Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Oracle Cloud Infrastructure Developer Professional 1z0-1084-26 Exam Questions

Page: 1 / 13 Total 181 questions

Want more questions? Get Premium Access.

Question 1

With the volume of communication that can happen between different components in cloud-native applications, it is vital to not only test functionality, but also service resiliency. Which statement is true regarding service resiliency?

Correct Answer: C. Resiliency is about recovering from failures without downtime or data loss.
Explanation:

The correct answer is: 'Resiliency is about recovering from failures without downtime or data loss.' Service resiliency, in the context of cloud-native applications, is the ability of a service or system to recover from failures and continue functioning without downtime or data loss. It involves designing and implementing mechanisms to handle failures, such as network outages, hardware failures, or software errors, in a way that minimizes the impact on the overall system. The goal of resiliency is to ensure that the application or service can continue to operate and provide a certain level of functionality, even in the face of failures. This typically involves techniques such as redundancy, fault tolerance, and graceful degradation. By implementing resiliency measures, a cloud-native application can recover and adapt to failures, maintain availability, and preserve data integrity. The other statements are not accurate regarding service resiliency: Resiliency is not about not bringing a service to a functioning state after a failure. Instead, it is about recovering from failures and ensuring continued functionality. Resiliency is not about avoiding failures entirely. While it is desirable to prevent failures, resiliency focuses on the ability to handle and recover from failures when they do occur. Resiliency testing is not limited to a test environment. It is important to test and validate the resiliency measures in both test environments and production environments to ensure the application can effectively handle failures in real-world scenarios.


Question 2

You have developed a cloud-native application on OCI, and you need to enable diagnostic logging for an OCI API Gateway deployment and a backend Oracle Function. Corporate compliance mandates that both the gateway activity and the function execution logs must be collected and stored in separate centralized log resources under a common log group named AppLoggingGroup.

Which TWO configuration steps must you perform within the OCI Logging service to satisfy these requirements?

Correct Answer: C. Create an OCI Logging Service Log resource under AppLoggingGroup, selecting API Gateway as the service and the target deployment as the resource.; D. Create an OCI Logging Service Log resource under AppLoggingGroup, selecting Functions as the service and the target application as the resource.
Explanation:

API Gateway and Oracle Functions are OCI-managed services with native integration into OCI Logging, so their diagnostic output is collected through service logs, not host-based custom-log agent configurations. Oracle's Service Log Reference explicitly includes both API Gateway and Functions. For Functions, Oracle's current CLI example creates a SERVICE log whose source resource is the Function application and whose category is invoke. API Gateway likewise exposes service logging for gateway/deployment activity. Both log resources can be placed in the same organizational log group while remaining separate log objects, satisfying the compliance requirement. Logging agents and custom logs are intended primarily for files produced on managed hosts or applications, not for these managed OCI service sources. Therefore, C and D are correct.


Question 3

A DevOps engineer is troubleshooting the Meshifyd application, which is running in an Oracle Cloud Infrastructure (OCI) environment. The engineer has set up the OCI Logging service to store access logs for the application but notices that the logs from the Meshifyd application are not showing up in the logging service. The engineer suspects that there might be an issue with the logging configuration. Which two statements are potential reasons for logs from the Meshifyd application not showing up in the OCI Logging service?

Correct Answer: A. The logconfig.json file has incorrect or missing OCID for the custom log in the logobjectId field.; E. The logconfig.json file has incorrect or missing OCID for the custom log group in the logGroupObjectId field.
Explanation:

The logconfig.json file is a configuration file that specifies how the Unified Monitoring Agent collects and uploads custom logs to the OCI Logging service2.The logconfig.json file contains an array of objects, each representing a custom log configuration2.Each custom log configuration object has the following fields2:

logGroupObjectId: The OCID of the log group where the custom log is stored.

logObjectId: The OCID of the custom log.

paths: An array of paths to files or directories containing the custom logs.

src: A regular expression that matches the files containing the custom logs.

parser: A parser definition that specifies how to parse the custom logs. If the logconfig.json file has incorrect or missing OCID for the custom log in the logobjectId field, or incorrect or missing OCID for the custom log group in the logGroupObjectId field, then the Unified Monitoring Agent will not be able to upload the custom logs to the OCI Logging service2. Therefore, these are potential reasons for logs from the Meshifyd application not showing up in the OCI Logging service. Verified Reference:Unified Monitoring Agent Configuration File


Question 4

You are developing a real-time monitoring application for a fleet of vehicles, which will be deployed on Oracle Cloud Infrastructure (OCI). You need to choose between using OCI Queue or OCI Streaming to handle the real-time data feeds from the vehicles. Based on the scenario described, which is the most appropriate choice for handling real-time data feeds?

Correct Answer: A. OCI Streaming, because it is designed for high-volume, continuous ingestion and processing of data, making it the best choice for a fleet of vehicles
Explanation:

OCI Streaming is a fully managed, scalable, and durable messaging solution for ingesting continuous, high-volume streams of data that you can consume and process in real-time1.Streaming is suitable for any use case in which data is produced and processed continually and sequentially in a publish-subscribe messaging model1.Streaming can handle millions of messages per second with low latency2. Therefore, OCI Streaming is the most appropriate choice for handling real-time data feeds from a fleet of vehicles. Verified Reference:Overview of Streaming,Container Engine for Kubernetes


Question 5

Who is responsible for patching, upgrading, and maintaining the worker nodes in Oracle Cloud Infrastructure (OCI) Container Engine for Kubernetes (OKE)? (Choose the best answer.)

Correct Answer: C. The user
Explanation:

The user is responsible for patching, upgrading, and maintaining the worker nodes in Oracle Cloud Infrastructure (OCI) Container Engine for Kubernetes (OKE). In OKE, the user has control over the worker nodes, which are the compute instances that run the Kubernetes worker components. As the user, you are responsible for managing and maintaining these worker nodes, including tasks such as patching the underlying operating system, upgrading Kubernetes versions, and performing any necessary maintenance activities. While Oracle provides the underlying infrastructure and support services, including managing the control plane and ensuring the availability of the OKE service, the responsibility for managing the worker nodes lies with the user. This allows you to have control and flexibility in managing your Kubernetes environment according to your specific needs and requirements.


Question 6

Which industry standard specification defines the structure and format of messages processed by the Oracle Cloud Infrastructure Events service?

Correct Answer: A. CloudEvents
Explanation:

OCI Events messages follow the CloudEvents industry-standard event-envelope format hosted by the Cloud Native Computing Foundation. Oracle's Events documentation explicitly states that every event message includes an envelope and payload and that the envelope structure follows the CloudEvents specification. Standard OCI event fields include cloudEventsVersion, eventID, eventType, eventTime, contentType, extensions, and data. CloudEvents provides a consistent representation for describing event data across services and platforms, improving interoperability in event-driven architectures. AsyncAPI is primarily a specification for describing asynchronous APIs rather than the OCI Events message envelope itself. ''Webhooks v2'' and ''OpenMessage'' are not the standards Oracle identifies for OCI Events message structure. Therefore, A is directly supported by Oracle documentation.


Question 7

You are developing a continuous integration (CI) pipeline running on an Oracle Cloud Infrastructure (OCI) Compute instance that automatically builds and pushes container images to Container Registry (OCIR). You need to configure dynamic group membership and write the minimum required IAM policies to authorize this Compute instance to push images to repositories within a compartment named qa-compartment.

Which TWO steps must you perform to achieve this authorization?

Correct Answer: B. Create a dynamic group named ci-pipeline-dg with the matching rule: ANY {instance.id = 'ocid1.instance.oc1.phx.exampleinstanceocid'}; D. Add an IAM policy statement: Allow dynamic-group ci-pipeline-dg to manage repos in compartment qa-compartment
Explanation:

OCI dynamic groups identify Compute instances using the documented instance.id attribute, making B valid. Oracle Container Registry documentation also shows manage repos as a policy capable of authorizing image pushes within a specified compartment, making D the sufficient policy among the supplied choices. container.instance is not a valid Compute-instance matching variable, while inspect repos provides only discovery-level permissions. use repos does not supply the repository update permissions required for pushing images. For stricter production least privilege, Oracle additionally documents conditioning a manage repos policy to specific permissions such as REPOSITORY_READ, REPOSITORY_UPDATE, and REPOSITORY_CREATE; however, that granular variant is not offered among these choices. Therefore, B and D are the correct selections.


Question 8

Which protocol or mechanism does the Docker client use by default to communicate with the Docker daemon when both are running on the same local host?

Correct Answer: B. Local UNIX Sockets
Explanation:

In the Linux/Unix environment normally assumed for OCI container development, the Docker client communicates with the locally running Docker daemon through a UNIX domain socket. Docker's default endpoint on Linux is unix:///var/run/docker.sock. This allows local inter-process communication without requiring a TCP network connection. TCP can be configured when the client must communicate with a daemon through a network, while SSH can provide secure access to a remote Docker daemon. RPC is not the default Docker client transport. Therefore, for a Docker client and daemon running locally on a Linux-based OCI development host, Local UNIX Sockets is the correct answer. On Windows, Docker uses a named pipe by default, so the answer is specifically applicable to the Linux/Unix OCI context.


Question 9

What are the TWO main reasons you would choose to implement a serverless architecture? (Choose two.)

Correct Answer: B. Automatic horizontal scaling; D. Reduced operational cost
Explanation:

The two main reasons to choose a serverless architecture are: Automatic horizontal scaling: Serverless architectures allow for automatic scaling of resources based on demand. The infrastructure automatically provisions and scales resources as needed, ensuring that applications can handle varying workloads efficiently. This eliminates the need for manual scaling and optimizes resource utilization. Reduced operational cost: Serverless architectures follow a pay-per-use model, where you are billed only for the actual execution time and resources consumed by your functions. This leads to cost savings as you don't have to pay for idle resources. Additionally, serverless architectures remove the need for managing and maintaining servers, reducing operational overhead and associated costs. No need for integration testing: Integration testing is still necessary in serverless architectures to ensure that functions integrate correctly with other components and services. Serverless functions can interact with various event sources, databases, and APIs, and testing is required to verify the integration points. Improved in-function state management: Serverless architectures typically encourage stateless functions that operate on short-lived requests or events. While there are mechanisms to manage state within a function, serverless architectures are designed to be stateless by default, promoting scalability and fault tolerance. Easier to run long-running operations: Serverless functions are generally designed for short-lived operations rather than long-running tasks. If you have a requirement for long-running operations, a serverless architecture may not be the ideal choice, as it has execution time limits and may not provide the necessary resources for extended execution.


Question 10

You are designing the persistence layer for a multi-service financial application where each microservice must completely isolate its private persistent data to enforce a bounded context. Which database configuration strategy should you implement within a multi-tenant Oracle Database to satisfy this requirement with the lowest operational overhead?

Correct Answer: B. Provision a single pluggable database (PDB) for each individual microservice.
Explanation:

Oracle specifically recommends the multitenant database model for microservices because multiple Pluggable Databases can reside within one Container Database while retaining logical isolation. Oracle's microservices architecture guidance identifies PDBs as a strong persistence choice for bounded-context isolation, security, and high availability. Allocating a PDB per microservice isolates that service's private database objects while avoiding the infrastructure and operational overhead of provisioning an entire VM database system for every service. Shared schemas or shared tables weaken service autonomy and create tight coupling between bounded contexts. Because a CDB can host multiple isolated PDBs while sharing common database infrastructure and administration, option B best combines isolation with operational efficiency.


Question 11

You are developing a cloud native serverless application where uploaded PDF documents inside an OCI Object Storage bucket must automatically trigger an OCI Function for text processing. You have created an OCI Events rule configured with the condition eventType: com.oraclecloud.objectstorage.createbucket matching the bucket's compartment. However, when test files are uploaded, the function does not trigger.

Which TWO actions must you perform to successfully implement and troubleshoot this event-driven integration?

Correct Answer: B. Enable the 'Emit Object Events' setting on the source Object Storage bucket.; D. Verify the rule's condition is configured with the com.oraclecloud.objectstorage.createobject event type rather than com.oraclecloud.objectstorage.createbucket.
Explanation:

Object-level state changes in OCI Object Storage do not emit Events by default. Oracle requires the bucket's Emit Object Events capability to be enabled before object create, update, or delete events are generated. In addition, the rule must use the correct event type. com.oraclecloud.objectstorage.createbucket represents creation of a bucket itself, whereas uploading a new object generates com.oraclecloud.objectstorage.createobject. Therefore, the current rule can never match ordinary PDF uploads. Dynamic groups are not used to assign identities to buckets, Events does not require permission to read the actual object's contents, and no VCN Service Gateway is necessary for this native OCI service integration. Consequently, B and D are required.


Question 12

You are building a container image and pushing it to Oracle Cloud Infrastructure Registry (OCIR). You need to ensure that these images never get deleted from the repository. Which action should you take?

Correct Answer: D. Edit the tenancy global retention policy.
Explanation:

The correct answer is: 'Edit the tenancy global retention policy.' To ensure that container images never get deleted from the Oracle Cloud Infrastructure Registry (OCIR), you should edit the tenancy global retention policy. The tenancy global retention policy is a setting that determines the retention behavior for all the images in the OCIR across the entire tenancy. By editing this policy, you can define the retention behavior that suits your requirements. To edit the tenancy global retention policy, you would typically perform the following steps: Access the Oracle Cloud Infrastructure Console and navigate to the OCIR service. Go to the 'Policies' section or 'Settings' section in the OCIR service. Locate the tenancy global retention policy settings. Modify the retention policy to specify the desired retention behavior. In this case, you would set the policy to retain all images, ensuring they are never deleted from the repository. By setting the global policy of image retention to 'Retain All Images,' you can ensure that the container images in your OCIR repository are permanently retained and not subject to deletion based on any default or automatic retention rules. The other options mentioned are not directly related to ensuring that container images are never deleted from the repository: Creating a group and assigning a policy to perform lifecycle operations on images or writing a policy to limit access to the specific repository in your compartment are access control measures and do not address the retention of images. Setting the global policy of image retention to 'Retain All Images' is the correct action to achieve the desired outcome of preventing image deletion from the repository.


Question 13

Your company requires strict compartment isolation for an event-driven automation framework. You have deployed an Oracle Functions function inside a secure compartment named SecOps-Fn-Compartment. An OCI Events rule has been configured in a separate compartment named App-Resources-Compartment to capture critical resource state changes. Which configuration approach is required to allow the OCI Events service to successfully invoke your function?

Correct Answer: B. Define an IAM policy allowing the service principal cloudevents to use functions in the function's compartment.
Explanation:

OCI Events invokes configured action resources as a managed service rather than by assuming the identity of the human user who created the rule. Oracle's Events material documents the service principal cloudEvents and the policy pattern allowing that service to use functions-family. Scoping that permission to the compartment containing the target Function provides the required compartment isolation. A dynamic group is inappropriate because an Events rule is not a Compute instance or workload principal. Granting permissions to oraclefunctions reverses the invocation relationship, while granting a user group broad function-management rights does not authorize the Events runtime itself. Current Oracle documentation additionally represents cross-tenancy delivery using an eventrule principal and FN_INVOCATION; within the source scenario, B is the intended service authorization model.


Question 14

Which command is used to get a Docker image from Oracle Cloud Infrastructure Registry (OCIR) to the client machine?

Correct Answer: A. docker pull <region-key>.ocir.io/<tenancy-namespace>/<repo-name>: <tag>
Explanation:

To pull a Docker image from OCI Registry to the client machine, you need to use the docker pull command with the following syntax1: docker pull <region-key>.ocir.io/<tenancy-namespace>/<repo-name>:<tag> where:

<region-key> is the key for the OCI Registry region you're using. For example, iad.See Availability by Region1.

ocir.io is the OCI Registry name.

<tenancy-namespace> is the auto-generated Object Storage namespace string of the tenancy that owns the repository from which you want to pull the image (as shown on the Tenancy Information page)1.

<repo-name> is the name of the repository that contains the image you want to pull.

<tag> is the tag of the image you want to pull.


Question 15

Which token authentication policy configuration parameter should be defined when adjusting for potential clock synchronization differences between the external OAuth2 identity provider and the OCI API Gateway?

Correct Answer: B. maxClockSkewInSeconds
Explanation:

maxClockSkewInSeconds specifies the maximum expected difference between the system clock of the token issuer and the OCI API Gateway. Oracle documents this value as part of token/JWT authentication policy configuration. The gateway accounts for the configured skew when evaluating time-dependent JWT claims such as nbf (not before) and exp (expiration), preventing otherwise valid tokens from being rejected because of minor clock differences between systems. Oracle currently documents a valid range from 0 through 120 seconds for the JWT policy. maxCacheDurationInHours controls caching behavior rather than clock synchronization, while SSL verification relates to certificate validation. allowedClockVariance is not the documented OCI API Gateway property. Therefore, B is the correct configuration parameter.