1Z0-1109-25 Sample Questions & Answers
Ranges across CI/CD pipeline configuration running neck and neck with Kubernetes cluster management through OKE, plus core DevOps principles, Terraform-based infrastructure as code, securing pipelines with DevSecOps, and observability dashboards.
Launch the full 1Z0-1109-25 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Understand DevOps principles and effectively work with containerization services · Identify the need for containerization and create containers using Docker
A developer is writing a Dockerfile for a new Python microservice. To minimize the final image size and reduce the attack surface, they want to use a multi-stage build. The first stage will build the application dependencies, and the final stage will copy only the necessary artifacts into a minimal base image. Which Dockerfile command is essential for transferring the built artifacts from the builder stage to the final production stage?
Show answer & explanation
Correct answer: C
In a multi-stage Dockerfile, the
COPYcommand with the--fromflag is used to copy files or directories from a previous stage (referenced by its name or index) into the current stage. This is the fundamental mechanism for creating a lean production image by selectively transferring only the necessary compiled code, dependencies, or other artifacts, leaving behind the build tools and intermediate files. - Question 2Intermediate
Managing Containers using Container Orchestration Engine · Evaluate and configure security within OCI OKE service
An organization is deploying a multi-tier application on an OKE cluster with public-facing web servers and private backend services. For security reasons, network traffic between the web and backend pods must be strictly controlled, allowing only specific ingress traffic on port 8080. Which Kubernetes resource should be implemented to enforce this policy?
Show answer & explanation
Correct answer: C
A NetworkPolicy is a Kubernetes-native firewalling resource used to control traffic flow at the IP address or port level (OSI layer 3 or 4). To enforce traffic rules between pods, you would create a NetworkPolicy that selects the backend pods and defines an ingress rule allowing traffic only from the web server pods on the specified port (8080). This provides granular, declarative network segmentation within the cluster.
- Question 3Intermediate
Implementing Monitoring and Observability (O&M) · Create and track events with OCI Events Service
A DevOps team needs to automate notifications for their OCI deployment pipeline. They want to send a message to a Slack channel whenever a deployment to the production environment fails. Which combination of OCI services should they use to build this automation?
Show answer & explanation
Correct answer: B
This is the standard, event-driven approach in OCI. OCI DevOps services emit events for pipeline state changes. An OCI Events rule can be configured to filter for the specific 'Deployment Succeeded' or 'Deployment Failed' event type. The action for this rule would be to send the event to an OCI Notifications topic. An OCI Function, which contains the logic to format and send a message to the Slack webhook URL, can subscribe to this topic, triggering the notification.
- Question 4Intermediate
Managing Containers using Container Orchestration Engine · Perform scaling, cluster upgrades, use admission controllers, and execute applications on specialized nodes
An e-commerce company experiences significant traffic spikes during holiday seasons. Their application runs on an OKE cluster, and they need to ensure the application can scale automatically to handle the load. The application pods' CPU utilization is a reliable indicator of load. Which Kubernetes controller is designed to automatically adjust the number of running pods in a deployment based on observed CPU utilization?
Show answer & explanation
Correct answer: C
The Horizontal Pod Autoscaler (HPA) is the Kubernetes component responsible for automatically scaling the number of pods in a ReplicaSet, Deployment, or StatefulSet. It periodically checks metrics such as CPU utilization or custom metrics against a target value defined in the HPA configuration and increases or decreases the number of replicas accordingly. The Cluster Autoscaler scales the number of nodes, and the VPA adjusts the resource requests/limits of individual pods.
- Question 5Beginner
Using Code and Templates for Provisioning and Configuring Infrastructure · Deploy infrastructure using Infrastructure as Code and Terraform on OCI
A team is adopting Infrastructure as Code using Terraform to manage their OCI resources. They need to provision a VCN, multiple subnets, and a compute instance. To ensure the compute instance is only created after the subnets are available, what Terraform mechanism should be used?
Show answer & explanation
Correct answer: B
Terraform automatically builds a dependency graph by analyzing the references between resources. When the
subnet_idargument in theoci_core_instanceresource references an attribute of theoci_core_subnetresource (e.g.,oci_core_subnet.mysubnet.id), Terraform understands that the subnet must be created before the instance. This is known as an implicit dependency and is the preferred method. Thedepends_onmeta-argument is for creating explicit dependencies when there is no direct reference between resources. - Question 6Intermediate
Configuring and Managing Continuous Integration and Continuous Delivery (CI/CD) · Evaluate and Configure Build and Deployment Pipelines
A DevOps team is setting up a new CI/CD process using OCI DevOps services. They require different build steps for feature branches versus the main branch. For example, feature branches should only run unit tests, while a merge to main should run unit tests, build a container image, and push it to OCIR. How should this conditional logic be implemented within the OCI DevOps build pipeline?
Show answer & explanation
Correct answer: B
The OCI DevOps build service provides predefined environment variables, including
${OCI_TRIGGER_SOURCE_BRANCH_NAME}, which contains the name of the Git branch that triggered the build. The most efficient way to implement conditional logic is to use this variable within a shell script inside thebuild_spec.yaml. This allows a single pipeline and build specification to handle different workflows based on the source branch, reducing management overhead. - Question 7Intermediate
Understand DevOps principles and effectively work with containerization services · Create and manage Oracle Cloud Infrastructure Container Instances
When deploying a containerized application to OCI Container Instances, you need to provide sensitive configuration data, such as an API key, to the container at runtime. What is the most secure method to achieve this?
Show answer & explanation
Correct answer: C
OCI Container Instances integrate directly with OCI Vault for secure secret management. Instead of passing sensitive data in plain text, you store it as a secret in Vault. When configuring the container instance, you can define an environment variable and provide the OCID of the Vault secret as its value. The Container Instances service will securely fetch the secret's content and inject it into the container's environment at runtime, avoiding any exposure of the sensitive data.
- Question 8Advanced
Enabling DevSecOps · Evaluate and configure security for container images used in OCI
A security team wants to enforce a policy that prevents any container images with known 'CRITICAL' or 'HIGH' severity vulnerabilities from being deployed to their production OKE cluster. Which combination of OCI services and features provides the most direct and automated way to implement this policy?
Show answer & explanation
Correct answer: C
This is the most robust and integrated solution. First, OCIR's native scanning automatically identifies vulnerabilities in pushed images. Second, OKE's Admission Controller can be configured with an image policy. This policy can enforce rules at deployment time, such as rejecting any pod creation that attempts to use an image with vulnerabilities exceeding a defined threshold (e.g., 'HIGH' or 'CRITICAL'). This creates a powerful, automated gatekeeper that prevents insecure images from ever running in the cluster.
- Question 9Advanced
Managing Containers using Container Orchestration Engine · Create, manage, and optimize Kubernetes clusters in the OCI environment
A global retail company is building a new e-commerce platform using a microservices architecture. They plan to host this on Oracle Cloud Infrastructure. The key requirements are high availability across multiple geographic regions, independent scalability for each service, and technology stack flexibility for different development teams.
To meet these requirements, the architecture team has decided on a container-based approach. Each microservice will be packaged as a Docker container. They will use OCI DevOps services for their CI/CD pipelines, storing container images in Oracle Cloud Infrastructure Registry (OCIR). For orchestration, they will use managed Kubernetes clusters.
The main challenge is ensuring that application deployments are consistent across all environments (development, staging, production) and that the infrastructure itself can be version-controlled and replicated easily. The operations team is small, so they need a solution that minimizes manual configuration and allows them to manage the entire application lifecycle, from infrastructure to application code, declaratively.
Given these requirements, which approach provides the most comprehensive and declarative solution for managing both the OCI infrastructure and the Kubernetes application deployments?
Show answer & explanation
Correct answer: C
This approach addresses all requirements comprehensively. OCI Resource Manager with Terraform provides a declarative, version-controllable method for provisioning the entire infrastructure (VCN, OKE clusters, etc.), ensuring consistency and repeatability. Helm charts are the industry standard for packaging and managing Kubernetes applications, allowing for templating, versioning, and dependency management. Integrating Helm deployments into an OCI DevOps pipeline automates the application lifecycle on the provisioned infrastructure, creating a full-stack, declarative solution.
- Question 10Intermediate
Managing Containers using Container Orchestration Engine · Understand cluster types, cluster access, and other management activities such as deployments, networking, storage, and observability
A developer needs to connect to a private OKE cluster's Kubernetes API endpoint from their local machine for troubleshooting. The cluster does not have a public IP address, and corporate policy prohibits exposing it to the internet. Which OCI service provides the most secure and straightforward method to establish this connection?
Show answer & explanation
Correct answer: B
OCI Bastion is a fully managed service that provides secure access to private resources. For accessing a private Kubernetes API endpoint, the 'Port Forwarding' session type is ideal. It creates a secure tunnel from the developer's local machine to the Bastion service, which then forwards the connection to the specified private IP and port of the OKE API endpoint. This allows the developer to configure their
kubeconfigto point tolocalhoston the forwarded port, enablingkubectlcommands to work seamlessly and securely without exposing the cluster.
Ready for the real thing?
The full 1Z0-1109-25 simulator has every exam-style question, timed mode, and instant scoring.