Storage tier bucket can be downgraded to the Archive Object Storage tier.
Question #:11
Your company has decided to move a few applications to Oracle Cloud Infrastructure and you have been
asked to design it for Disaster Recovery (DR). One of the items of your design is to deploy the DR at least 300
miles from the home site and minimize the network latency as much as possible.
A. Deploy applications in two separated VCNs in different Availability Domains and use VCN Remote
Peering
B. Deploy applications in different regions and have them connected using VCN Remote Peering
C. Deploy applications in two separated VCNs in different regions and use VCN Local Peering
4 of 76
Oracle - 1z0-1072
D. Deploy applications on the same region splitting workloads across Availability Domains.
A. Not Correct. If within ADs, then VCN Local Peering, NOT VCN Remote Peering.
B. Correct
Answer: B C. Not correct. If VCNs in different regions then we can use VCN Remote Peering
D. Not Correct. this is done across FDs.
Question #:12
Which two options are true for Autonomous Transaction Processing (ATP) database? (Choose two.)
D. You can add more Pluggable Database for consolidating multiple databases in ATP
E. You can add new ORACLE_HOME for bringing older versions of on-premises databases to ATP
Answer: B C
https://docs.oracle.com/en/cloud/paas/atp-cloud/atpug/autonomous-add-resources.html#GUID-DA72422A-5A70-42FA-A363-AB
269600D4B0
Question #:13
Which three methods can you use to manage Oracle Cloud Infrastructure services? (Choose three.)
D. Command-line Interface
E. REST API
Answer: B D E
Explanation
https://docs.cloud.oracle.com/iaas/Content/GSG/Concepts/baremetalintro.htm
Question #:14
What is the maximum number of security lists that can be associated with a subnet?
A. four
B.
5 of 76
Oracle - 1z0-1072
B. three
C. five
D. two
Answer: C
Explanation
you may optionally specify one or more security lists for the subnet to use (up to five). If you don’t specify
any, the subnet uses the cloud network’s default security list. You can change which security list the subnet
uses at any time.
https://docs.cloud.oracle.com/iaas/Content/Network/Tasks/managingVCNs.htm
Question #:15
A. YAML
B. JSON
C. HCL
D. XML
Answer: B C
Explanation
References:
Terraform configuration files can use either of two formats: Terraform domain-specific language (HashiCorp
Configuration Language format [HCL]), which is the recommended approach, or JSON format if the files need
to be machine-readable.
Question #:16
Which two statements about the Oracle File Storage Service (FSS) Security are accurate? (Choose two.)
B. Security lists can be used as a virtual firewall to prevent an instance from mounting an FSS mount target
within a subnet.
D.
6 of 76
Oracle - 1z0-1072
E. FSS leverages UNIX user group and permission checking for file access security.
Answer: B D
Question #:17
ON NO: 131
A. For private peering, FastConnect extends your existing infrastructure to allow you to consume object
storage from your on-premises data center
B. For private peering, FastConnect extends your existing infrastructure to a virtual cloud network
C. The FastConnect provider network offers only 1 Gbps port connection speed increments
D. For public peering, a dynamic routing gateway must be configured and attached to the virtual cloud
network (VCN)
Private peering: To extend your existing infrastructure into a virtual cloud network (VCN) in Oracle Cloud Infrastructure (for
example, to implement a hybrid cloud, or a lift and shift scenario). Communication across the connection is with IPv4 private
Answer: B addresses (typically RFC 1918).
References:
Question #:18
You have an application running on Oracle Cloud Infrastructure. You Identified that the read and write
operations are slowing your application down enough to impair user access. The application is currently using
a VM.Standard2.1 compute without any block storage attached to it.
A. Terminate the compute instance preserving the boot volume. Create a new compute instance using the
VM.DenseI02.8 shape using the boot volume preserved and use the NVMe devices to host your
application.
B. Terminate the compute instance preserving the boot volume. Create a new compute instance using the
VM.Standard2.2 shape using the boot volume preserved and attach a new block volume to host your
application.
C. Terminate the compute instance preserving the boot volume. Create a new compute instance using the
VM.Standard2.2 shape using the boot volume preserved, but no block volume attached.
D. Terminate the compute instance preserving the boot volume. Create a new compute instance using the
7 of 76
Oracle - 1z0-1072
D.
BM.GPU2.2 shape using the boot volume preserved, but no block volume attached.
Answer: A D
Question #:19
Your company has decided to move a few applications to Oracle Cloud and you have been asked to design it
for both High Availability (HA) and Disaster Recovery (DR).
Which two should you consider while designing your Oracle Cloud Infrastructure architecture? (Choose two.)
A. Region
B. Instance Shape
C. Compartments
D. Availability Domain
Answer: A D
Explanation
References:
https://blogs.oracle.com/cloud-infrastructure/migration-and-disaster-recovery-in-the-oracle-cloud-with-rackware
Question #:20
What does Terraform use to create, manage, and manipulate infrastructure resources?
A. resources
B. provisioner
C. instances
D. provider
Answer: D
Explanation
The Oracle Cloud Infrastructure provider is used to interact with the many resources supported by the Oracle
Cloud Infrastructure. The provider needs to be configured with credentials for the Oracle Cloud Infrastructure
account.
Question #:21
8 of 76
Oracle - 1z0-1072
You have provisioned an Autonomous Data Warehouse (ADW) database with 16 enabled OCPUs and need to
configure the consumer group for your application.
Which two are true when deciding the number of sessions for each application? (Choose two.)
A. The MEDIUM and LOW consumer group can run up to 16 concurrent SQL statements if HIGH
consumer group has 0 SQL statements
B. The HIGH consumer group can run up to 16 concurrent SQL statements as long as MEDIUM and LOW
consumer groups have 0 SQL statements
C. The MEDIUM consumer group can run 20 concurrent SQL statements when HIGH consumer group has
0 SQL statements
D. The HIGH consumer group can run up to 16 concurrent SQL statements in addition to 32 concurrent
SQL statements in MEDIUM and LOW consumer group each
E. The HIGH consumer group can run 3 concurrent SQL statements when MEDIUM consumer group has
0 SQL statements
For example, for an Autonomous Data Warehouse with 16 OCPUs, the HIGH consumer group will be able to run 3 concurrent SQL
statements when the MEDIUM consumer group is not running any statements. The MEDIUM consumer group will be able to run 20
Answer: C E concurrent SQL statements when the HIGH consumer group is not running any statements. The LOW consumer group will be able
to run 4800 concurrent SQL statements. The HIGH consumer group can run at least 1 SQL statement when the MEDIUM
consumer group is also running statements. When these concurrency levels are reached for a consumer group new SQL
Explanation statements in that consumer group will be queued until one or more running statements finish.
https://docs.oracle.com/en/cloud/paas/autonomous-data-warehouse-cloud/user/manage-prioriti
References: es.html#GUID-80E464A7-8ED4-45BB-A7D6-E201DD4107B7
https://docs.oracle.com/en/cloud/paas/autonomous-data-warehouse-cloud/user/connect-predefined.html#GUID-9747539
Database Service NameConcurrent Statements
high. 3
medium. 1.25 × OCPUs
Question #:22 low. 300 × OCPUs
Your on-premises hosted application uses Oracle database server. Your database administrator must have
access to the database server for managing the application. Your database server is sized for seasonal peak
workloads, which results in high licensing costs. You want to move your application to Oracle Cloud
Infrastructure (OCI) to take advantage of CPU scaling options.
B. VM DB systems Note
You cannot change the number of CPU cores for a virtual machine DB system
C. Autonomous Transactions Processing (ATP) in the same way. Instead, you must change the shape to one with a different
number of OCPUs. See To change the shape of a virtual machine DB system
to learn how.
D. Autonomous Data Warehouse (ADW)
Answer: A
Explanation
References:
9 of 76
Oracle - 1z0-1072
Question #:23
Your organization has deployed a large, complex application across multiple compute instances in Oracle
Cloud Infrastructure (OCI). These compute instances also have block volume storage attached to them. You
want to create a time consistent backup of these block volume storage.
C. Group volumes in a volume group first and then use available scripts in OCI
D. Group volumes in a volume group and create a manual backup of the volume group
Answer: D
Question #:24
For what business need should you use Database Cloud Service (DBCS) instead of Oracle database on a
compute instance?
DBCS is PaaS so
A. to bring your own license on a compute service . Not an compute service
. Can’t use own license
B. to lower license and infrastructure cost . No need to think about infra
. So best is RAC for HA
C. to implement Oracle RAC for high availability
Answer: C
Question #:25
You have multiple applications installed on a compute instance and these applications generate a large amount
of log files. These log files must reside on the boot volume for a minimum of 15 days and must be retained for
at least 60 days. The 60-day retention requirement is causing an issue with available disk space.
What are the two recommended methods to provide additional boot volume space for this compute instance?
(Choose two.)
A. Terminate the instance while preserving the boot volume. Create a new instance from the boot volume
and select a DenseIO shape to take advantage of local NVMe storage.
B. Create an object storage bucket and use a script that runs daily to move log files older than 15 days to
10 of 76
Oracle - 1z0-1072
B.
the bucket.
C. Create and attach a block volume to the compute instance and copy the log files.
D. Create a custom image and launch a new compute instance with a larger boot volume size.
E. Write a custom script to remove the log files on a daily basis and free up the space on the boot volume.
Answer: B C
Question #:26
You currently manage an e-commerce application that utilizes 25 identical compute resources to handle
customer traffic. The stakeholders have asked you to create another 25 identical compute resources in order to
deploy and test a new version of the software?
What is the most efficient process to create 25 additional compute resources that are identical to the first 25?
A. Create a custom image from 1 of the 25 servers. Use this custom image to provision 25 more servers
B. Create a manual backup of each boot volume belonging to the 25 servers. Restore each backup to create
25 new boot volumes, from which you will provision 25 more servers
C. Provision a new server and configure it to be identical to the first 25. Create a custom image from the
new server, then use the custom image to provision 24 more servers
D. Clone the boot volume of 1 of the 25 servers. Use the boot volume clone to provision 25 more servers
Answer: A A is best
C cloning we need to clone 25 times and time consume activity
Question #:27
C. A cloned volume is the same as a snapshot that has a dependency on the source volume.
D. You can change the block volume size when cloning a volume.
A is wrong You can only create a clone for a volume within the
Answer: D same region, availability domain and tenant.
B is wrong because you can clone volume on fly
C is wrong, because cloned vol doesnt depend on source vol
D is correct while cloing you can able to increase block vol size
Question #:28
11 of 76
Oracle - 1z0-1072
You are tasked with creating a highly available clustered application on Oracle Cloud Infrastructure consisting
of three nodes. The round-trip latency between nodes must be less than 500 µs (micro-seconds) and your cluster
should be resilient to hardware failure.
A. Deploy the cluster nodes in a single region and deploy each node into a different AD. Select the same
fault domain in each AD to ensure consistency.
B. Deploy the cluster nodes in two separate regions and take advantage of multiple availability domains
(ADs) in each region.
C. Deploy the cluster nodes in a single region and deploy each node into a different AD.
D. Deploy the cluster nodes in a single region and deploy each node in different fault domains within a
single AD.
Answer: D
Question #:29
Which two statements are true about adding secondary VNICs to an existing compute instance? (Choose two.)
A. The primary and secondary VNIC association must be in the same availability domain
C. You can remove the primary VNIC after the secondary VNIC’s attachment is complete
D. The primary and secondary VNIC association can be in different virtual cloud networks (VCNs)
Answer: A B
Question #:30
Your company is moving an Internet-facing, 2-tier web application into Oracle Cloud Infrastructure. The
application must have a highly available architecture.
A. Configure a Dynamic Route Gateway in your VCN and make it highly available.
B. Configure a NAT instance in your Virtual Cloud Network (VCN). Create a route rule by using the
private IP of the NAT instance as a route target for all the private subnets in your VCN.
C. Create an Internet Gateway and attach it to your VCN. Deploy public load balancer nodes into two
12 of 76
Oracle - 1z0-1072
C.
* For a public load balancer, create a VCN with an internet gateway and a
Available Domains. public regional subnet.
* For a private load balancer, create a VCN with at least one private subnet.
* Create at least two Compute instances, each in a separate availability
D. Place all web servers behind a public load balancer.domain.
* Create a load balancer.
* Create a backend set with a health check policy.
Answer: C D * Add backend servers (Compute instances) to the backend set.
* Create a listener, with optional SSL handling.
* Update the load balancer subnet security rules so they allow the intended
traffic.
Question #:31
Which two choices are true for Autonomous Data Warehouse (ADW)? (Choose two.)
B. Billing stops for both CPU usage and storage usage when ADW is stopped
Answer: C D
Explanation
References:
Question #:32
Which two statements are true about subnets within a VCN? (Choose two.)
A. You can have multiple subnets in an Availability Domain for a given VCN.
B. Private and Public subnets cannot reside in the same Availability Domain for a given VCN.
C. Subnets can have their IP addresses overlap with other subnets in another network for a given VCN.
D. Instances obtain their private IP and the associated security list from their subnets.
Answer: A D
Explanation
References: https://cloud.oracle.com/en_US/bare-metal-network/vcn/faq
Question #:33
You are in the process of setting up a highly available student registration website on Oracle Cloud
Infrastructure (OCI). You use a load balancer and a database service on OCI. You launch two compute
instances each in a different subnet and add them to the back end set of a public load balancer. The load
13 of 76
Oracle - 1z0-1072
balancer is configured correctly and working. You then deploy the student registration application on these
two compute instances. The application can communicate with the database service. However, when you type
the URL of this student registration application in your browser, no web page appears.
A. The security lists of the subnets on which the two instances are located do not have “allow” rules for
port 80 and 443.
B. The load balancer performed a health check on the application and found that compute instances were
not in a healthy state and terminated the instances.
C. The client requested https access to the application and the load balancer service does not support
end-to-end SSL from the client to the listener to the back-end set.
D. The Dynamic Routing Gateway is preventing the client traffic from your data center network from
reaching the public IP of the load balancer.
Answer: A
Question #:34
O: 113
You are planning to deploy a multi-region web application in Oracle Cloud Infrastructure (OCI). You have
customers in North America, Asia and Europe who will access the application.
What service is available in OCI to help you choose the regions the lowest latency to these markets?
A. Internet Intelligence
B. FastConnect
C. IPsec VPN
Answer: A
Question #:35
You are about to deploy an e-business application on Oracle Cloud Infrastructure and one of the requirements
is to use a shared file system that supports the NFS protocol.
A. object storage
14 of 76
Oracle - 1z0-1072
The File Storage service supports the Network File System version 3.0 (NFSv3) protocol.
B. block volume
D. file storage
Answer: D
Question #:36
You have a shared file system between two web servers using File Storage Service (FSS) and you were tasked
to create a backup plan for this environment to protect the data placed into the shared file system.
What is the recommended approach to create this backup using FSS features?
B. Implement a backup policy to copy data from the shared volume to object storage.
C. Compress the data that is in the shared volume and copy it into a different folder on the boot volume
disk.
D. Use the rsync tool to send data from the shared volume to a boot volume disk.
E. Use the rsync tool to send data from the shared volume to a block volume.
Answer: A
Question #:37
Answer: C D
VCN is region specific
Explanation Groups, Object Storage are global
15 of 76
Oracle - 1z0-1072
References: https://docs.cloud.oracle.com/iaas/Content/General/Concepts/regions.htm#one
Question #:38
You have one database-style application that frequently makes many random reads and writes across the
dataset.
Answer: D
Question #:39
You are running a mission-critical database in Oracle Cloud Infrastructure (OCI). You take regular backups of
your DB system to OCI object storage. Recently, you notice a failed database backup status in the console.
What two steps can you take to determine the cause of the backup failure? (Choose two.)
B. Ensure that your database host can connect to the OCI object storage
D. Make sure that the database is not active and running while backup is in progress
Answer: B C
https://docs.cloud.oracle.com/en-us/iaas/Content/Database/Troubleshooting/Backup/backupfail.htm
Question #:40
Which two are true for achieving High Availability on Oracle Cloud Infrastructure? (Choose two.)
A. Store your database across multiple regions so that half of the data resides in one region and the other
half resides in another region.
B. Attach your block volume form Availability Domain 1 to a compute instance in Availability Domain 2
(and vice versa) so that they are highly available.
C.
16 of 76
Oracle - 1z0-1072
C. Configure your database to have Data Guard in another Availability Domain in Sync mode within a
region.
D. Store your database files on Object Storage so that they are available in all Availability Domains in all
regions.
E. Distribute your application servers across all Availability Domains within a region.
Answer: C E
Question #:41
You are designing a networking infrastructure in multiple Oracle Cloud Infrastructure regions and require
connectivity between workloads in each region. You have created a dynamic routing gateway (DRG) and a
remote peering connection. However, your workloads are unable to communicate with each other.
A. The security lists associated with subnets in each virtual cloud network (VCN) do not have the
appropriate ingress rules
B. Identity and Access Management (IAM) policies have not been defined to allow connectivity across the
two VCNs in different regions
C. A local peering gateway needs to be created in each VCN with a default route rule added in the route
table forwarding the traffic to the local peering gateway
D. An Internet gateway needs to be created in each VCN with a default route rule added in the route table
forwarding the traffic to the Internet Gateway
E. The route table associated with subnets in each VCN do not have a route rule defined to forward the
traffic to their respective DRGs
Answer: A E
Question #:42
Which two actions will occur when a back-end server that is registered with a backend set is marked to drain
connections? (Choose two.)
B. It keeps the connections to that instance open and attempts to complete any in-flight requests.
17 of 76
Oracle - 1z0-1072
Answer: A B
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/Balance/Reference/sessionpersistence.htm
The Load Balancing service considers a server marked drain available for existing persisted sessions. New
requests that are not part of an existing persisted session are not sent to that server.
Question #:43
You have an Oracle Cloud Infrastructure (OCI) load balancer distributing traffic via an evenly-weighted round
robin policy to your backend web servers. You notice that one of your web servers is receiving more traffic
than other web servers.
A. Check security lists and route tables of your virtual cloud network (VCN) and fix any issues associated
with the rules
Answer: D
Question #:44
You are asked to create a user that will access programmatic endpoints in Oracle Cloud Infrastructure. The
user must not be allowed to authenticate by username and password.
B. Auth tokens
D. Windows password
Answer: B C
18 of 76
Oracle - 1z0-1072
Question #:45
You are the Solutions Architect of a large company and are tasked with migrating all your services to Oracle
Cloud Infrastructure. As part of this, you first design a Virtual Cloud Network (VCN) with a public subnet and
a private subnet. Then in order to provide Internet connectivity to the instances in your private subnet, you
create an Oracle Linux instance in your public subnet and configure NAT on it. However, even after adding all
related security list rules and routes in the Route Table, your private subnet instances still cannot connect to
the Internet.
A. Disable “Source and Destination Check” on the VNIC of your Linux instance.
C. Create a Dynamic Routing Gateway (DRG) and route your private IP traffic to the DRG.
Answer: A
Explanation
https://docs.cloud.oracle.com/iaas/Content/Network/Tasks/managingVNICs.htm#Source/D
By default, every VNIC performs the source/destination check on its network traffic. The VNIC looks at the
source and destination listed in the header of each network packet. If the VNIC is not the source or destination,
then the packet is dropped.
If the VNIC needs to forward traffic (for example, if it needs to perform Network Address Translation (NAT)),
you must disable the source/destination check on the VNIC. For instructions, see To update an existing VNIC.
For information about the general scenario, see Using a Private IP as a Route Target.
Question #:46
Which two statements are true about an Oracle Cloud Infrastructure Virtual Cloud Network (VCN)? (Choose
two.)
A. A VCN can reside in multiple Oracle Cloud Infrastructure regions and Availability Domains.
Answer: B C
19 of 76
Oracle - 1z0-1072
Question #:47
You have created a virtual cloud network (VCN) with three private subnets. Two of the subnets contain
application servers and the third subnet contains a DB System. The application requires a shared file system so
you have provisioned one using the file storage service (FSS). You also created the corresponding mount
target in one of the application subnets. The VCN security lists are properly configured so that both
application servers and the DB System can access the file system. The security team determines that the DB
System should have read-only access to the file system.
A. Create an NFS export option that allows READ_ONLY access where the source is the CIDR range of
the DB System subnet.
B. Connect via SSH to one of the application servers where the file system has been mounted. Use the Unix
command chmod to change permissions on the file system directory, allowing the database user read
only access.
C. Modify the security list associated with the subnet where the mount target resides. Change the ingress
rules corresponding to the DB System subnet to be stateless.
D. Create an instance principal for the DB System. Write an Identity and Access Management (IAM)
policy that allows the instance principal read-only access to the file storage service.
Answer: A
Question #:48
You are designing a lab exercise for your team that has a large number of graphics with large file sizes. The
application becomes unresponsive if the graphics are embedded in the application. You have uploaded the
graphics to Oracle Cloud Infrastructure and only added the URL in the application. You need to ensure these
graphics are accessible without requiring any authentication for an extended period of time.
A. Create pre-authenticated requests (PAR) and specify 00:00:0000 as the expiration time.
B. Make the object storage bucket private and all objects public and use the URL found in the Object
“Details”.
C. Make the object storage bucket public and use the URL found in the Object “Details”.
Answer: C
20 of 76
Oracle - 1z0-1072
Question #:49
You have an application server that needs to copy data on Oracle Cloud Infrastrucutre (OCI) object storage in
the same region. You have created a service gateway for OCI object storage in your virtual cloud network
(VCN) and modified security lists associated with the subnet to allow traffic to the service gateway. You are
able to connect to the OCI object storage, however, you notice that the connectivity is over the Internet instead
of the service gateway.
A. The route table associated with the subnet has no route rule where the destination is object storage
service
B. The service gateway created in the VCN resides in a different availability domain
C. The security list associated with the subnet has an egress rule that allows all traffic to be forwarded to a
destination CIDR 0.0.0.0/0
D. Identity and Access Management (IAM) policies restrict the access to the object storage bucket
Answer: A
Question #:50
Which two identity providers can your administrator federate with Oracle Cloud Infrastructure? (Choose two.)
Answer: A B
Explanation
References:
Oracle Cloud Infrastructure supports federation with Oracle Identity Cloud Service and Microsoft Active
Directory (via Active Directory Federation Services (AD FS)), and any identity provider that supports the
Security Assertion Markup Language (SAML) 2.0 protocol.
Question #:51
Which two are true for Oracle Cloud Infrastructure DNS? (Choose two.)
A.
21 of 76
Oracle - 1z0-1072
Answer: B C
Explanation
References: B – Support for Oracle Cloud Infrastructure, other Cloud provider endpoints (AWS, Azure) and
private assets, including Cloud, CDNs and Data CentersC – Customers may purchase Oracle Cloud
Infrastructure Private Pool and Vanity Nameserver to have their Domain Names and Zones under a private IP
pool with dedicated nameservers to segregate from those of other customers in order to reduce the risk of
external issues affecting their websites.
https://www.oracle.com/cloud/networking/dns-faq.html
Question #:52
Which two options are available when configuring DNS resolution for your virtual cloud network? (Choose
two.)
C. custom resolver
Answer: C D
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/Database/Tasks/launchingDB.htm
Question #:53
D.
22 of 76
Oracle - 1z0-1072
D. Users can preserve the boot volume associated with the instance.
Answer: D
Question #:54
Which service would you use if your big data workload required shared access and NFS-based connectivity?
A. block volume
B. archive storage
C. object storage
D. file storage
Answer: D
Explanation
References:
Question #:55
NO: 145
You have hired a new employee to run reports from the Autonomous Data Warehouse (ADW) and are not
confident in their SQL writing ability.
Into which consumer group will you assign this individual to minimize the impact of their code?
A. Lowest
B. Medium
C. Highest
D. High
E. Low
Answer: D
Explanation
References:
23 of 76
Oracle - 1z0-1072
Question #:56
In which two ways does Oracle Cloud Infrastructure (OCI) file storage (FSS) differ from OCI object storage
and block volume services? (Choose two.)
B. Object storage and block volume services offer default encryption, but FSS does not
C. A file system is created within an availability domain, whereas object storage buckets exist at the region
level
D. FSS uses the network file system (NFS) protocol, whereas block volume uses iSCSI
Answer: C D
Explanation
References:
Question #:57
B. Setting the variable as key value pairs in a file in a subdirectory named tfvar
D. Setting the environment variable using a TF_VAR_ predicate in front of the variable name
Question #:58
You had an outage in your application caused by the loss of a shared volume provisioned by File Storage
Service (FSS). At this point, you need to restore the data from a snapshot you created of the FSS.
A. Access the directory where the shared volume is mounted, then cd into .snapshot folder, find the
snapshot folder you want to recover and use cp or rsync tool to copy the files to the original location.
B. Open OCI Console, select File Storage Service, find the shared storage, then click on snapshot and
restore.
C. Open OCI Console, select File Storage Service, find the snapshot you created and click restore.
24 of 76
Access the directory where the shared volume is mounted, then cd into .snapshot folder, find the
snapshot folder you want to recover and use cp or rsync tool to copy the files to the original location. Oracle - 1z0-1072
D. Access the directory, where you mounted the shared volume, then cd into .snapshot folder and find the
snapshot folder you want to recover and rename that folder to the original folder name.
Answer: B
Question #:59
Which two statements about fault domains are true? (Choose two.)
Answer: A B
Explanation
References:
Question #:60
Which two tools would you use to manage Database Cloud Service (DBCS)? (Choose two.)
A. psql
B. Oracle Swingbench
C. SQL Developer
Answer: C D
Explanation
References:
Question #:61
Which two statements define the types of DNS resolvers that exist? (Choose two.)
A. A custom resolver allows instances to use the host names of the hosts in your on-prem network that are
25 of 76
Oracle - 1z0-1072
A.
connected to your VCN by an IPSec VPN connection.
B. A VCN resolver allows instances to use the host names of the hosts in your on-prem network that are
connected to your VCN by an IPSec VPN connection.
C. A VCN resolver allows instances to use host names to communicate with instances on other VCNs in
your tenancy.
D. An Internet resolver allows instances to use the host names that are published on the Internet.
Answer: A D
Checkit
Explanation
https://docs.cloud.oracle.com/iaas/Content/Network/Concepts/dns.htm
This is an Oracle-provided option that includes two parts:Internet Resolver: Lets instances resolve hostnames
that are publicly published on the internet. The instances do not need to have internet access by way of either
an internet gateway or a connection to your on-premises network (such as an IPSec VPN connection through a
DRG ).VCN Resolver: Lets instances resolve hostnames (which you can assign) of other instances in the same
VCN. For more information, see About the DNS Domains and Hostnames.By default, new VCNs you create
use the Internet and VCN Resolver. If you’re using the Networking API, this choice refers to the
VcnLocalPlusInternet enum in the DhcpDnsOption object.
The Internet and VCN Resolver does not let instances resolve the hostnames of hosts in your on-premises
network connected to your VCN by IPSec VPN connection or FastConnect. Use your own custom DNS
resolver to enable that.
https://docs.cloud.oracle.com/iaas/Content/Network/Concepts/dns.htm?Highlight=DNS%20resolver#About
Question #:62
You have provisioned an Autonomous Transaction Processing (ATP) database and logged into the ATP
service console.
What are three abilities that can be performed from this service console? (Choose three.)
Answer: C D E
https://www.lkakarla.com/2019/08/oracle-cloud-oci-autonomous-database.html
26 of 76
Oracle - 1z0-1072
Question #:63
NO: 66
You are the Cloud Architect of a company, and are designing a solution on Oracle Cloud Infrastructure where
you want to have all your compute instances resistant to hardware failure.
Which two are recommended best practices to achieve the requirement on Oracle Cloud Infrastructure?
(Choose two.)
A. Create a custom image of your system drive each time you change the image.
B. Attach block volumes from different Availability Domains to compute instances in different Availability
Domains for high availability.
C. Design your system with redundant compute modes in different Availability Domains to support the
failover capability.
D. Create backups of your block volumes that are associated with compute instances in different regions.
Answer: A C
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/Compute/References/bestpracticescompute.htm
System ResilienceOracle Cloud Infrastructure runs on Oracle’s high-quality Sun servers. However, any
hardware can experience a failure. Follow industry-wide hardware failure best practices to ensure the
resilience of your solution. Some best practices include:
Design your system with redundant compute nodes in different availability domains to support fail-over
capability.Create a custom image of your system drive each time you change the image.Back up your data
drives, or sync to spare drives, regularly.If you experience a hardware failure and have followed these
practices, you can terminate the failed instance, launch your custom image to create a new instance, and then
apply the backup data.
Question #:64
You deployed a web server in Oracle Cloud Infrastructure using an ephemeral public IP. After a few changes
in your web server configuration, you rebooted the server and a new public IP was associated to your instance.
A. Create a reserved public IP and associate it with the security list that your complete instance is using
B. Create a reserved public IP and associate it with the subnet of your compute instance
C. Create a reserved public IP and associate it with the VNIC of your compute instance
D.
27 of 76
Oracle - 1z0-1072
D. Create a reserved public IP and associate it with the hosts file of your web server
Answer: C
https://oracle.github.io/learning-library/oci-library/L100-LAB/Using_Reserved_Public_IP/Reserved_Public_IP_HOL.html
Question #:65
You deployed a compute instance (VM.Standard2.16) to run a SQL database. After a few weeks, you need to
increase disk performance by using NVMe disks; the number of CPUs will not change. As a first step you
terminate the instance and preserve the boot volume.
A. Create a new instance using a VM.DenseIO2.16 shape using the preserved boot volume and move the
SQL Database data to block volume
B. Create a new instance using a VM.DenseIO2.8 shape using the preserved boot volume and move the
SQL Database data to NVMe disks
C. Create a new instance using a VM.Standard1.16 shape using the preserved boot volume and move the
SQL Database data to NVMe disks
D. Create a new instance using a VM.DenseIO2.16 shape using the preserved boot volume move the SQL
Database data to NVMe disks
Answer: D
Question #:66
You have an application running on Oracle Cloud Infrastructure. You identified that the read and write
operations are slowing your application down enough to impair user access. The application is currently using
a VM.Standard 1.2 compute without any block storage attached to it.
Which two options allow you to increase disk performance? (Choose two.)
A. Terminate the compute instance preserving the boot volume. Create a new compute instance a VM
Dense IO shape using the boot volume preserved.
B. Terminate the compute instance preserving the boot volume. Create a new compute instance using a VM
Standard shape and attach a new block volume to host your application.
C. Create a backup of the boot volume. Create a new compute instance a VM Dense IO shape and restore
the backup.
D. Terminate the compute instance and create a backup of the boot volume. Create a new compute instance
using a VM Dense IO shape and restore the backup.
Answer: A C
28 of 76
Oracle - 1z0-1072
Question #:67
When deploying a highly available, Internet-facing, 2-tier web application on Oracle Cloud Infrastructure
(OCI), which design option would you use?
A. Deploy all web servers into one Availability Domain and behind a public load balancer, and deploy two
single-node OCI database systems in the same Availability Domain with Data Guard enabled.
B. Deploy all web servers into multiple Availability Domains and behind a public load balancer, and
deploy two single-node OCI database systems across two Availability Domains with Data Guard
enabled.
C. Deploy all web servers into multiple Availability Domains and behind a private load balancer, and
deploy two single-node OCI database systems across two Availability Domains with Data Guard
enabled.
D. Deploy all web servers into one Availability Domain, and deploy a single-node OCI database system
into a different Availability Domain.
Answer: B
Question #:68
Which two are required parameters to create a public load balancer instance? (Choose two.)
A. certificate
C. listener
Answer: C D
Explanation
References: https://docs.cloud.oracle.com/en-us/iaas/Content/GSG/Tasks/loadbalancing.htm
Question #:69
Where do you find the tnsnames.ora for your Autonomous Data Warehouse (ADW) database?
A.
29 of 76
Oracle - 1z0-1072
A. You can download tnsnames.ora from Oracle Cloud Infrastructure web console under ADW details page
B. The tnsnames.ora file is included in credentials.zip file that you download from service console of ADW
C. The ADW database will place the tnsnames.ora file in an object storage bucket
D. You are automatically prompted to download the tnsnames.ora file upon creation of the ADW database
Answer: B
Explanation
https://docs.oracle.com/en/cloud/paas/autonomous-data-warehouse-cloud/user/connect-intorduction.html#GUID-CD4C
Question #:70
A new employee has just started working for your company. You create an Oracle Cloud Infrastructure user
account for this employee, following which they are able to log in, but still cannot create any resources.
C. Make sure that the employee is logging in to the Oracle Cloud Infrastructure account from your
corporate network only.
D. Add the employee to a group with policies to grant access to relevant resources.
Answer: D
Question #:71
Which storage service is used on OCI for a Data Transfer Service job?
B. An object bucket
D. Block Volume
Answer: B
Explanation
30 of 76
Oracle - 1z0-1072
https://docs.cloud.oracle.com/en-us/iaas/Content/DataTransfer/Concepts/overview.htm
Question #:72
You are designing a high bandwidth, redundant connection between your data center and Oracle Cloud
Infrastructure (OCI). While researching for OCI FastConnect locations, you notice that you are co-located
with Oracle at one of the Oracle FastConnect locations in the Ashburn region.
A. Create a cross-connect group and have two or more cross-connects in that group. Create an IPsec VPN
connection on this group.
B. Setup two IPsec connections between your data center and OCI Ashburn region. Create a OCI load
balancer to distribute the traffic across the two connections.
C. Create a cross-connect group and have at least two or more cross-connects in that group. Create at least
two or more virtual circuits in the group.
D. Create a cross-connect group and have at least one cross-connect in that group. Create at least one
virtual circuit in the group.
Answer: C
Question #:73
NO: 120
Your company has been running several small applications in Oracle Cloud Infrastructure and is planning a
proof-of-concept (POC) to deploy PeopleSoft.
If your existing resources are being maintained in the root compartment, what is the recommended approach
for defining security for the upcoming POC?
A. Create a new compartment for the POC and grant appropriate permissions to create and manage
resources within the compartment.
B. Provision all new resources into the root compartment. Grant permissions that only allow for creation
and management of resources specific to the POC.
C. Provision all new resources into the root compartment. Use defined tags to separate resources that
belong to different applications.
D. Create a new tenancy for the POC. Provision all new resources into the root compartment. Grant
appropriate permissions to create and manage resources within the root compartment.
Answer: A
31 of 76
Oracle - 1z0-1072
Explanation
If your organization is small, or if you are still in the proof-of-concept stage of evaluating OracleCloud
Infrastructure, consider placing all of your resources in the root compartment (tenancy). This approach
makes it easy for you to quickly view and manage all your resources. You can still write policies and
create groups to restrict permissions on specific resources to only the users who need access.If you plan
to maintain all your resources in the root compartment, we recommend setting up aseparate sandbox
compartment to give users a dedicated space to try out features. In the sandbox compartment, you can
grant users permissions to create and manage resources, whilemaintaining stricter permissions on the
resources in your tenancy (root) compartment.
https://www.oracle.com/a/ocom/docs/best-practices-for-iam-on-oci.pdf
Question #:74
B. Open port 1521 in the VCN to allow for traffic to the listener
E. Clone a DB
Answer: A C D
Explanation
https://docs.oracle.com/en/cloud/paas/database-dbaas-cloud/csdbi/dbaascli.html
32 of 76
Oracle - 1z0-1072
https://docs.oracle.com/en/cloud/paas/database-dbaas-cloud/csdbi/dbaascli.html
Question #:75
Which two features are offered natively on Oracle Cloud Infrastructure Database Cloud Service (DBCS)?
(Choose two.)
Answer: A D
Explanation
Data Guard in Maximum Performance protection mode is supported not simply Maximum Protection mode,
however, you can configure additional protection modes and transport types by logging on to the DB system
and accessing Data Guard command-line interface( DGMGRL).
Question #:76
You are running your warehouse using Autonomous Data Warehouse (ADW) service and you noticed that a
newly configured batch job is always running in serial even through nothing else is running in the database.
All your jobs are configured to run with parallelism enabled.
What could be the reason for this batch job to run in serial?
A. The batch job depends on only one table and parallelism cannot be enabled on single-table queries.
B. The parallelism of batch job depends on the number of ADW databases involved in the query.
D. The new batch job runs on database tables that are not enable for parallel execution.
Answer: C
Question #:77
What is the maximum IP address size range that you can have in a Virtual Cloud Network?
A.
33 of 76
Oracle - 1z0-1072
A. /16
B. /26
C. /24
D. /8
Answer: A
Explanation
When you create your VCN, you assign a contiguous IPv4 CIDR block of your choice. VCN sizes ranging
from /16 (65,533 IP addresses) to /30 (1 IP address) are allowed. Example: 10.0.0.0/16, 192.168.0.0/24.
Question #:78
A. Python
B. Go
C. C
D. Ruby
Answer: B
Explanation
References: https://www.terraform.io/docs/extend/writing-custom-providers.html
Question #:79
C. block volume
Answer: D
34 of 76
Oracle - 1z0-1072
Question #:80
Which three actions need to be performed before attempting a data transfer service job?
A. Obtain an available host machine which can run the dts utility on-premise with SATA or USB drives
attached for the transfer job.
C. Data Transfer Service and Storage Service Limits should be checked and raised if required.
Answer: A C E
Question #:81
Which three must be configured for a load balancer to accept incoming traffic? (Choose two.)
A. a listener
B. a back-end server
E. a certificate
Answer: A B C
Explanation
https://docs.cloud.oracle.com/iaas/Content/Balance/Tasks/managingloadbalancer.htm?tocpath=Services%7CLoad%20B
The essential components for load balancing include:• A load balancer with pre-provisioned bandwidth.• A
backend set with a health check policy. See Managing Backend Sets.• Backend servers for your backend set.
See Managing Backend Servers.• One or more listeners . See Managing Load Balancer Listeners.• Load
balancer subnet security rules to allow the intended traffic. To learn more about these rules, see Security
Rules.• Optionally, you can associate your listeners with SSL server certificate bundles to manage how your
system handles SSL traffic. See Managing SSL Certificates.
Question #:82
Which three types of credentials are used to manage Oracle Cloud Infrastructure Identity and Access
Management (IAM)? (Choose three.)
35 of 76
Oracle - 1z0-1072
A. Windows Password
C. Swift Password
D. SSH Key
E. Console Password
Answer: B C E
Explanation
References: https://cloud.oracle.com/iaas/whitepapers/best-practices-for-iam-on-oci.pdfYou manage the
following types of credentials with Oracle Cloud Infrastructure IAM:Console password: For signing in to the
Console, which is the user interface for interacting with Oracle Cloud InfrastructureAPI signing key (in PEM
format): For sending API requests, which require authenticationSwift password: For using a Swift client with
Recovery Manager (RMAN) to back up an Oracle Database System (DB System) database to Object Storage
Question #:83
Given: When creating multiple subnets within a Virtual Cloud Network (VCN), security lists are often made to
group common services, for example, SSH and RDP (remote access), 80 and 443 (HTTP), and so on.
By default, what is the maximum number of security lists that can be associated with a subnet upon creation?
A. 4
B. 2
C. 5
D. 3
Answer: C
Explanation
References:
Question #:84
Within your tenancy you have a compute instance with a boot volume and a block volume attached. The boot
volume contains the OS and the attached block volume contains the instance’s important data. Logs on the
boot volume have filled the boot volume and are causing issues with the OS.
36 of 76
Oracle - 1z0-1072
A. Stop the instance that is full. Create a manual backup of the block storage before making changes.
Detach the block volume, create a new instance of the same shape with a larger custom boot volume and
attach the block volume to the new instance. Configure the OS and any related application(s) to access
the block volume under the same mount point as before.
B. Create a new instance with a larger boot volume size as well a new block volume which is the same size
or larger than the one attached to the full instance. rsync the state of the boot volume and the state of the
block volume between the two instances.
C. Detach the block volume from the full instance. Create a new instance of the same shape with a larger
boot volume and rsync the state of the boot volume between the instances. Attach the block volume to
the new instance.
D. Create a manual backup of the block storage instance. Create a custom image of the full instance. Once
that completes deploy the custom image to a new instance.
Answer: A
Explanation
https://docs.cloud.oracle.com/en-us/iaas/Content/Block/Tasks/resizingavolume.htm
Question #:85
As the Cloud Architect for your company, you have been tasked with designing a high performance (HPC)
cluster in Oracle Cloud Infrastructure (OCI). The following requirements have been defined:
The cluster must be a minimum of three nodes, but may increase to six nodes when demand requires.
To minimize latency, all nodes must be deployed within the same availability domain (AD).
Adding or replacing nodes within the cluster should take no more than 30 minutes.
Which two steps should be performed to satisfy these requirements in OCI? (Choose two.)
A. Deploy the cluster in a single AD with a shared file system that leverages the file storage service (FSS).
Deploy a standby cluster in another AD and configure it to use the same shared file system.
B. Deploy the cluster in a single AD. Place each of the nodes in one of the three different fault domains in
that AD.
C. Create a backup of your HPC node compute instance boot volume. Launch new compute instances
directly from the backup reduce provisioning time.
D. Create a custom image of your HPC node compute instance. Launch new compute instances using this
image to reduce provisioning time.
E.
37 of 76
Oracle - 1z0-1072
E. Deploy the cluster in a single AD. Place each of the nodes in a different virtual cloud network (VCN)
subnet.
Answer: A D
Question #:86
An instance is launched with a primary VNIC that is created during instance launch.
Which two operations are true when you add secondary VNICs to an existing instance? (Choose two.)
A. You can remove the primary VNIC after the secondary VNIC’s attachment is complete.
C. The primary and secondary VNIC association should be within the same Availability Domain.
Answer: B C
Explanation
https://docs.cloud.oracle.com/iaas/Content/Network/Tasks/managingVNICs.htm
Question #:87
NO: 133
What is true about data guard set up with fast-start failover (FSFO) in Oracle Cloud Infrastructure (OCI)?
A. The best practice for high availability and durability is to run the primary, standby, and observer in
separate availability domains (ADs).
B. When you configure data guard using OCI console, the default mode is set to maxprotection.
C. You cannot create the standby DB system in a different AD from the primary DB system.
D. You cannot use database command line interface (CLI) to set up data guard with FSFO.
Answer: A
Explanation
References:
Question #:88
38 of 76
Oracle - 1z0-1072
D. installing the operating system (OS), Grid Infrastructure, and database software
Answer: A
Explanation
On autonomous there’s no patching needed. But on the regular DB Cloud services you need to patch the DB
and the OS. During the creation on the OCDB the first DB is created automatically
Question #:89
Which two resources are available by default when your Oracle Cloud Infrastructure tenancy is provisioned?
A. an NVMe SSD boot disk for each instance, whose size is determined by the image and shape of the
instance
C. a set of images, where each image is a template of a virtual hard drive that consists of the OS and
installed software and applications
D. a variety of shapes, where each shape determines the number of CPUs and memory allocated to an
instance.
Answer: C D
Question #:90
Which two statements are true about data guard service on DB Systems in Oracle Cloud Infrastructure (OCI)?
A. Data guard implementation requires two DB Systems, one running the primary database on a virtual
machine and the standby database running on bare metal.
B. Data guard implementation requires two DB Systems, one containing the primary database and one
containing the standby database.
D. Both DB Systems must use the same VCN, and port 1521 must be open.
39 of 76
Oracle - 1z0-1072
Answer: B D
Explanation
References:
Question #:91
Your company has decided to move a few applications to Oracle Cloud Infrastructure (OCI) and you have
been asked to design a cloud-based disaster recovery (DR) solution. One of the requirements is to deploy the
DR resources at least 300 miles from the home OCI region and minimize the network latency.
A. Deploy production and DR applications in the same VCN. Create production subnets in one AD, and
DR subnets in another AD.
B. Deploy production and DR applications in two separate VCNs in different availability domains (ADs)
within your home region, and then use a VCN remote peering connection for connectivity.
C. Deploy production and DR applications in two separate VCNs, each in different regions. Connect them
using a VCN remote peering connection.
D. Deploy production and DR applications in two separate virtual cloud networks (VCNs), each in different
regions, and then use VCN local peering gateways for connectivity.
Answer: C
Question #:92
B. If you delete a user, and them create a new user with the same name, the user will be considered a
different user because of different OCIDs.
C. Users can customize OCIDs for all the resources in their compartments.
D. If you delete a user, and then create a new user with the same name, the new user will be assigned the
exact same OCIDs as the system remembers.
Answer: B
Explanation
References:
40 of 76
Oracle - 1z0-1072
Question #:93
Which two resources reside exclusively in a single availability domain? (Choose two.)
A. compute instance
B. block volume
C. object storage
D. groups
Answer: A B
Question #:94
You are deploying a highly available web application In Oracle Cloud Infrastructure and have decided to use a
public load balancer. The back-end web servers will be distributed across all three availability domains (ADs).
How many subnets should you create to deliver a secure, highly available application?
A. two subnets in total; one regional private subnet to host your back-end web servers and one regional
public subnet to host your public load load balancer.
B. two subnets in total; one regional public subnet to host your back-end web servers and one regional
private subnet to host your public load load balancer.
C. three subnets in total; one regional public subnet to host your back-end web servers and two AD specific
private subnets to host your private load load balancer.
D. one subnet in total; one regional private subnet to host your back-end web servers and your public load
balancer.
five subnets in total; two subnets each in the first and
Answer: C second AD with a single subnet in the third AD
Question #:95
What is the maximum CIDR range that can be assigned when configuring a Virtual Cloud Network?
A. /16
B. /26
C. /24
D. /8
41 of 76
Oracle - 1z0-1072
Answer: A
Explanation
References:
Question #:96
A. Python
B. RPM
C. APT
D. PIP
Answer: D
Explanation
References:
https://docs.cloud.oracle.com/iaas/Content/API/SDKDocs/climanualinst.htm
Question #:97
You are deploying a highly available web application in Oracle Cloud Infrastructure and have decided to use a
public load balancer. The back-end web servers will be distributed across all three availability domains (ADs).
How many subnets should you create to deliver a secure highly available application?
B. five subnets in total; two subnets each in the first and second AD with a single subnet in the third AD
C. six subnets in total; two subnets in each AD; one for the load balancer and one for the web servers
D. four subnets in total; one subnet in each AD for the web servers and a single subnet in any one AD for
the load balancer
As Web servers are placed in different ADs, so - 3 Subnet
Answer: C For load balancer , i 2 subnets are required {one is primary and one is
standby} in two different ADs, in case of regional subnet only one subnet will
be required, however here the question is related with AD specific subnets
so total required subnets will be 5.
Question #:98
Which two statements are true about Oracle Cloud Infrastructure Compute Service? (Choose two.)
42 of 76
Oracle - 1z0-1072
A. You can launch a virtual or bare metal instance by using the same LaunchInstance API.
B. You cannot launch a bare metal server in Oracle Cloud Infrastructure Compute Service.
C. You can attach a block volume in an Availability Domain other than your compute instance.
Answer: A D
Explanation
References:
Regions and Availability DomainsVolumes are only accessible to instances in the same availability domain .
You cannot move a volume between availability domains or regions.
FYI: https://docs.cloud.oracle.com/iaas/Content/Block/Concepts/overview.htm
Question #:99
Which three actions are required to configure a highly available and secure hybrid network between Oracle
Cloud and your data center? (Choose three.)
A. Define a non-overlapping IP Address Space between the data center and the cloud.
B. Configure each of the CPEs to leverage each of the IPSec Tunnels created by the connection process.
C. Create two or more CPEs that map to the private IP addresses of the customer routers used in the IPSec
VPN Tunnel.
D. Define a default route table entry for the VCN that directs all traffic to the data center network to a
single DRG.
E. Create dynamic routing gateways in more than one AD within your region.
Answer: A B C
Explanation
https://docs.cloud.oracle.com/iaas/Content/Network/Tasks/configuringCPE.htm
Question #:100
You need to create a high performance shared file system, and have been advised to use file storage service
(FSS). You have logged into the Oracle Cloud Infrastructure console, created a file system, and followed the
steps to mount the shared file system on your Linux instance. However, you are still unable to access the
shared file system from your Linux instance.
43 of 76
Oracle - 1z0-1072
C. There is no Identity and Access Management (IAM) policies set up to allow you to access the mount
target
D. There is no route in your virtual cloud network’s (VCN) route table for mount target traffic
Answer: A
Explanation
Virtual firewall rules for your VCN. Your VCN comes with a default security list, and you can add more.
These security lists provide ingress and egress rules that specify the types of traffic allowed in and out of the
instances. You can choose whether a given rule is stateful or stateless. Security list rules must be set up so that
clients can connect to file system mount targets. For more information about how security lists work in Oracle
Cloud Infrastructure, see Security Lists in the Networking documentation. For information about setting up
specific security list rules required for mount target traffic, see Configuring VCN Security List Rules for File
Storage. About Security explains how security lists interact with other types of security in your file system.
https://docs.cloud.oracle.com/iaas/Content/File/Concepts/filestorageoverview.htm
Question #:101
C. You have full control over the automatic backup schedule and retention periods.
Answer: A C
Question #:102
Which five are the required parameters to launch an instance in Oracle Cloud Infrastructure? (Choose five.)
A. subnet
B. Availability Domain
C.
44 of 76
Oracle - 1z0-1072
D. host name
E. instance shape
G. private IP address
Answer: A B C E F
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/Compute/Concepts/computeoverview.htm
Question #:103
ESTION NO: 36
When terminating a compute instance, you want to preserve the boot volume and its data.
A. You cannot preserve the boot volume; it will always be deleted when you terminate the instance.
C. Disable the default option to delete the boot volume when terminating an instance.
D. Before terminating the instance, you must detach the boot volume.
Answer: C
Explanation
References: The dialog will show you when you terminate the instance. If you want to preserve the boot
volume associated with the instance, uncheck Permanently delete the attached Boot Volume.
https://docs.cloud.oracle.com/iaas/Content/Compute/Tasks/terminatinginstance.htm
Question #:104
A customer wants to do development on premise while leveraging services such as Java Cloud, Mobile
Developer Cloud, and App Builder Services. The customer would also like to scale out the application,
stretching from on-premises to the cloud by using a common API.
Which two Infrastructure options can the customer leverage to do this? (Choose two.)
A.
45 of 76
Oracle - 1z0-1072
Answer: A D
Question #:105
You want an Oracle Cloud Infrastructure (OCI) compute instance in your compartment to make API calls to
other services within OCI without storing credentials in a configuration file.
A. Create a dynamic group with appropriate matching rules to include the instance, and reference this
group in your IAM policy statement
C. VM instances are treated as users. Create a user, assign the user to that VM instance, and reference the
instance in your Identity and Access Management (IAM) policy statement
D. By default, all VM instances are created with an instance principal. Reference this instance principal in
your IAM policy statement
Dynamic groups allow you to group Oracle Cloud Infrastructure computer instances as "principal" actors
Answer: A (similar to user groups). You can then create policies to permit instances to make API calls against Oracle
Cloud Infrastructure services. When you create a dynamic group, rather than adding members explicitly to the
group, you instead define a set of matching rules to define the group members.
Question #:106
Which DNS resource record type is used to point a host name to an IPv4 address?
A. ALIAS
B. A
C. CNAME
D. AAAA
Answer: B
Explanation
References:
https://docs.cloud.oracle.com/iaas/Content/DNS/Reference/supporteddnsresource.htm?tocpath=Services%7CDNS%7C
46 of 76
Oracle - 1z0-1072
Question #:107
References:
Question #:108
You have been notified of an application failure indicating that one or more of the Oracle Cloud Infrastructure
(OCI) resources have become unavailable. After scanning the Compute and Database consoles, you notice that
one of the DB Systems is missing.
What would you do to identify the reason for this missing resource?
A. Navigate to the Audit console and search the previous 24 hours for all Delete actions to get a list of any
resource that was deleted in the past 24 hours.
B. Create a serial console connection to the DB System that does not appear in the management console.
Connect to the serial console connection, and then review the system logs under /var/log/messages.
C. View the service limits associated with your account to ensure that you have not exceeded the available
number of DB system in your tenancy.
D. Navigate to the Audit console and search the previous 24 hours for all List actions to get a list of every
event that occurred in the past 24 hours.
A is correct answer since dB system is missing. It means dB
Answer: D
system is deleted
Question #:109
You are designing a two-tier web application in Oracle Cloud Infrastructure (OCI). Your clients want to access
the web servers from anywhere, but want to prevent access to the database servers from the Internet.
47 of 76
Oracle - 1z0-1072
A. Create public subnets for web servers and private subnets for database servers in your virtual cloud
network (VCN), and associate separate internet gateways for each subnet.
B. Create public subnets for web servers and associate a dynamic routing gateway with that subnet, and a
private subnet for database servers with no association to dynamic gateway.
C. Create public subnets for web servers and private subnets for database servers in your VCN, and
associate separate security lists and route tables for each subnet.
D. Create a single public subnet for your web servers and database servers, and associate only your web
servers to internet gateway.
Answer: C
Question #:110
You have created a public subnet in a VCN, and your public subnet has a Route Table, a Security List, and an
Internet Gateway. However, none of the compute instances can connect to the Internet.
Which two are possible reasons for the connectivity issue? (Choose two.)
B. The Route Table has no default route for routing traffic to the Internet Gateway.
C. There is no stateful ingress rule in the Security List associated with the public subnet.
D. There is no stateful egress rule in the Security List associated with the public subnet.
Question #:111
For a compute instance that is launched in a private subnet in a Virtual Cloud Network (VCN), which action
needs to be performed to connect to the Internet, assuming that the required security list is properly set up?
B. Create and configure Network Address Translation (NAT) in a public subnet and route all traffic to it.
D. Create a default route entry in the route table to forward all traffic to the Internet gateway.
A and C are definitely not correct.
Answer: D B. Not correct : It says create NAT in public subnet. You can’t create a NAT gateway in public subnet. NAT is
usually created and attached to the VCN. Typically a private subnet will send the traffic through NAT. This
makes B not a valid option.
D is not the most ideal choice to implement the solution. This is the best choice out of the options given!
48 of 76
Oracle - 1z0-1072
Question #:112
When creating a subnet, one or more placeholder security lists are often associated with the subnet. Why?
C. Each network endpoint or instance in the subnet needs its own security list.
Answer: C
Explanation
References:
https://docs.cloud.oracle.com/iaas/Content/Network/Concepts/securitylists.htm?tocpath=Services%7CNetworking%7C
Question #:113
You are responsible for creating and maintaining an enterprise application that consists of multiple storage
volumes across multiple instances. The storage volumes include boot volumes and block volumes for your
data storage. You need to create backups of these storage volumes in the most time-efficient manner.
B. You can group together multiple storage volumes in a volume group and create volume group backups
C. You can create on-demand one-off backups of boot volumes, but not block volumes
D. You can create on-demand one-off backups of block volumes, but not boot volumes
Answer: B
Question #:114
Which resource is required when connecting to your on-premise network from your Virtual Cloud Network
(VCN) via IPSec VPN or FastConnect?
D.
49 of 76
Oracle - 1z0-1072
D. NAT
Answer: B
Explanation
References: https://cloud.oracle.com/networking/vcn/faq
Question #:115
Which statement is true about restoring a block volume from a manual or policy-based block volume backup?
A. It can be restored as new volumes to any Availability Domain within the same region.
B. It must be restored as new volumes to the same Availability Domain on which the original block volume
backup resides.
C. It can be restored as new volumes to any Availability Domain across different regions.
D. It can be restored as new volumes with different sizes from the backups.
A,D
Answer: A
A – Backups are encrypted and stored in Oracle Cloud Infrastructure Object Storage, and can be
restored as new volumes to any availability domain within the same region they are stored.
Explanation
D- You can restore a block volume backup to a larger volume size. To do this, check Custom Block
References: Volume Size (GB), and then specify the new size. You can only increase the size of the volume, you
cannot decrease the size.
Question #:116
Which two statements are true about Database Cloud Service (DBCS)? (Choose two.)
Answer: B C
Explanation
References: https://cloud.oracle.com/database/faq#backup
Can I set up Data Guard across Availability Domains?Yes, you can set up Data Guard in the same or different
Availability Domains in a region. However, Oracle recommends that you set up your Data Guard
configuration across Availability Domains.Can I set up Data Guard across Oracle Cloud Infrastructure
regions?Yes, you can set up Data Guard across regions,
50 of 76
Oracle - 1z0-1072
“but the Database Cloud Service Data Guard feature currently does not support it. ”
You can manually set up Data Guard across regions by logging on to your host and using DGMGRL. You
must enable an internet gateway on the primary and standby DB system VCN for Data Guard to transport logs
across regions. Learn more about DGMGRL.
To configure a Data Guard system across regions or between on-premises and Oracle Cloud Infrastructure DB
systems, you must access the database host directly and use the DGMGRL utility.
https://docs.cloud.oracle.com/iaas/Content/Database/Tasks/usingdataguard.htm
Question #:117
Answer: D
Explanation
Identity > Compartments >(The root Compartment of the tenancy)
Question #:118
Which storage would you use if your big data workload requires shared access and an NFS based interface?
A. File Storage
C. Object Storage
Use the File Storage service when your application or workload
D. Archive Storage includes big data and analytics, media processing, or content
management, and you require Portable Operating System
Interface (POSIX)-compliant file system access semantics and
E. Block Volume concurrently accessible storage.
Answer: A
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/File/Concepts/filestorageoverview.htm
51 of 76
Oracle - 1z0-1072
Question #:119
You are an administrator with an application running on OCI. The company has a fleet of OCI compute virtual
instances behind an OCI Load Balancer. The OCI Load Balancer Backend Set health check API is providing a
‘Critical’ level warning. You have confirmed that your application is running healthy on the backend servers.
A. A user does not have correct IAM credentials on the Backend Servers.
B. The Backend Server VCN’s Route Table does not include the route for OCI LB.
D. The Backend Server VCN’s Security List does not include the IP range for the source of the health
check requests.
Answer: D
Explanation
References:
“In this case, your security rules might not include the IP range for the source of the health check requests.
You can find the health check source IP on the Details page for each backend server. You can also use the API
to find the IP in the sourceIpAddress field of the HealthCheckResult object.”
https://docs.cloud.oracle.com/iaas/Content/Balance/Tasks/editinghealthcheck.htm#health-status
Question #:120
Which two options are available when setting up DNS for your bare metal and virtual machine DB Systems?
(Choose two.)
C. custom resolver
Answer: C D
Explanation
References:
52 of 76
Oracle - 1z0-1072
Question #:121
You have successfully configured identity federation between Oracle Cloud Infrastructure (OCI) and Oracle
Identity Cloud Services (IDCS). A new project manager wants access to OCI for her team and provides the
name of an existing group within IDCS to use when granting access.
How do you configure federation to allow the project team access to OCI resources?
A. Create a new IAM group in OCI and map it to the existing IDCS group. Create a new policy in IDCS
and reference the name of the IAM group.
B. Create a new Identity and Access Management (IAM) policy in OCI and reference the name of the
IDCS group in each policy statement.
C. Create a new compartment in OCI with the same name as the existing IDCS group. Create an IAM
policy that references the new compartment and the name of the IDCS group.
D. Create a new IAM group in OCI and map it to the existing IDCS group. Create a new IAM policy and
reference the name of the IAM group in each policy statement.
Answer: D remember
Question #:122
A. You can use read, write, manage, and inspect as verbs for defining a policy.
B. A policy is a document that specifies who can access which Oracle Cloud Infrastructure resources that
your company has, and how.
C. Users need not do anything but still have to be added to a group with appropriate policies defined.
Answer: B C
Explanation
References:
https://docs.cloud.oracle.com/iaas/Content/Identity/Concepts/policies.htm
Question #:123
Which two are a valid image source when launching a new compute instance? (Choose two.)
B.
53 of 76
Oracle - 1z0-1072
B. object storage
C. custom image
D. boot volume
Answer: C D
Explanation
https://docs.cloud.oracle.com/en-us/iaas/Content/Resources/Assets/whitepapers/deploying-custom-os-images.pdf
Question #:124
Which scaling option does Database Cloud Service (DBCS) on Bare Metal Shape offer?
A. network bandwidth
B. CPU
C. storage
D. memory
Answer: B
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/Database/Tasks/managingDBsystem.htm
Question #:125
B. A cloned volume is the same as a snapshot that has a dependency on the source volume.
C. You cannot change the block volume size when cloning a volume.
Answer: B
D is wrong You can only create a clone for a volume within the same region,
availability domain and tenant.
Explanation A is wrong because you can clone volume on fly
B is wrong, because cloned vol doesnt depend on source vol
References: C is correct while cloing you can able to increase block vol size
54 of 76
Oracle - 1z0-1072
Question #:126
Which statement is true about Oracle Cloud Infrastructure (OCI) object storage support for server-side
encryption?
A. You must manually enable server-side encryption for each object as you upload to OCI object storage
B. Objects are automatically encrypted as they are uploaded to object storage and decrypted upon retrieval
C. You must manually decrypt the data when retrieving from OCI object storage
D. Only the object data is encrypted and the user-defined metadata that is associated with the object is not
encrypted
Answer: B
Explanation
References: https://www.oracle.com/cloud/storage/object-storage-faq.html
Question #:127
A. A database name cannot be used concurrently for both an Autonomous Data Warehouse (ADW) and an
ATP database
B. After terminating a database, the database name is available for immediate reuse
Answer: A
You cannot use the same database name concurrently for both an
Explanation Autonomous Data Warehouse and an Autonomous Transaction Processing
database.
References:
https://docs.cloud.oracle.com/en-us/iaas/Content/Database/Tasks/adbcreatin
g.htm
Question #:128
What is a “transfer package” when transferring data to OCI via the OCI Data Transfer Service?
A. A transfer package is the logical representation of the physical shipment containing the HDD transfer
devices that you ship to Oracle to upload to OCI.
B. A transfer package is the software Oracle provides for you to prepare transfer devices for shipment to
Oracle
C.
55 of 76
Oracle - 1z0-1072
D. A transfer package is the archive file that the Data Transfer Service Utility (dts) writes to the transfer
device.
Answer: A
Explanation
References:
https://blogs.oracle.com/cloud-infrastructure/introducing-oracle-cloud-infrastructure-data-transfer-service
Question #:129
Which two options are valid for loading data directly into Autonomous Data Warehouse (ADW)? (Choose
two.)
Loading Data with Autonomous Data Warehouse
A. Data Integrator Describes packages and tools to load data with Autonomous Data
Warehouse.
B. Data Pump Topics
Question #:130
Which two statements are true about the Oracle Cloud Infrastructure Object Storage Service? (Choose two.)
Answer: D E
Explanation
56 of 76
Oracle - 1z0-1072
STRONG CONSISTENCYWhen a read request is made, Object Storage always serves the most recent copy
of the data that was written to the system.DURABILITYObject Storage is a regional service. Data is stored
redundantly across multiple storage servers. Object Storage actively monitors data integrity using checksums
and automatically detects and repairs corrupt data. Object Storage actively monitors and ensures data
redundancy. If a redundancy loss is detected, Object Storage automatically creates more data copies. For more
details about Object Storage durability, see the Oracle Cloud Infrastructure Object Storage FAQ.CUSTOM
METADATAYou can define your own extensive metadata as key-value pairs for any purpose. For example,
you can create descriptive tags for objects, retrieve those tags, and sort through the data. You can assign
custom metadata to objects and buckets using the Oracle Cloud Infrastructure CLI or SDK. See Software
Development Kits and Command Line Interface for details.ENCRYPTIONObject Storage employs 256-bit
Advanced Encryption Standard (AES-256) to encrypt object data on the server. Each object is encrypted with
its own key. Data encryption keys are encrypted with a master encryption key that is frequently rotated.
Encryption is enabled by default and cannot be turned off.
Question #:131
NO: 157
You must implement a backup solution for your Autonomous Data Warehouse (ADW) that will enable you to
restore data as old as one year with a recovery point objective (RPO) of 10 days.
A. Take weekly manual backups to supplement the automated backups and preserve them for 12 months.
C. Take monthly manual backups to supplement the automated backups and preserve them for 12 months.
D. Take quarterly manual backups to supplement the automated backups and preserve them for 12 months.
Answer: A
Question #:132
Which three components can you configure in Oracle Infrastructure Identity and Access Management?
(Choose three.)
A. Groups
B. Users
C. Instances
D. Policies
E. VCNs
57 of 76
Oracle - 1z0-1072
Answer: A B D
Explanation
References: https://cloud.oracle.com/governance/identity/faq
Question #:133
Your company is developing a new database application in Oracle Cloud Infrastructure. You need to test
application functionality including a hardware failure scenario. Since the application is still in the development
phase, you want to minimize infrastructure costs.
B. Autonomous Data Warehouse (ADW) system as it provides auto fail over functionality
Answer: A
Explanation
References:
Question #:134
You are managing a tier-1 OLTP application on an Autonomous Transaction Processing (ATP) database. Your
business needs to run hourly batch processes on this ATP database that may consume more CPUs than what is
available on the server.
How can you limit these batch processes to not interfere with the OLTP transactions?
A. Copy OLTP data into new tables in a new table space and run batch processes against these new tables
B. ATP is designed for OLTP workload only; you should not run batch processes on ATP
D. Configure ATP resource management rules to manage runtime and IO consumption for the consumer
group of batch processes
Answer: D
Explanation
58 of 76
Oracle - 1z0-1072
References:
Question #:135
Why are two subnets required to create a public load balancer when additional subnets are often used for
back-end servers? (Choose two.)
A. Routing is simpler when the load balancer is not in the same subnet as the back-end server.
C. Additional subnets for back-end servers allow for separate route tables for these servers.
D. Additional subnets for back-end servers allow for separate security lists for these servers.
Answer: B D
Explanation
References:
http://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/ocis/load-balancer/load-balancer.html
Question #:136
Which two are required to create an IPSec VPN connection? (Choose two.)
A. security list
C. name
D. compute instance
Answer: A B
Explanation
References:
Question #:137
Your Operations team has recently created a new, standard image that will be used to launch all new
application servers in the Finance compartment. The custom image currently exists in the Operations
compartment. You have access to manage all-resources in the Finance compartment and do not have access to
the Operations compartment.
59 of 76
Oracle - 1z0-1072
Which two methods would make the new image available for you to use when deploying new servers in the
Finance compartment? (Choose two.)
A. Instruct the Operations team to reassign the custom image to the Finance compartment so you can select
it from a drop-down list when launching new compute resources.
B. Instruct the Operations team to export the image to an object storage bucket, create a pre-authenticated
request (PAR), and provide you with the URL. Download the custom image to your laptop and import it
as a custom image in the Finance compartment.
C. Instruct the Administrators team to grant you access to use instance-images in the Operations
compartment. Use the Oracle Cloud Identifier (OCID) of the custom image when launching new
compute resources in the Finance compartment.
D. Instruct the Operations team to export the image to an object storage bucket, create a PAR, and provide
you with the URL. Use that URL as the source when importing a custom image. Import the custom
image into the Finance compartment.
E. Instruct the Operations team to export the image to an object storage bucket. Instruct the Administrators
team to grant you access to the object storage bucket where the custom image is stored. Use the
download URL of the custom image as the image source when launching new compute resources in the
Finance compartment.
Answer: C E
Question #:138
B. by adding users to a group and defining a policy to provide the group access to the compartment
C. by adding users to a compartment. All users in the compartment will have access to the objects in the
compartment.
Answer: B
Question #:139
A. variable
B. region
60 of 76
Oracle - 1z0-1072
C. metadata
D. instance
E. resource
F. data source
Answer: A E F
Question #:140
Which deployment architecture is offered when you deploy the Platform Service Manager based Database
Cloud Service (DBCS) onto Oracle Cloud Infrastructure?
A. Two node Primary RAC database leveraging ACFS for the shared file system
B. Single Instance database with a Single Instance Data Guard in Maximum Performance mode
C. Single Instance database with a Single Instance Data Guard in Maximum Protection mode
D. Two node Primary RAC database with a two node RAC Data Guard Standby in Maximum Performance
mode
Answer: D
Question #:141
You are about to upload log file (5 TiB size) to Oracle Cloud Infrastructure object storage and have decided to
use multipart upload capability for a more efficient and resilient upload.
Which two statements are true about multipart upload? (Choose two.)
B. While a multipart upload is still active, you cannot add parts even if the total number of parts is less than
10,000
D. You do not have to commit the upload after you have uploaded all the object parts
With multipart upload, you split the object you want to upload into individual parts. Individual parts can be as large as 50 GiB or as
small as 10 MiB. (Object Storage waives the minimum part size restriction for the last uploaded part.) Decide what part number
Answer: A C you want to use for each part. Part numbers can range from 1 to 10,000. You do not need to assign contiguous numbers, but
Object Storage constructs the object by ordering part numbers in ascending order.
Explanation
The maximum size for an uploaded object is 10 TiB. Object parts must be no larger than 50 GiB.
https://docs.cloud.oracle.com/iaas/Content/Object/Tasks/usingmultipartuploa
ds.htm
61 of 76
Oracle - 1z0-1072
References:
Question #:142
A customer has launched a compute Instance in the Virtual Cloud Network (VCN), which has an Internet
gateway, a service gateway, a default security lists and a default route table. Customer has opened up Port 22
in the security lists attached to the compute instance subnet, however is still unable to connect to compute
instances using ssh.
A. Modify the route table associated with the VCN subnet in which the instance resides. Add a following
route to the route table.
B. Modify the security list associated with the VCN subnet in which the instance resides. Add a stateful
egress rule to allow icmp traffic in addition to the port 22.
C. Modify the route table associated with the VCN subnet in which the instance resides. Add a following
route to the route table.
D. Modify the route table associated with the VCN subnet in which the instance resides. Add a following
route to the route table.
Answer: D
Question #:143
B. It shows the operator the course of action that would be taken if a change is applied.
62 of 76
Oracle - 1z0-1072
Answer: B
Explanation
References:
The terraform plan command is used to create an execution plan. Terraform performs a refresh, unless
explicitly disabled, and then determines what actions are necessary to achieve the desired state specified in the
configuration files.
This command is a convenient way to check whether the execution plan for a set of changes matches your
expectations without making any changes to real resources or to the state. For example, terraform plan might
be run before committing a change to version control, to create confidence that it will behave as expected.
Question #:144
You are designing a shared storage solution for your company in Oracle Cloud Infrastructure. The proposed
storage solution should allow users to create a hierarchical structure (similar to the directory structure in Linux
or Windows based systems). The solution should provide data encryption and a large amount of storage space.
A. Use block storage. Create and attach a large block storage volume to one compute instance. Assign a
public IP to the compute instance. Store data on the block storage and access it by connecting to the
compute instance.
B. Use object storage. Create a single namespace and multiple buckets to create the hierarchical directory
structure.
C. Use object storage. Create multiple namespaces with one bucket each. Make the buckets publicly
accessible.
D. Use file storage service. Create a file system and a mount target. Share the private IP of the mount
target.
Answer: D
Question #:145
You have created a public subnet and an internet gateway in your virtual cloud network (VCN). The public
subnet has an associated route table and security list. However, after creating several compute instances in the
public subnet, none can reach the Internet.
Which two are possible reasons for the connectivity issue? (Choose two.)
A. The route table has no default route for routing traffic to the internet gateway
B. There is no stateful egress rule in the security list associated with the public subnet
63 of 76
Oracle - 1z0-1072
D. There is no stateful ingress rule in the security list associated with the public subnet
Answer: B D
Explanation
https://docs.cloud.oracle.com/iaas/Content/Network/Concepts/securitylists.htm
Question #:146
A. Create resources in the right order without regard to the order in the terraform plan file.
B. Automatically re-provision the resources that are tainted or whose configuration has changed.
Answer: A B D
Question #:147
You have an external facing web server running in the Oracle Cloud Infrastructure (OCI) London region. You
are notified that customers in North America and Australia are facing high latency while connecting to your
web server.
Which services are available on OCI that can help you get current latency statistics to your web server from
these markets?
A. Use DNS Zone Management service to check latency over that connection
B. Setup an IPsec VPN with customers in those markets and check latency over that connection
C. Use the Internet Intelligence tool. Run tests using the web server’s public IP address and review
traceroute details from different vantage points
D. Setup a FastConnect with customers in those markets and check latency over that connection
Answer: C
Explanation
64 of 76
Oracle - 1z0-1072
The second tool, OCI IP Troubleshooting, helps troubleshoot issues with public facing IP addresses.
This feature is also part of our Internet Intelligence toolset, providing analytical insight to help network
operations teams reduce the time it takes to troubleshoot an issue by providing awareness of availability
and latency across the Internet.
Ref:
https://blogs.oracle.com/cloud-infrastructure/internet-intelligence,-now-available-in-the-oracle-cloud-infrastruct
Question #:148
You create a public Load Balancer instance and configure a back end set “BES1” with one back end server
running a service on port 80. You also create a listener on port 80 and configure that listener to use the back
end set “BES1”. A client makes one HTTP request to the Load Balancer with the correct protocol and port.
A. 1
B. 2
C. 4
D. 3
Answer: B
Question #:149
Which two parameters are required in a back end set’s HTTP health check? (Choose two.)
A. response body
B. URL path
C. timeout
D. port
E. status code
Answer: B D
Explanation
https://docs.cloud.oracle.com/iaas/Content/GSG/Tasks/loadbalancing.htm#Create
65 of 76
Oracle - 1z0-1072
Load Balancing automatically checks the health of the instances for your load balancer. If it detects an
unhealthy instance, it stops sending traffic to the instance and reroutes traffic to healthy instances. In this step,
you provide the information required to check the health of servers in the backend set and ensure that they can
receive data traffic.
Protocol: Select HTTP.Port: Enter 80URL Path (URI): Enter /The rest of the fields are optional and can be left
blank for this tutorial.
Click Create.
Question #:150
: 64
You need to transfer over 12 TB of data from on-premises to your cloud account. You started copying this
data over the internet and noticed that it will take too long to complete.
Without increasing the costs of your subscription, what is the recommended way to send this amount of data to
your cloud account?
B. Split the data into multiple parts and use the multipart tool.
Answer: A
Explanation
References:
Overview of Data Transfer ServiceOracle offers offline data transfer solutions that let you migrate data to
Oracle Cloud Infrastructure. Moving data over the public internet is not always feasible due to high network
costs, unreliable network connectivity, long transfer times, and security concerns. Our transfer solutions
address these pain points, are easy to use, and provide significantly faster data upload compared to
over-the-wire data transfer.https://docs.cloud.oracle.com/iaas/Content/DataTransfer/Concepts/overview.htm
Question #:151
You have five different company locations spread across the US. For a proof-of-concept (POC) you need to
setup secure and encrypted connectivity to your workloads running in a single virtual cloud network (VCN) in
the Oracle Cloud Infrastructure Ashburn region from all company locations.
66 of 76
Oracle - 1z0-1072
A. Create five internet gateways in your VCN and have separate route table for each internet gateway.
B. Create five virtual circuits using FastConnect for each company location and terminate those
connections on a single dynamic routing gateway (DRG). Attach that DRG to your VCN.
C. Create five IPsec connections with each company location and terminate those connections on a single
DRG. Attach that DRG to your VCN.
D. Create five IPsec VPN connections with each company location and terminate those connections on five
separate DRGs. Attach those DRGs to your VCN.
Answer: C
Question #:152
What is the default backup location for database backup on Database Cloud Service (DBCS)?
B. ASM diskgroup
C. block volume
Answer: A
Explanation
References: https://docs.oracle.com/en/cloud/paas/database-dbaas-cloud/csdbi/backing.html
Question #:153
Which two are valid options when migrating a database from on-premise to Oracle Cloud Infrastructure?
(Choose two.)
B. performing a backup to Oracle Cloud Infrastructure Object Storage, and then restoring to a database
server on Oracle Cloud Infrastructure
C. performing RMAN backup to an on-premise storage device, and then shipping to Oracle Cloud
Infrastructure
D. converting the Oracle database to a NoSQL database and migrating to Oracle Cloud Infrastructure by
using rsync file copy
67 of 76
Oracle - 1z0-1072
Answer: A C
Question #:154
Which two Oracle Cloud Infrastructure database services allow you to dynamically both scale CPU and
storage? (Choose two.)
Answer: A B
Explanation
References:
Question #:155
A. nothing by default
D. statistics about what was added, changed, and destroyed, and the values of outputs
Answer: D
Explanation
References:
Question #:156
A company currently uses Microsoft Active Directory as its identity provider. The company recently
subscribed to Oracle Cloud Infrastructure (OCI) to leverage the cloud platform for test and development. As
the administrator, you configured the OCI tenancy to be federated with Microsoft Active Directory. Now you
need to give access to developers so that they can start creating resources in their OCI accounts.
Which step will you perform to make sure you are not duplicating user creation inside of OCI tenancy?
68 of 76
Oracle - 1z0-1072
A. Create a group for developers on OCI and map the group to a similar group in Microsoft Active
Directory during the federation process.
B. Create a new user account in OCI for each user, and then create policies to provide access to developers.
C. Create a group for developers on OCI, export all the developers from Microsoft Active Directory, and
then import them into the Identity and Access Management (IAM) group.
D. Create a single user account in OCI, and then create policies to provide access to developers to this
single account.
Answer: A
Question #:157
You are a network architect and have designed the network infrastructure of a three-tier application on Oracle
Cloud Infrastructure (OCI). In the architecture, back-end DB servers are in a private subnet. One of your DB
administrators requests to have access to OCI object storage service.
A. Create a service gateway, add a new route rule to the private subnet route table that uses storage as your
service gateway target type
B. Create a dynamic routing gateway (DRG) and attach it your virtual cloud network (VCN). Add a default
route rule to the private subnets route table and set the target as DRG
C. Attach a public IP address to the instances in the private subnet, and then add a new route rule to the
private subnet route table to route default traffic to the internet gateway
D. Add a new route rule to the private subnet route table to route default traffic to the internet gateway
Answer: A
Explanation
References: https://blogs.oracle.com/cloud-infrastructure/connect-private-instances-with-oracle-services-thro
ugh-an-oracle-cloud-infrastructure-service-gateway
Question #:158
You have been tasked with creating one virtual cloud network (VCN) each for two line of business (LOB)
applications. LOB A and LOB B will need to communicate with each other. To ensure that you can utilize
VCN peering, which network CIDR ranges should be used?
C.
69 of 76
Oracle - 1z0-1072
Answer: C
Question #:159
70 of 76
Oracle - 1z0-1072
Answer: D
Explanation
https://docs.cloud.oracle.com/iaas/Content/Object/Tasks/usingpreauthenticatedrequests.htm
You can’t edit a pre-authenticated request. If you want to change user access options in response to changing
requirements, you must create a new preauthenticated request.
URL: https://docs.cloud.oracle.com/iaas/Content/Object/Tasks/managingbuckets.htm
You can change a bucket’s access from public to private or from private to public. Changing the type of access
doesn’t affect existing pre-authenticated requests. Existing pre-authenticated requests still work.
Question #:162
You are responsible for setting up access for all the cloud users of a large enterprise. You log in to the Phoenix
region and start creating users and policies. You then realize that some users might be creating resources in the
Ashburn region.
A. You can assign a region to each of the users at the time of creation.
B. IAM users are global and non-admin users can add resources to any region by default.
C. You need to log in to each region separately to create users for that particular region.
D. IAM users are global. As an administrator, make sure that you subscribe to the Ashburn region.
Answer: D
Question #:163
There are multiple options of migrating Oracle Databases from on-premises to Oracle Cloud Infrastructure.
Which two characteristics do you need to consider when choosing a migration method? (Choose two.)
71 of 76
Oracle - 1z0-1072
Answer: B C
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/Database/Tasks/migrating.htm
Some of the characteristics and factors to consider when choosing a migration method are:
On-premises database versionDatabase service database versionOn-premises host operating system and
versionOn-premises database character setQuantity of data, including indexesData types used in the
on-premises databaseStorage for data stagingAcceptable length of system outageNetwork bandwidth
Question #:164
Which two statements are true about an Oracle Cloud Infrastructure object storage bucket? (Choose two.)
D. You cannot edit or append data to an object, but you can replace the entire object
Answer: C D
Explanation
References:
Question #:165
A customer has established an Oracle Cloud Infrastructure (OCI) FastConnect connection to OCI. The virtual
circuit is up and routes are being advertised from the customer’s end, however the customer is unable to ping
from compute instances inside the virtual cloud network (VCN) to servers residing in its on-premises data
center.
Which two options on OCI would remedy this situation? (Choose two.)
A. Modify the route table associated with the VCN subnet in which the instance resides. Add a route to the
customer’s on-premises network via the Dynamic Routing Gateway (DRG).
B.
72 of 76
Oracle - 1z0-1072
B. Modify the security list associated with the VCN subnet in which the instance resides. Add a stateful
egress rule to allow ICMP traffic to the customer’s on-premises network.
C. Modify the security list associated with the VCN subnet in which the instance resides. Add a stateful
ingress rule to allow ICMP traffic from anywhere.
D. Modify the default VCN route table to add a route back to the customer’s on-premises network via the
DRG.
Answer: A B
Question #:166
You have an application deployed in Oracle Cloud Infrastructure running only in the Phoenix region. You
were asked to create a disaster recovery (DR) plan that will protect against the loss of critical data. The DR site
must be at least 500 miles from your primary site and data transfer between the two sites must not traverse the
public Internet.
A. Create a new virtual cloud network (VCN) in the Phoenix region and create a subnet in one availability
domain (AD) that is not currently being used by your production systems. Establish VCN peering
between the production and DR sites.
B. Create a DR environment in Ashburn. Associate a DRG with the VCN in each region and create a
remote peering connection between the two VCNs.
C. Create a DR environment in Ashburn and provision a FastConnect virtual circuit using DRG between
the regions.
D. Create a DR environment in Ashburn. Associate a dynamic routing gateway (DRG) with the VCN in
each region and configure an IPsec VPN connection between the two regions.
Answer: C
Question #:167
A company currently uses Microsoft Active Directory as its identity provider. The company recently
purchased Oracle Cloud Infrastructure (OCI) to leverage the cloud platform for its test and development
operations. As the administrator, you are now tasked with giving access only to developers so that they can
start creating resources in their OCI accounts.
A. Create a group for developers on OCI and map the group to a similar group in Microsoft Active
Directory during the federation process.
B.
73 of 76
Oracle - 1z0-1072
B. Federate all Microsoft Active Directory groups with OCI to allow users to use their existing credentials.
C. Create a new user account for each user, and then create policies to provide access to developers.
D. Create a group for developers on OCI, export all the developers from Microsoft Active Directory, and
then import them into the Identity and Access Management (IAM) group.
Answer: A
Question #:168
You want an instance in your compartment to make API calls to other services within Oracle Cloud
Infrastructure without storing credentials in a configuration file.
A. No action is required. By default, all VM instances are created with an Instance Principal.
C. VM instances are treated as users. Create a user and assign the user to that VM instance.
D. Create appropriate matching rules in the Dynamic Group to create an Instance Principal.
Answer: D
Explanation
References: https://docs.cloud.oracle.com/iaas/Content/Identity/Tasks/managingdynamicgroups.htm
Question #:169
You are implementing Oracle Cloud Infrastructure (OCI) FastConnect to access OCI public access points (e.g.
– object storage). You want other Internet traffic from your on-premises environment to use your existing
connection with your ISP.
What is the correct way to establish OCI FastConnect to access these OCI public endpoints?
A. Configure private peering on your FastConnect link. Redistribute BGP routes learned into your existing
routing table and advertise a default from your network infrastructure to OCI.
B. Configure private peering on your FastConnect link with a static route that points to OCI object storage
service.
C. Configure public peering on your FastConnect link with a static route that points to OCI object storage
service.
D. Configure public peering on your FastConnect link. Redistribute BGP routes learned into your existing
74 of 76
Oracle - 1z0-1072
D.
routing table and advertise a specific route for your network infrastructure to OCI.
Answer: D
Explanation
https://www.oracle.com/a/ocom/docs/connectivity-fast-connect-200.pdf
Question #:170
A. PFX
B. PEM
C. PKCS12
D. CRT
Answer: B
Explanation
https://docs.cloud.oracle.com/iaas/Content/Balance/Tasks/managingcertificates.htm
Question #:171
Which three are default Virtual Cloud Network (VCN) components? (Choose three.)
A. Security List
C. DHCP options
D. Internet Gateway
E. Route Table
Answer: A C E
Explanation
References:
75 of 76
Oracle - 1z0-1072
(0)Network Security Groups (0)Security Lists (1)DHCP Options (1)Local Peering Gateways (0)NAT
Gateways (0)Service Gateways (0)
Question #:172
Which three load-balancing policies can be used with a back end set? (Choose three.)
A. Throughput
B. IP Hash
D. CPU Utilization
E. Least Connections
Answer: B C E
Explanation
References:
After you create a load balancer, you can apply policies to control traffic distribution to your backend servers.
The Load Balancing service supports three primary policy types:
76 of 76