Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Oracle Cloud Infrastructure 2025 Architect Associate 1Z0-1072-25 Exam Questions

Page: 1 / 6 Total 51 questions

Want more questions? Get Premium Access.

Question 1

Which TWO statements are NOT correct regarding the Oracle Cloud Infrastructure (OCI) burstable instances?

Correct Answer: A. Burstable instances cost less than regular instances.; B. Burstable instances are charged according to the baseline OCPU.
Explanation:

The following statements about OCI burstable instances are NOT correct:

A . Burstable instances cost less than regular instances: This is incorrect because burstable instances are not necessarily cheaper; the cost depends on the baseline utilization. While they allow for cost efficiency when running at a lower CPU baseline, they can become more expensive if frequently bursting above the baseline.

B . Burstable instances are charged according to the baseline OCPU: This is incorrect because burstable instances are billed based on actual OCPU usage, which includes both baseline and burst usage. If an instance frequently operates above its baseline, the cost will reflect this higher usage.

Correct Concepts:

C . Burstable instances can temporarily use more CPU than their baseline if the average CPU utilization is below the baseline.

D . Baseline utilization is a fraction of each CPU core, which determines the level of consistent performance available without bursting.


Oracle Cloud Infrastructure Documentation: Burstable Instances

Question 2

Which Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM) policy is invalid?

Correct Answer: C. Allow any-user to inspect users in tenancy
Explanation:

In Oracle Cloud Infrastructure (OCI), Identity and Access Management (IAM) policies are used to control access to resources. The policy in option C is invalid because 'any-user' is not a valid principal in OCI IAM policies. OCI policies can only grant permissions to groups or dynamic groups, but not to arbitrary users.

Here's an explanation for each option:

A . Allow dynamic-group 'Default'/'FrontEnd' to manage instance-family in compartment Project-A: This is valid. It grants the dynamic group 'FrontEnd' the ability to manage instances within the Project-A compartment.

B . Allow group 'Default'/'A-Admins' to manage all-resources in compartment Project-A: This is valid. It provides full administrative access to all resources in the Project-A compartment for the 'A-Admins' group.

C . Allow any-user to inspect users in tenancy: This is invalid because OCI does not allow the use of 'any-user' in policies. You must specify a valid group or dynamic group to define permissions.

D . Allow group 'Default'/'A-Developers' to create volumes in compartment Project-A: This is valid. It permits the 'A-Developers' group to create volumes in the Project-A compartment.

For reference:

OCI Policy Reference


Question 3

You can attach resources to a Dynamic Routing Gateway (DRG). Select THREE of these resources.

Correct Answer: A. Virtual Circuits; D. Remote Peering Connections; E. IPSec Tunnel
Explanation:

A Dynamic Routing Gateway (DRG) in Oracle Cloud Infrastructure (OCI) is a virtual router that provides a path for private traffic between your on-premises network and your VCN, or between your VCN and other VCNs. The resources that can be attached to a DRG include:

A . Virtual Circuits: Used to establish a private connection between your on-premises data center and your VCN via Oracle's FastConnect service.

D . Remote Peering Connections: Enables peering between VCNs located in different regions (Remote VCN Peering).

E . IPSec Tunnel: Facilitates secure VPN connections between your on-premises network and your OCI VCN.


Oracle Cloud Infrastructure Documentation: Dynamic Routing Gateway Overview

Question 4

How can an organization securely grant a third-party application access to specific OCI resources?

Correct Answer: C. By configuring the application to utilize Instance Principal
Explanation:

To securely grant a third-party application access to specific Oracle Cloud Infrastructure (OCI) resources, the recommended approach is to configure the application to use Instance Principal. This method allows the application to authenticate directly with OCI services without needing to manage sensitive credentials like passwords or API keys.

Instance Principals: Enable compute instances to directly make API calls against OCI services, inheriting permissions through IAM policies. This setup is more secure than sharing user credentials, as it avoids hardcoding credentials within the application and leverages OCI's native security features.


Oracle Cloud Infrastructure Documentation: Instance Principals

Question 5

Which image option allows you to create identical instances with minimal effort?

Correct Answer: D. Create a custom image
Explanation:

When you need to create identical instances with minimal effort, creating a custom image is the best option.

Custom Images: A custom image captures the exact configuration of an instance, including the OS, software, configurations, and data. By using a custom image, you can easily replicate the same setup across multiple instances, ensuring consistency and reducing the need for manual configuration each time.

Other Options:

Bring Your Own Image: This allows you to import your custom OS image into OCI, but it's more suited for cases where you are migrating from another environment.

Select an Image from the OCI Marketplace: This provides pre-configured images from Oracle or third parties, but they may require additional setup to match your specific requirements.

Use Oracle-Provided Images: These are basic images provided by Oracle, which may not include the specific customizations you need.

Relevant OCI Documentation:

Custom Images Overview

This resource explains how to create and use custom images for quickly deploying identical instances.


Question 6

You want to protect your VM instance from low-level threats, such as rootkits and bootkits. What should you do?

Correct Answer: A. Create a shielded instance.
Explanation:

To protect your VM instance from low-level threats, such as rootkits and bootkits, you should create a shielded instance in Oracle Cloud Infrastructure (OCI). Shielded instances are designed to provide enhanced security features, including:

Secure Boot: Ensures that the instance boots only with trusted software.

Measured Boot: Records boot metrics, allowing verification that the instance has not been tampered with.

Trusted Platform Module (TPM): Provides additional security through cryptographic functions.

These features help protect against low-level threats that could compromise the integrity of the instance at boot time.


Oracle Cloud Infrastructure Documentation: Shielded Instances

Question 7

Which statement is true about instance configurations and instance pools in OCI?

Correct Answer: C. You can only delete an instance configuration if it is not associated with any instance pool.
Explanation:

Instance configurations and instance pools are used in OCI to manage groups of instances collectively:

Deleting Instance Configurations: An instance configuration cannot be deleted if it is currently associated with an instance pool. You must first disassociate or delete the instance pool before you can delete the instance configuration.

Reusing Instance Configurations: You can reuse the same instance configuration for multiple instance pools, which allows you to deploy identical groups of instances in different contexts.

Instance Pools: A single instance pool can only be associated with one instance configuration, ensuring uniformity across the instances in the pool.

Relevant OCI Documentation:

Instance Configuration Overview

Instance Pools Overview

These references explain how to manage instance configurations and pools, including the rules for deletion.


Question 8

Which Traffic Management Steering Policy facilitates the distribution of DNS traffic based on the geographical location of end users?

Correct Answer: A. Geolocation Steering
Explanation:

Geolocation Steering in OCI's Traffic Management Steering Policy allows you to distribute DNS traffic based on the geographical location of the end users. This method helps direct users to the nearest regional endpoint, optimizing latency and improving user experience.

Use Cases: Geolocation Steering is commonly used to deliver region-specific content, comply with data residency laws, or optimize service performance by directing traffic to the closest available servers.


Oracle Cloud Infrastructure Documentation: Traffic Management Steering Policies

Question 9

By default, OCI IAM policies follow the principle of least privilege. What does this principle mean in the context of policy creation?

Correct Answer: C. Policies should provide only the minimum set of permissions required for users to perform their tasks effectively.
Explanation:

The principle of least privilege is a security best practice that dictates that users should only be granted the minimum set of permissions necessary to perform their tasks. This principle helps to minimize the risk of accidental or malicious actions that could compromise security.

IAM Policies in OCI: When creating IAM policies in OCI, you should carefully evaluate the required permissions and only grant those that are absolutely necessary for the users or groups to perform their specific roles. This helps to reduce the attack surface and prevent unauthorized access to sensitive resources.


Oracle Cloud Infrastructure Documentation: Identity and Access Management (IAM) Best Practices

Question 10

Which components are required for establishing remote peering between two Virtual Cloud Networks (VCNs) in Oracle Cloud Infrastructure (OCI)?

Correct Answer: D. Two VCNs with nonoverlapping CIDRS in different regions, a dynamic routing gateway (DRG) attached to each VCN, a remote peering connection (RPC) on each DRG, and a connection established between the RPCs.
Explanation:

Remote peering in Oracle Cloud Infrastructure allows two VCNs in different regions to communicate securely. To establish remote peering, the following components are required:

Two VCNs with Nonoverlapping CIDRs:

The CIDR blocks of the two VCNs must not overlap. This is crucial to avoid routing conflicts and ensure that traffic is correctly routed between the VCNs.

Dynamic Routing Gateway (DRG) Attached to Each VCN:

A DRG is a virtual router that provides a path for traffic between the VCN and networks outside the VCN, such as other VCNs via remote peering, on-premises networks, or other cloud services. Each VCN needs its own DRG.

Remote Peering Connection (RPC):

An RPC is a specialized connection on the DRG used specifically for remote peering. You need to create an RPC on each DRG associated with the VCNs you wish to peer.

Connection Between RPCs:

Finally, a connection must be established between the RPCs of the two DRGs. This connection facilitates the secure and private exchange of traffic between the VCNs over Oracle's backbone network.

Incorrect Options:

Option A involves a single VCN, which does not fulfill the requirement of remote peering between two VCNs.

Option B involves overlapping CIDRs and VPN gateways, which are incorrect for remote peering.

Option C suggests peering within the same region, which would be considered local peering rather than remote peering.

Relevant OCI Documentation:

OCI Remote VCN Peering

Dynamic Routing Gateway (DRG) Overview

These resources provide a detailed guide on configuring remote peering in OCI, ensuring secure and effective communication between VCNs across regions.