1Z0-1072-25 Sample Questions

1Z0-1072-25 Sample Questions & Answers

Weighted toward virtual cloud networks, connectivity and DNS traffic management, the largest category, then block, object and file storage, choosing and configuring compute instances with autoscaling, and identity and access management basics.

Launch the full 1Z0-1072-25 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Networking · Configure Local and Remote Peering

    You are tasked with designing a networking architecture that connects two VCNs in different OCI regions (US East and EU Frankfurt) to enable a disaster recovery strategy. The connection must be private, reliable, and provide predictable performance. Which OCI networking component should be used to establish this connection?

    Show answer & explanation

    Correct answer: C

    A Remote Peering Connection (RPC) is the specific OCI component used to connect two VCNs in different regions. It allows resources in the VCNs to communicate using private IP addresses over Oracle's private network backbone, providing a secure and reliable connection suitable for disaster recovery scenarios.

  2. Question 2Intermediate

    Identity and Access Management · Configure Dynamic Groups, Network Sources, and Tag-Based Access Control

    A DevOps team is deploying a containerized application on OCI using an instance pool. They need to grant the application running on the instances permission to write logs to an OCI Object Storage bucket without storing or managing long-lived user credentials on the instances. What is the most secure method to achieve this?

    Show answer & explanation

    Correct answer: B

    This is the most secure and recommended method. By creating a dynamic group with a matching rule for the instance pool's OCID, all instances in that pool become members. You can then write an IAM policy that grants this dynamic group permission to manage objects in the target bucket. Applications on the instances can then use instance principals to be authenticated and authorized to call OCI services without needing to handle credentials.

  3. Question 3Intermediate

    Compute · Describe and configure OS Management

    A new compute instance is launched using a standard Oracle Linux image. A developer attempts to use the OS Management service to apply the latest security patches but finds the instance is not visible in the OS Management console. What is a prerequisite that might have been missed during the instance provisioning?

    Show answer & explanation

    Correct answer: B

    For an instance to be managed by the OS Management service, the Oracle Cloud Agent must be installed and running, and specifically, the OS Management Service Agent plugin must be enabled. While Oracle Linux images typically include the agent, it must be active and able to communicate with the OCI services. Connectivity via a Service Gateway (for private subnets) or Internet Gateway is also required, but the agent itself is the primary prerequisite for visibility in the console.

  4. Question 4Intermediate

    Networking · Configure Security Lists and Network Security Groups

    True or False: When configuring a Network Security Group (NSG), the rules defined within it are automatically applied to all Virtual NICs (VNICs) within the same subnet as the NSG.

    Show answer & explanation

    Correct answer: B

    This statement is false. Unlike Security Lists which apply to all VNICs in a subnet, Network Security Groups (NSGs) must be explicitly associated with a VNIC. An NSG acts as a virtual firewall for a chosen set of VNICs, allowing you to define security rules based on application tier or workload rather than subnet boundaries.

  5. Question 5Intermediate

    Storage · Configure Volume Groups, Backups, Clones

    A database administrator needs to create a point-in-time, crash-consistent backup of a group of Block Volumes that are attached to a running database server. The database's data, redo logs, and archive logs are on separate Block Volumes. What OCI feature should be used to ensure all volumes are backed up at the exact same moment?

    Show answer & explanation

    Correct answer: C

    A Volume Group is designed for this exact purpose. It allows you to group multiple Block Volumes together and perform coordinated, time-consistent operations on them. Creating a backup of the Volume Group ensures that a crash-consistent backup of all member volumes is taken at the same point in time, which is critical for database recovery.

  6. Question 6Advanced

    Networking · Configure Traffic Management Steering Policies

    A global e-commerce company wants to direct users to the geographically closest OCI region to reduce latency. If the primary region becomes unavailable, traffic should automatically be rerouted to the next closest healthy region. Which OCI service and steering policy should be used to achieve this routing behavior?

    Show answer & explanation

    Correct answer: C

    OCI Traffic Management's Geolocation steering policy is designed for this exact scenario. It allows you to define routing rules based on the geographic origin of the DNS query. You can configure it to serve answers pointing to the closest region for a given user. Combined with health checks, it will automatically stop sending traffic to an unhealthy region and fail over to the next priority pool, fulfilling both requirements.

  7. Question 7Intermediate

    Identity and Access Management · Create and manage IAM domains, users, groups, and compartments

    An administrator is setting up a new compartment structure for an organization. They want to prevent teams from creating excessively expensive Bare Metal GPU instances in a development compartment. Which IAM feature should be used to enforce this spending control?

    Show answer & explanation

    Correct answer: C

    Compartment quotas are specifically designed to control resource consumption. The administrator can set a quota on the development compartment for specific resource types, such as setting the count of a particular Bare Metal GPU shape to zero. This will prevent any user from creating that resource within the compartment, effectively enforcing the spending control.

  8. Question 8Advanced

    Compute · Select appropriate compute choices

    A solutions architect needs to provision a high-performance computing (HPC) cluster. The workload is sensitive to network latency between nodes and requires the highest possible bandwidth. Which OCI compute placement strategy should be implemented to minimize network latency for this cluster?

    Show answer & explanation

    Correct answer: C

    For latency-sensitive HPC workloads, OCI provides cluster networks. This feature groups HPC or GPU instances onto a dedicated, rear-end, ultra-low-latency network that supports Remote Direct Memory Access (RDMA). This provides microsecond-level latency between nodes, which is ideal for tightly coupled HPC applications.

  9. Question 9AdvancedSelect 3

    Networking · Troubleshoot using Network Path Analyzer

    A network engineer is troubleshooting a connectivity issue between a web server in a public subnet and a database server in a private subnet within the same VCN. The engineer uses the Network Path Analyzer to test the connection. The analysis fails. Which of the following are potential root causes that the Network Path Analyzer would identify? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

    If the route table associated with the public subnet doesn't have a rule to direct traffic to the private subnet's CIDR block, the packets will be dropped. Network Path Analyzer checks route tables along the path.

    Network Path Analyzer inspects both Security Lists and Network Security Groups. If the database subnet's security list blocks incoming traffic from the web server's source CIDR on the database port, the path analysis will report a failure.

    Similar to security lists, if an NSG is applied to the database server's VNIC and it doesn't have a rule to permit the traffic, the connection will be blocked, and Network Path Analyzer will identify this as the point of failure.

  10. Question 10Beginner

    Compute · Configure Autoscaling

    A company has deployed a critical application using an instance pool. To handle variable traffic, they have configured a metric-based autoscaling policy based on CPU utilization. During a recent high-traffic event, the autoscaling policy failed to add new instances, causing a service degradation. Upon investigation, it was found that the instance pool was at its maximum configured size. Which setting should have been checked and adjusted to prevent this issue?

    Show answer & explanation

    Correct answer: B

    The autoscaling configuration defines the minimum, maximum, and initial number of instances for an instance pool. The autoscaling policy can only add instances up to the specified maximum. If the pool is already at its maximum size, no further scale-out events will occur, regardless of the metric thresholds being met. The maximum number of instances should be set high enough to accommodate peak load.

Ready for the real thing?

The full 1Z0-1072-25 simulator has every exam-style question, timed mode, and instant scoring.