1Z0-1067-25 Sample Questions

1Z0-1067-25 Sample Questions & Answers

Most of the questions target cost and performance tuning, automated failover and elastic scaling, and deploying resources through the CLI and infrastructure as code, plus configuration management, tenancy security and secrets, and metric-based observability.

Launch the full 1Z0-1067-25 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Optimizing Cost and Performance · Implement performance optimization strategies

    An e-commerce platform runs its primary database on a high-performance compute instance with a 1 TB block volume. During peak sales events, the database experiences I/O bottlenecks, leading to slow transaction times. The current block volume is set to the 'Balanced' performance level. What is the most effective and immediate action to mitigate the I/O bottleneck without causing downtime for the database?

    Show answer & explanation

    Correct answer: B

    OCI Block Volume service allows dynamic performance scaling. You can change the performance setting of an attached block volume without detaching it, meaning there is no downtime. Moving from 'Balanced' to 'Higher Performance' will increase the IOPS and throughput available to the volume, directly addressing the I/O bottleneck experienced by the database.

  2. Question 2Beginner

    Optimizing Cost and Performance · Implement budgets and compartment quotas to limit usage

    True or False: A compartment quota policy, once set, prevents users from creating any new resources in that compartment if any one of the specified limits in the policy statement is reached.

    Show answer & explanation

    Correct answer: A

    This statement is true. Compartment quotas are hard limits. If a quota policy is in effect for a compartment, any user action that would exceed a limit defined in that policy will be denied. This is a key governance feature to control resource consumption and costs within specific organizational units or projects.

  3. Question 3Intermediate

    Implementing Reliability and Business Continuity · Implement scalability and elasticity

    A global logistics company is designing a highly available application on OCI. The application consists of a web tier running on an instance pool. To ensure resilience and responsiveness, the application must automatically scale out when CPU utilization averages above 70% for 5 minutes, and scale in when it drops below 30% for 10 minutes. Which OCI service is used to define these specific scaling triggers?

    Show answer & explanation

    Correct answer: C

    The Autoscaling Configuration service is where you define the policies that govern how an instance pool scales. This includes creating metric-based scaling policies that monitor performance metrics like CPU or memory utilization, defining the thresholds (e.g., >70% or <30%), and specifying the cooldown periods and number of instances to add or remove.

  4. Question 4Advanced

    Implementing Reliability and Business Continuity · Implement automated failover

    A healthcare provider needs to implement a robust disaster recovery (DR) plan for their critical patient data stored in an OCI Block Volume. The Recovery Point Objective (RPO) is 1 hour, and the Recovery Time Objective (RTO) is 4 hours. The primary region is US East (Ashburn) and the DR region is US West (Phoenix). Which OCI feature should be implemented to meet these DR requirements?

    Show answer & explanation

    Correct answer: B

    Cross-region asynchronous replication for block volumes is the native OCI solution designed specifically for this DR scenario. It continuously replicates data to a destination region with a typical RPO of less than a minute, easily meeting the 1-hour requirement. In a DR event, the replica volume can be activated in the DR region, allowing for rapid recovery that meets the 4-hour RTO.

  5. Question 5Intermediate

    Implementing Reliability and Business Continuity · Implement data retention strategies

    A retail company uses OCI Object Storage to store transaction logs. For compliance reasons, logs must be retained for 7 years. However, they only need to be accessed frequently for the first 30 days. After 30 days, they should be moved to a more cost-effective storage tier, and after one year, they should be moved to the most cost-effective long-term storage. Which OCI mechanism automates this process?

    Show answer & explanation

    Correct answer: B

    Object Storage Lifecycle Policies are designed for this exact purpose. You can define rules that automatically perform actions on objects based on their age. A policy can be created with two rules: one to move objects from the Standard tier to the Infrequent Access tier after 30 days, and a second rule to move them from Infrequent Access to the Archive tier after 365 days. A final rule can be set to delete objects after 7 years.

  6. Question 6Advanced

    Managing Identity and Security · Implement tenancy security posture

    A security administrator is configuring OCI Cloud Guard for a tenancy. They want to ensure that any publicly accessible Object Storage bucket is immediately flagged as a high-risk problem. However, they have a specific bucket used for public-facing website assets that must remain public and should not trigger an alarm. What is the correct way to handle this exception?

    Show answer & explanation

    Correct answer: D

    The correct and scalable way to manage exceptions in Cloud Guard is to use managed lists. You would create a managed list containing the OCID of the specific bucket that needs to be public. Then, you would clone the Oracle-managed detector recipe, modify the 'Publicly visible Object Storage bucket' rule to use this managed list as an exception, and attach the new custom recipe to your target. This ensures that only the intended resource is excluded from the check, maintaining security posture for all other resources.

  7. Question 7Intermediate

    Managing Identity and Security · Manage secrets and encryption keys

    A developer needs to store a third-party API key securely in OCI. An application running on a compute instance will need to retrieve this key at runtime to make API calls. The security policy mandates that the key must be encrypted at rest and rotated every 90 days. Which combination of OCI services should be used to meet these requirements?

    Show answer & explanation

    Correct answer: B

    OCI Vault is the designated service for securely storing secrets like API keys. Storing the key as a secret in a vault ensures it's encrypted at rest using a Master Encryption Key. To allow the application to retrieve it, you should use an Instance Principal for the compute instance and create a specific IAM policy that grants it permission to read that particular secret. This avoids storing credentials on the instance. The secret can then be managed and rotated within the Vault service.

  8. Question 8Beginner

    Managing Identity and Security · Implement least-privilege access control policies

    An administrator needs to create an IAM policy that allows a group called DatabaseAdmins to manage Autonomous Databases (list, create, start, stop, delete) but only within a specific compartment named DB_Prod. Which policy statement correctly implements this least-privilege requirement?

    Show answer & explanation

    Correct answer: C

    This policy statement is correct because it follows the principle of least privilege. It specifies the actor (group DatabaseAdmins), the permission level (manage), the resource type (autonomous-databases), and correctly scopes the permission to a specific location (in compartment DB_Prod). The manage verb includes all necessary permissions (list, create, update, delete) for that resource type.

  9. Question 9Advanced

    Implementing Observability · Implement Metric Query Language (MQL)

    A monitoring specialist needs to create an alarm that triggers if the average CPU utilization across all instances in a specific compartment (App_Servers) exceeds 80% for a continuous 15-minute period. Which MQL query should be used in the alarm definition?

    Show answer & explanation

    Correct answer: C

    This MQL query is correctly structured. CpuUtilization is the metric. [15m] specifies the interval for the alarm evaluation. {compartmentId = '...'} is the dimension filter that scopes the query to the correct compartment. .mean() is the aggregation function to calculate the average across all instances in that compartment. Finally, &gt; 80 sets the threshold for the alarm to trigger.

  10. Question 10Intermediate

    Implementing Observability · Implement alarms and notifications

    An operations engineer has configured an OCI alarm to monitor disk space on a critical server. When the alarm enters the 'Firing' state, they need to automatically trigger three distinct actions: send an email to the on-call team, post a message to a Slack channel, and create a ticket in a PagerDuty system. How should this be configured?

    Show answer & explanation

    Correct answer: B

    The OCI Notifications service uses a topic-and-subscription model. The correct approach is to create one Notification Topic to associate with the alarm. Then, you create three separate subscriptions on that topic: one of type 'Email' for the on-call team, one of type 'PagerDuty' for ticketing, and one of type 'Function' which triggers an OCI Function to send a formatted message to the Slack API. When the alarm fires, it publishes a message to the topic, which then fans out to all its subscriptions.

Ready for the real thing?

The full 1Z0-1067-25 simulator has every exam-style question, timed mode, and instant scoring.