OCI Architect Associate Practice
|
|
Título del Test:
![]() OCI Architect Associate Practice Descripción: 63 questions from the final OCI Architect Associate practice bank. |



| Comentarios |
|---|
NO HAY REGISTROS |
|
Your organization has recently migrated its infrastructure to Oracle Cloud Infrastructure (OCI). The DNS team needs to ensure that virtual machines within a specific VCN can resolve private domain names hosted in a new private DNS zone. Which of the following correctly describes how a private DNS zone is made accessible to resources within a VCN in OCI?. The private DNS zone is attached to a subnet within the VCN, and all resources in that subnet automatically inherit DNS resolution for that zone. The private zone becomes resolvable within a VCN only when it is attached to a view that is associated with the VCN's dedicated resolver. The private DNS zone is attached to a Dynamic Routing Gateway (DRG), which then advertises the zone to all connected VCNs automatically. The private DNS zone is directly attached to the VCN, making it immediately resolvable by all resources within that VCN. A solutions architect at a healthcare company discovers that several OCI compute instances running Oracle Linux have not received critical kernel security patches in months, creating a significant compliance risk. The architect needs a centralized solution to monitor patch compliance and apply security updates across all instances. Which OCI service addresses this requirement?. Artifact Registry. Data Safe. Container Registry. OS Management Hub. A solutions architect at a logistics company receives an urgent request to provision multiple OCI compute instances for a new application rollout. The architect notices that an existing running instance in the OCI tenancy already has the exact configuration and software stack required for the new instances. What is the most efficient image option the architect should recommend to provision these instances with the least amount of effort?. Import an external image using the Bring Your Own Image (BYOI) option and use it as a template for the new instances. Select a pre-configured image from the OCI Marketplace that closely matches the required software stack. Use an Oracle-provided image and customize each instance's software installation using a third-party configuration management tool. Create a custom image from the existing running instance and use it as a template to provision the new instances. You are a cloud architect at a global e-commerce company with servers hosted in multiple regions. Your organization wants to ensure that customers are automatically directed to the nearest or most appropriate server based on where they are located in the world, in order to improve performance and user experience. You have been tasked with configuring an OCI Traffic Management Steering Policy to achieve this. Which Traffic Management Steering Policy should you implement to route DNS traffic to specific endpoints based on the geographical location of end users?. IP Prefix Steering. Geolocation Steering. Proximity Steering. ASN Steering. You are managing storage operations for workloads running on Oracle Cloud Infrastructure (OCI). Your team frequently handles block volume management tasks to meet evolving storage requirements. During a routine review, one of the submitted storage operations is flagged as invalid. Which of the following operations is NOT a valid action within the OCI Block Volume service?. Attaching an existing block volume to a compute instance located in a different availability domain. Restoring a volume from an existing backup to a new, larger volume to support additional workload requirements. Cloning an existing block volume to a new, larger volume to accommodate growing data needs. Expanding an existing block volume in place using offline resizing to increase its capacity. You are provisioning a VM.Standard3.Flex instance with an Oracle Linux 8 platform image. Your security team requires that the instance must: 1. Prevent unauthorized bootloaders and operating systems from executing 2. Store and verify measurements of boot components across reboots to detect tampering Which combination of Shielded Instance features must you enable to meet both requirements?. Measured Boot and Vulnerability Scanning Service. Secure Boot only. Secure Boot and Measured Boot. Measured Boot only. Your organization is planning to migrate a business-critical application to OCI Compute VM instances. During the planning phase, your architecture and licensing teams have outlined the following non-negotiable requirements: Requirement 1: The VMs must run on physical infrastructure that is not shared with any other tenancy or customer. Requirement 2: The software vendor mandates node-based licensing, which requires licensing the entire underlying physical server, not individual VMs. Requirement 3: The solution must allow you to control which VM shapes are deployed on the physical server to optimize resource utilization. Which compute capacity type satisfies all three requirements?. Dedicated host. On-demand capacity. Preemptible capacity. Capacity reservation. You are setting up Oracle Cloud Infrastructure (OCI) File Storage for your organization. After creating a file system and successfully mounting it on your compute instances, you notice that all instances on the subnet can access the file system without any restrictions. What should you configure to control and restrict which NFS clients can access the file system and define their level of access?. Enable in-transit encryption on the mount target to restrict unauthorized client connections. Move the file system to a private subnet to prevent unauthorized instances from mounting it. Update the IAM policies to restrict access to specific compute instances. Configure NFS export options on the export to define access for specific IP addresses or CIDR block ranges. You are a cloud infrastructure architect at a financial institution that is setting up a private Network Load Balancer (NLB) in Oracle Cloud Infrastructure (OCI) to handle internal traffic between application tiers. Before configuring the load balancer, your team needs to verify which protocols are supported by OCI private Network Load Balancers to ensure compatibility with your internal applications. Which THREE protocols does the OCI private Network Load Balancer support?. UDP. HTTP. BGP. iSCSI. ICMP. TCP. You are an administrator overseeing an Oracle Cloud Infrastructure (OCI) environment that includes multiple compute instances with attached block volumes. In an effort to reduce costs and maintain optimal performance, you decide to enable the detached volume performance auto-tuning feature available in the Block Volume service. When a block volume is detached from a compute instance and performance auto-tune is enabled, what change occurs to the volume's performance level?. The performance level is automatically adjusted to Lower Cost (0 VPUs/GB). The performance level is automatically upgraded to Higher Performance. The performance level is automatically set to Balanced. The performance level stays the same as it was before detachment. Your engineering team is designing a hybrid cloud architecture in OCI and needs to configure a Dynamic Routing Gateway (DRG) to connect multiple network resources. Which THREE resources can be attached to a DRG to enable this connectivity?. Subnet. IPSec Tunnel. VNIC. Local Peering Connection. Remote Peering Connections. Virtual Circuits. A solutions architect is designing the networking configuration for a new OCI deployment. During a design review, the team raises several questions about how private IP addresses work with VNICs in OCI. The architect needs to clarify the correct behavior before finalizing the design. Which TWO statements correctly describe private IP address behavior in OCI?. By default, the primary VNIC of an instance in a subnet has one primary private IP address and one secondary private IP address. A private IP can have an optional public IP assigned to it if it resides in a public subnet. By default, the primary VNIC of an instance in a subnet has one primary private IP address. Each VNIC can only have one private IP address. A solutions architect at a retail company is designing a scalable OCI compute infrastructure for the company's e-commerce platform. The architect plans to standardize instance settings using instance configurations and manage workloads through multiple instance pools across different environments - development, staging, and production. While viewing the architecture, the architect needs to advise the team on the correct rules governing instance configurations and instance pools before the deployment begins. Which of the following statements should the architect include in the design guidelines?. An instance pool can have multiple instance configurations associated with it simultaneously, allowing different instance types within the same pool. An instance configuration cannot be deleted if it is associated with an instance pool, but the same instance configuration can be reused across multiple instance pools. A separate instance configuration must be created for each instance pool - the same configuration cannot be reused across multiple pools. An instance configuration can be deleted at any time, even if it is currently associated with an instance pool, as the pool will automatically revert to default settings. You are an architect at a healthcare organization running critical applications on Oracle Cloud Infrastructure (OCI). Several departments have reported intermittent connectivity issues between their cloud resources, but no actual network outage has been detected. A thorough investigation is needed to pinpoint the root cause without disrupting live traffic. Which of the following best describes how OCI's Network Path Analyzer (NPA) tool would help in this situation?. It provides real-time monitoring of live network traffic across all resources, enabling proactive detection of security threats and unauthorized access. It dynamically adjusts routing paths based on current traffic patterns to automatically resolve connectivity issues between departments. It sends actual traffic between the source and destination endpoints to actively diagnose and reproduce the connectivity issues being reported. It collects and analyzes the network configuration to identify any misconfigurations that may be impacting connectivity between resources. You are a cloud infrastructure manager at a global retail company that operates across 10 regions on Oracle Cloud Infrastructure (OCI). Your team is planning a major data transfer from your primary region in the US to backup regions in Europe and Asia. You recall that OCI provides an Inter-Region Latency dashboard. How would this dashboard help you in planning your data transfer strategy?. It's designed for troubleshooting latency issues within your specific applications, providing targeted insights for optimizing performance. It provides real-time data specific to your tenancy's workloads. It offers a current and historical view of latency snapshots, enabling you to analyze up to a 30-day history. It focuses solely on latency within your own tenancy ensuring accurate monitoring of data transfer. Company ABC is currently paying $450,000.00 USD per month in egress fees for 10 Petabytes (1 Petabyte = 1000 Terabytes | 1 Terabyte = 1000 Gigabytes) of Outbound Data Transfer in North America with their existing cloud provider. Their CFO has mandated a significant reduction in cloud spending without any reduction in data consumption. As their cloud consultant, you recommend migrating to Oracle Cloud Infrastructure (OCI), where Outbound Data Transfer in North America is priced at $0.0085 USD per Gigabyte, with a high threshold for free outbound data transfer. How much will Company ABC spend per month for 10 Petabytes of Outbound Data Transfer on OCI?. $85,000.00. $84,915.00. $0.00 (OCI offers free egress for enterprise customers). $225,000.00. A team is deploying a backend application on multiple OCI Compute instances. The application must securely access OCI Object Storage and other services without storing user credentials or configuration files on the instances. The development team has already updated the application to use the Instance Principals authentication provider available in the OCI SDK. However, during testing, the application fails to successfully call OCI APIs. As the cloud architect, you are asked to troubleshoot the issue. Which of the following actions would NOT help resolve the problem?. Ensure the application and OCI SDK are deployed on all instances that are part of the dynamic group. Generate Auth Tokens to enable the instances to authenticate API requests. Verify that the dynamic group was created with the correct matching rules to include the intended compute instances. Verify that a policy exists granting the required permissions to the dynamic group for accessing OCI services. A developer at a fintech company creates a new dynamic group in OCI and defines matching rules to include all compute instances in a specific compartment. After creating the dynamic group, the developer expects the instances to automatically have access to OCI services and starts testing but all API calls from the instances are being rejected. What is the most likely reason for this behavior?. The matching rules are incorrectly defined and need to be rewritten using instance OCIDs instead of compartment OCIDs. Dynamic groups can only be used to grant access to OCI services within the same compartment where the group was created. Dynamic groups require a separate IAM policy to be created that explicitly grants the group permissions before instances can access OCI services. The compute instances need to be manually added to the dynamic group before they can make API calls to OCI services. Your organization needs to connect workloads running in two separate Oracle Cloud Infrastructure (OCI) regions so they can communicate securely. What components must be in place to successfully establish this remote peering between the two Virtual Cloud Networks (VCNs)?. Two VCNs with nonoverlapping CIDRs in the same region, a dynamic routing gateway (DRG) attached to each VCN, and a direct connection between the DRGs. Two VCNs with overlapping CIDRs in different regions, a virtual private network (VPN) gateway attached to each VCN, and a direct connection between the VPN gateways. A single VCN with nonoverlapping CIDRs in each region, a dynamic routing gateway (DRG) attached to each VCN, and a direct connection between the DRGs. Two VCNs with nonoverlapping CIDRs in different regions, a dynamic routing gateway (DRG) attached to each VCN, a remote peering connection (RPC) on each DRG, and a connection established between the RPCs. An architect has deployed a three-tier application on Oracle Cloud Infrastructure (OCI), with web servers in a public subnet (10.0.1.0/24) and database servers in a private subnet (10.0.2.0/24). A bastion host has been provisioned in the public subnet to allow secure administrative access to backend resources. The public subnet is protected by the following security list: Type | Direction | CIDR | Protocol | Source Port | Destination Port ---------|-----------|-------------|----------|-------------|----------------- Stateful | Ingress | 0.0.0.0/0 | TCP | All | 80 Stateful | Egress | 10.0.2.0/24 | TCP | All | 1521 Stateful | Ingress | 10.0.2.0/24 | TCP | All | 21 Stateful | Ingress | 10.0.2.0/24 | TCP | All | 80 The architect has also created a Network Security Group (NSG) and assigned it exclusively to the bastion host: Type | Direction | CIDR | Protocol | Source Port | Destination Port ---------|-----------|-------------|----------|-------------|----------------- Stateful | Ingress | 0.0.0.0/0 | TCP | All | 21 Stateful | Ingress | 0.0.0.0/0 | TCP | All | 443 Stateful | Ingress | 10.0.2.0/24 | TCP | All | 22 The architect has verified that all route tables are correctly configured and an Internet Gateway is attached to the VCN. However, when attempting to SSH into the bastion host from a remote location over the Internet, the connection consistently fails. What is the most likely cause of this connectivity issue?. Internet-facing traffic rules should only be defined at the NSG level and not within the security list. The SSH connection should succeed because port 22 is already open on the NSG for the bastion host. The public subnet is missing a route rule pointing to the Internet Gateway, preventing inbound SSH traffic. Neither the security list nor the NSG permits SSH traffic from the Internet, blocking all inbound SSH connections to the bastion host. You are managing block storage on Oracle Cloud Infrastructure (OCI) and have enabled Cross Region Replication for a block volume in the US West (Phoenix) region, with US West (San Jose) designated as the destination region. The replication has been running successfully for several days. Your organization is planning a regional expansion and needs to provision workloads in the San Jose region. A team member suggests that since the replica already exists in San Jose, it can be immediately used as a block volume without any additional steps, just like any other block volume. Is your team member correct, and what action, if any, must be taken to use the replica as a block volume in the US West (San Jose) region?. The team member is incorrect - the replica must first be activated to provision it as a new block volume in the destination region. The team member is incorrect the replica must first be restored from a backup stored in the San Jose region, because Cross Region Replication does not directly produce an attachable volume. The team member is incorrect - the replica must first be triggered to convert it into a usable block volume before it can be attached to an instance. The team member is correct - the replica is automatically available as a block volume and can be attached to an instance in San Jose immediately. A DevOps team at a financial firm accidentally moved a critical database instance from Compartment A to Compartment B within their OCI tenancy. Both compartments sit directly under the root compartment and are not nested within each other. The IAM policies that grant authorized users access to the database were written and attached specifically to Compartment A. How will this compartment change impact the authorized users' access to the database?. The existing IAM policies tied to Compartment A will continue to function normally, and user access to the database will remain unaffected despite the move. IAM policies in OCI do not apply to compartments they only govern individual resources, so the move will have no impact. Authorized users will immediately lose access to the database because the IAM policies are attached to Compartment A, and the database now resides in Compartment B. OCI prevents resources from being moved between compartments once they have been assigned, so the accidental move could not have occurred. A large healthcare organization has deployed Oracle Cloud Infrastructure and has a single identity domain administrator managing all IAM tasks. As the organization grows, the workload becomes overwhelming the administrator needs to delegate specific responsibilities such as managing users, configuring security settings, and handling application access to other trusted staff members, without granting them full superuser privileges. Which OCI IAM feature should the identity domain administrator use to distribute these responsibilities effectively?. Assign staff members to appropriate administrator roles such as User Administrator, Security Administrator, and Application Administrator within the identity domain. Create additional IAM policies at the root compartment level to grant specific permissions to each staff member. Provision separate identity domains for each administrative function and assign staff members as domain administrators. Grant all trusted staff members the identity domain administrator role to ensure they have sufficient access to carry out their tasks. A financial services firm operating on Oracle Cloud Infrastructure (OCI) has set up a multi-level compartment hierarchy - with a root compartment branching into dedicated sub-compartments for different business units, environments, and project teams. As part of a new initiative, a virtual machine is provisioned within the development sub-compartment assigned to one of their project teams. Which of the following statements is INCORRECT regarding the virtual machine in this scenario?. Access to the virtual machine is exclusively governed by policies attached to the root compartment, with no consideration of policies at the sub-compartment level. If required, the virtual machine can be relocated to a different compartment within the same tenancy. The virtual machine can interact with resources such as a Virtual Cloud Network (VCN) that resides in a different compartment. The virtual machine belongs to a single compartment at any given time and cannot exist in multiple compartments simultaneously. Your company has migrated its core banking application to a Virtual Cloud Network (VCN) in the us-ashburn-1 region on Oracle Cloud Infrastructure (OCI). The application processes millions of financial transactions daily and cannot tolerate any connectivity disruption between the on-premises data center and OCI. As the Lead Network Architect, you must ensure there is no single point of failure in the hybrid connectivity design. Which TWO architectures achieve full redundancy for the us-ashburn-1 VCN?. Configure one FastConnect virtual circuit to the us-ashburn-1 region and the second FastConnect virtual circuit to the us-phoenix-1 region. Configure one FastConnect virtual circuit to the us-ashburn-1 region and a Site-to-Site VPN to the us-ashburn-1 region. Configure a Site-to-Site VPN from a single on-premises CPE. Configure two FastConnect virtual circuits to the us-ashburn-1 region and terminate them in diverse hardware on-premises. A cloud architect at a multinational corporation is designing the IAM policy framework for their OCI tenancy. The tenancy has a complex compartment hierarchy with multiple teams - developers, database administrators, and security analysts - each requiring different levels of access. The security team has flagged that some developers currently have administrative-level access to production databases, which they do not need for their daily tasks. The architect is tasked with restructuring the IAM policies to align with OCI's default security principle. Which restructuring approach best reflects the principle of least privilege in this scenario?. Redesign the IAM policies so that developers are granted only the permissions required to interact with development resources, database administrators are restricted to database management actions, and security analysts are limited to audit and monitoring capabilities - each scoped to their respective compartments. Consolidate all IAM policies into a single root compartment policy that grants uniform access to all teams, ensuring no team is accidentally denied access to resources they may need in the future. Revoke all existing permissions across the tenancy and require each team to submit access requests on a case-by-case basis, which are then manually approved by the identity domain administrator. Grant developers read-only access across all compartments, including production, so they can troubleshoot issues without the risk of making unintended changes to critical resources. In OCI IAM, a policy condition uses the variable request.networkSource.name. What is the purpose of using this variable in a policy statement?. To define the maximum number of requests allowed from a specific network source per day. To log and audit all network requests made to OCI resources for compliance purposes. To identify the name of the OCI compartment from which the request originated. To restrict access to OCI resources based on a predefined network source object that contains a list of allowed IP addresses. You are managing Oracle Cloud Infrastructure (OCI) File Storage and want to accurately monitor the storage utilization of your file system, including snapshots and clones. You are deciding between using the df command and the du command from your instance. Which command should you use to get an accurate view of the file system's metered storage utilization?. The df command can only be used for live file system data and does not account for snapshots or clones, making it unreliable for tracking total metered storage utilization. Both df and du commands return identical results and can be used interchangeably to view metered storage utilization. The df command, as it reports the same value as the meteredBytes property and accurately reflects the file system's metered storage utilization. The du command, as it walks the entire directory tree and provides a precise count of all files including snapshots and clones. You are managing Object Storage on Oracle Cloud Infrastructure (OCI) for a Standard storage tier bucket. The bucket currently has a lifecycle policy rule configured to automatically move objects to the Infrequent Access tier after 30 days. As the application grows, the data access patterns are becoming unpredictable, and the organization decides to enable Auto-Tiering on the bucket to optimize storage costs automatically. During a review meeting, it is suggested that since the bucket is already a Standard tier bucket with a lifecycle policy in place, enabling Auto-Tiering should work seamlessly alongside the existing lifecycle policy without any changes. Is this assumption correct, and what action, if any, must be taken before enabling Auto-Tiering on the bucket?. The assumption is incorrect - the existing lifecycle policy rule that moves objects to the Infrequent Access tier must be deleted before Auto-Tiering can be enabled. The assumption is incorrect - the bucket must first be converted to an Archive tier bucket before Auto-Tiering can be enabled. The assumption is correct - Auto-Tiering can be enabled alongside the existing lifecycle policy without any conflict. The assumption is incorrect - Auto-Tiering can only be enabled on a newly created bucket and cannot be applied to an existing bucket. A financial services company is migrating its core banking application to OCI. Their security team is specifically concerned about sensitive data being exposed during active computation, including from the hypervisor, OCI itself, or any other unauthorized entity accessing the underlying infrastructure. The solution architect recommends OCI Confidential Computing to address this concern. Which statement best justifies this recommendation?. It encrypts and isolates in-use data and the applications processing that data, thereby preventing unauthorized access or modification. It optimizes network performance and reduces latency through advanced routing algorithms and caching mechanisms. It enables users to securely store and retrieve data by using distributed file systems, ensuring high availability and fault tolerance. It provides automatic scalability and load balancing capabilities, which allow seamless integration with other cloud providers. You recently joined a cloud architecture team responsible for designing and governing OCI Compute deployments across the organization. During an internal design review, a colleague claims that the following are all valid Oracle Cloud Agent plugins available on OCI Compute instances. You suspect one of them is incorrect and want to verify before finalizing the architecture documentation. Which option is NOT a valid Oracle Cloud Agent plugin?. OS Management Hub Agent. Compute Instance Run Command. Bastion. Instance Reboot Manager. Your company runs an e-commerce platform that triggers batch jobs after every purchase to generate invoices and receipts, which are then saved to object storage. These jobs are short-lived, typically completing within minutes, but order volumes spike unpredictably during flash sales and promotions. Your team wants to minimize compute costs and avoid paying for idle capacity between order bursts, while ensuring invoices are always saved before the instance terminates. Which compute instance type best meets these requirements?. On-Demand instances guarantee availability, making them the safest and most cost-effective choice for batch jobs that must complete without interruption. Dedicated Host instances eliminate shared infrastructure overhead, reducing processing time and overall cost for high-volume order processing workloads. Burstable instances automatically scale CPU up and down based on demand, eliminating idle compute costs during low-order periods. Preemptible instances offer significantly lower cost for short-lived batch workloads, with the ability to save outputs to object storage before the instance is reclaimed. You are managing Object Storage on Oracle Cloud Infrastructure (OCI) and have created a pre-authenticated request to share a set of objects in a bucket with a partner company. The partner has been actively accessing the objects using the pre-authenticated request URL. After a routine security review, your security team determines that the partner company's access needs to be modified, specifically the expiration date and the set of objects accessible through the existing pre-authenticated request need to be updated. What action must be taken to update the partner's access requirements?. Temporarily deactivate the existing pre-authenticated request, make the required modifications, and reactivate it with the updated access requirements. Provide your OCI credentials to the partner company so they can update the pre-authenticated request settings directly. Edit the existing pre-authenticated request to update the expiration date and the set of accessible objects as needed. Delete the existing pre-authenticated request and create a new one with the updated requirements, then share the new URL with the partner company. A company hosts its public web application on Oracle Cloud Infrastructure (OCI) behind a Layer 7 HTTP Load Balancer. Users from different regions report that pages load slowly, especially for static content such as CSS and JavaScript files. The architects decide to enable Web Application Acceleration on the load balancer to improve the performance of the application. Which capability of Web Application Acceleration helps address this requirement?. Increasing the availability of the load balancer by implementing redundancy mechanisms. Encrypting HTTP traffic between clients and backend servers to ensure secure communication. Monitoring and analyzing HTTP traffic patterns to identify potential security vulnerabilities. Speeding up traffic on layer 7 HTTP load balancers through caching and compression techniques. As a Cloud Architect at Company ABC, you are presenting a hybrid connectivity proposal to the leadership team. The CTO asks you to justify why Site-to-Site VPN on Oracle Cloud Infrastructure (OCI) was chosen over other connectivity options, and what specific architectural advantages it offers. Which TWO statements accurately describe key characteristics of OCI Site-to-Site VPN that strengthen your recommendation?. OCI Site-to-Site VPN establishes a dedicated private fiber connection, guaranteeing consistent sub-millisecond latency for all workloads. OCI automatically provisions redundant IPSec tunnels for each VPN connection, ensuring high availability without additional configuration. OCI Site-to-Site VPN can deliver bandwidth exceeding 2 Gbps, making it suitable for high-throughput enterprise workloads. OCI Site-to-Site VPN supports both static routing and dynamic routing via Border Gateway Protocol (BGP), giving network architects flexibility in route management. You are managing Oracle Cloud Infrastructure (OCI) File Storage and need to recover a file that was accidentally deleted from your file system. You have previously taken snapshots of the file system. Where can you access the snapshots to recover the deleted file?. Snapshots are accessible only through the OCI CLI and cannot be browsed directly from the file system. Snapshots are stored in a separate Object Storage bucket and must be downloaded before the file can be recovered. Snapshots are accessible from the OCI Console under the Block Storage section, where they can be mounted and browsed. Snapshots are accessible under the root directory of the file system at the .snapshot/name path. A developer at a mid-sized company is setting up an integration between Oracle Cloud Infrastructure and a third-party storage service. While configuring the credentials, the developer notices that OCI offers auth tokens as an authentication option. What is the most accurate description of how auth tokens function within OCI IAM?. Auth tokens are Oracle-generated strings used to authenticate with third-party APIs that do not support OCI's signature-based authentication, with each user allowed up to two active tokens at a time. Auth tokens automatically expire after a set period, requiring users to regularly generate them to maintain uninterrupted access to third-party services. Auth tokens require an administrator to create a dedicated IAM policy before a user can generate or manage their own tokens in the Console. Auth tokens are user-defined strings that can be customized to meet the naming conventions of third-party APIs, making them easier to manage across integrations. A leading e-commerce company is building a consumer-facing portal that requires a robust identity solution. The platform must support social sign-in options, allow users to manage their own passwords and profiles, obtain user consent through terms of use agreements, and be capable of scaling to accommodate millions of registered customers. Which IAM Identity Domain type should the organization select to meet these requirements?. External User. Free. Oracle Apps Premium. Premium. A large enterprise has recently migrated to Oracle Cloud Infrastructure and wants to leverage its existing Microsoft Active Directory setup without disrupting current workflows or user credentials. In what way does the AD Bridge component within OCI IAM identity domains help this organization improve its identity and access management (IAM) practices?. It adds an extra layer of authentication by integrating with Active Directory, reducing the risk of unauthorized access to OCI resources. It enables selected AD users to be granted administrative control over specific resources within the OCI identity domain, without giving them full administrative privileges. It simplifies user provisioning by enabling automated synchronization of user accounts and group memberships from an existing Microsoft Active Directory (AD) environment. It connects directly with OCI MFA providers, ensuring that users who sign in with their AD credentials are still required to complete multi-factor authentication seamlessly. You are managing an OCI Object Storage bucket with versioning enabled. The bucket contains an object called report.pdf that has multiple previous versions. During a routine cleanup, you delete report.pdf without targeting a specific version ID, intending to permanently remove the object and all its versions. A few days later, you notice that the object and its previous versions are still visible in the bucket. You escalate this to your storage administrator, who points out that the deletion may not have worked as expected. What actually happened when report.pdf was deleted without targeting a specific version ID, and what must be done to permanently remove the object?. The latest version of report.pdf became a previous version and a delete marker was created. To permanently remove the object, each version must be explicitly deleted by its version ID. Deleting an object in a versioning-enabled bucket permanently deletes the latest version and all its previous versions in a single operation. The object should no longer be visible. The deletion was automatically suspended because versioning was enabled. Versioning must be suspended first before any object can be permanently deleted from the bucket. The latest version of report.pdf was permanently deleted, but the previous versions were retained. Deleting the previous versions requires disabling versioning on the bucket first. A solutions architect at a retail company is informed that one of their OCI compute instances cannot be live-migrated during an upcoming infrastructure maintenance event. OCI sends a notification indicating that a maintenance due date has been scheduled within 14 to 16 days. The architect decides not to proactively reboot the instance before the scheduled maintenance due date. What will OCI do in this situation?. OCI will automatically reboot migrate the instance. OCI will send another notification requesting the architect to reboot the instance within the next 7 days. OCI will send another notification requesting the architect to reboot the instance within the next 14 days. The instance will be terminated permanently, requiring the architect to launch a new instance from the retained boot volume. You are setting up OCI File Storage replication for your organization's disaster recovery strategy. You identify an existing file system in the destination region to use as the replication target. Before configuring replication, you want to confirm whether this file system is eligible to be used as a target. Which of the following conditions would make a file system ineligible to be used as a replication target?. The file system does not have any snapshots created by the user. The file system is located in a different region than the source file system. The file system is located in a different availability domain than the source file system. The file system has previously been exported through a mount target. You are an architect at a large financial firm that has recently expanded its operations on Oracle Cloud Infrastructure (OCI). The organization has multiple Virtual Cloud Networks (VCNs) spread across different departments, and a full review of the virtual network infrastructure is required to ensure all connections and relationships between VCNs are properly configured. With limited time available, a quick yet comprehensive way is needed to understand the entire network layout without manually reviewing each VCN individually. How would OCI's Network Visualizer tool help in completing this review efficiently?. It continuously monitors live network traffic across all VCNs, enabling proactive detection of security threats and unauthorized access attempts. It displays the topology of all VCNs within a selected region and tenancy in a single view, allowing you to quickly understand their relationships and connections. It generates automated reports on network performance metrics, facilitating decision-making for optimizing network resources and bandwidth allocation. It provides detailed information about the physical network components underlying your OCI infrastructure, helping you identify hardware-level issues. You are managing storage for an enterprise application on Oracle Cloud Infrastructure (OCI). Your team has decided to reorganize the storage architecture and no longer requires a particular volume group. What happens to the individual volumes when the volume group is deleted in the OCI Block Volume service?. The individual volumes are detached from their compute instances but are not deleted. The individual volumes are moved to an archived state and must be manually restored before use. The individual volumes are retained and remain available even after the volume group is deleted. All individual volumes within the group are automatically deleted along with the volume group. A cloud engineer wants to analyze network traffic generated by a compute instance in Oracle Cloud Infrastructure (OCI) without affecting the production workload. The engineer configures a Virtual Test Access Point (VTAP) to mirror traffic from the instance's VNIC and send it to the designated target. Which requirement must be met for the VTAP configuration to successfully deliver mirrored traffic to the target?. The VTAP target must be a network load balancer with a UDP listener on port 4789, located in the same VCN as the VTAP source. The VTAP target can be any load balancer within the same Virtual Cloud Network (VCN). The VTAP target must be a network load balancer with a TCP listener on port 80, located in the same VCN as the VTAP source. The VTAP target can be any resource within the same subnet as the VTAP source. You are managing Object Storage on Oracle Cloud Infrastructure (OCI) and have configured replication between a source bucket in US East (Ashburn) and a destination bucket in US West (Phoenix). The replication policy has been active for several months and objects are being successfully replicated. Your organization now needs to set up a secondary replication from the destination bucket in US West (Phoenix) to a third bucket in EU Frankfurt, to ensure data is available across three regions for compliance purposes. Before proceeding, you review the replication constraints to confirm whether this configuration is supported. Which of the following correctly describes the outcome of this proposed configuration?. The configuration is supported - a destination bucket can also act as a source bucket, allowing chained replication across multiple regions. The configuration is not supported - a destination bucket cannot also be a replication source, as chained replication is not supported in OCI Object Storage. The configuration is not supported - OCI Object Storage replication is limited to two regions only, and no additional destination buckets can be added once a replication policy is active. The configuration is supported - however, a separate replication policy must be created in each region and authorized individually before chained replication can take effect. A solutions architect is designing a secure data processing pipeline for a financial institution on Oracle Cloud Infrastructure (OCI). The architecture has internet-facing web servers in a public subnet and database servers in a private subnet that perform nightly batch operations, pulling large datasets from OCI Object Storage for reconciliation and audit purposes. The security team has strictly mandated that all traffic between internal compute resources and OCI services must never traverse the public Internet and must not require additional virtual appliances. Which OCI feature best satisfies all of these requirements?. Use a NAT Gateway to enable private access to Object Storage. Use a VPN Gateway to create an encrypted tunnel to Object Storage. Use a Service Gateway to establish a secure connection to Object Storage. Use a Local Peering Gateway to peer with the Object Storage subnet. A solutions architect is designing the network infrastructure for a new application on OCI. As part of the design, the architect needs to create a VCN and must select a valid CIDR block that complies with RFC 1918 private address ranges and OCI's allowable VCN size requirements. Which of the following CIDR blocks is valid for creating an OCI VCN?. 10.0.0.0/8. 192.168.1.0/8. 172.16.0.0/16. 0.0.0.0/0. You are managing Oracle Cloud Infrastructure (OCI) File Storage for your organization. A compute instance that has been granted access to a file system through NFS export options is suddenly unable to mount it. After reviewing the export options, you confirm that the instance's IP address is correctly listed and has the appropriate access level configured. All IAM policies are also verified to be in order. Which security layer needs to be adjusted to restore access?. Network Security. NFS Export Options. IAM Policy. UNIX Security. You are managing Object Storage on Oracle Cloud Infrastructure (OCI) and have been using multipart uploads to transfer several large files to a bucket. Due to network instability, a few multipart uploads have failed midway and remain uncommitted in the bucket. During a routine cost review, you notice unexpected storage charges and suspect the uncommitted multipart upload parts may be contributing to the additional costs. What is the most efficient approach to address this issue and prevent it from recurring in the future?. Manually identify and delete the uncommitted multipart upload parts, and re-upload the objects as single-part uploads to avoid future failures. Delete and recreate the bucket, as uncommitted multipart upload parts are automatically cleaned up when the bucket is refreshed. Configure an object lifecycle policy rule to automatically delete uncommitted or failed multipart uploads after a specified number of days to prevent recurring storage charges. Raise a support request with OCI, as uncommitted multipart upload parts can only be removed by Oracle support and are not accessible to end users. A solutions architect is conducting a post-implementation security audit for a financial institution running multiple workloads across several VCNs in an OCI tenancy. During the audit, the architect discovers that a junior network administrator had previously been assigned to enforce a company-wide security policy that prohibits SSH access to all compute instances. The administrator used Tenancy Explorer to locate all VCNs and diligently removed port 22 from the Security Lists across every VCN in the tenancy. However, during the architect's validation exercise, one compute instance continues to accept inbound SSH connections from the internet despite the Security List changes, raising a potential compliance violation. As the architect responsible for identifying the root cause and recommending a remediation strategy, what is the most likely explanation for this security gap?. The VCN's route table contains a residual route rule permitting port 22 traffic, effectively bypassing the Security List modifications made by the administrator. The VNIC of the affected compute instance is associated with a Network Security Group (NSG) containing a stateful ingress rule that permits all protocols from any source (0.0.0.0/0), which continues to allow SSH traffic independently of the Security List rules that were modified. The VCN hosting the affected instance still has an Internet Gateway attached, which independently allows inbound SSH traffic without relying on Security List rules. The VNIC of the affected instance is attached to a Cluster Network configured with a stateful ingress rule allowing all protocols from any source (0.0.0.0/0), which takes precedence over the Security List restrictions applied at the VCN level. You are managing Oracle Cloud Infrastructure (OCI) File Storage and need to create a clone of an existing file system. Before proceeding, you want to confirm the prerequisites for creating a clone. What is required before you can create a clone of a file system in OCI File Storage?. The file system must be detached from all mount targets before a clone can be created. At least one snapshot of the file system must be available to use as the blueprint for the clone. The file system must be moved to the Archive storage tier before cloning is supported. The file system must be fully hydrated before it can be used as a source for cloning. You are managing an OCI Object Storage bucket that contains two objects: ObjectA: last modified 16 months ago ObjectB: last modified 5 months ago You create a time-bound retention rule with a duration of 1 year on the bucket. What is the impact of this retention rule on ObjectA and ObjectB immediately after the rule is applied?. ObjectA can be modified or deleted immediately, while ObjectB is protected from modification or deletion for the next 7 months. Both ObjectA and ObjectB are protected from modification or deletion for the next 1 year from the date the retention rule is created. Neither ObjectA nor ObjectB can be modified or deleted, as retention rules lock all objects in the bucket regardless of their Last Modified timestamp. ObjectA is protected from modification or deletion for the next 7 months, while ObjectB is protected for the full 1 year. A cloud architect at a healthcare company deletes a dynamic group named HealthOps and later creates a new dynamic group with the exact same name HealthOps. The administrator assumes that the existing IAM policies referencing the old HealthOps dynamic group will automatically apply to the newly created group since the name is identical. Is this assumption correct, and why?. Yes, because OCI IAM identifies dynamic groups by their name, so any policies referencing HealthOps will automatically apply to the new group. No, because OCI does not allow a new dynamic group to be created with the same name as a previously deleted group. No, because OCI IAM internally identifies dynamic groups by their OCID, and the new group will have a different OCID than the deleted group, making the old policies ineffective. Yes, because deleted dynamic groups retain their OCID for 30 days, allowing newly created groups with the same name to inherit the same OCID. As a Senior Cloud Architect at Company ABC, you are designing a hybrid cloud connectivity solution between the company's on-premises data center and Oracle Cloud Infrastructure (OCI). The solution requires private access to a managed database residing in a private subnet within a VCN. After evaluating the team's requirements - limited budget, minimal bandwidth needs, and no requirement for dedicated connectivity - you recommend a Site-to-Site VPN as the most appropriate architecture. During implementation, the on-premises network team provides you with the public IP address of their edge router. As the architect responsible for the OCI configuration, which object do you create in OCI to represent the on-premises router and enable the VPN setup to proceed?. Internet Gateway. Customer Premises Equipment (CPE). Dynamic Routing Gateway (DRG). IPSec Tunnel. Your organization is deploying a mission-critical application on Oracle Cloud infrastructure in the US West (Phoenix) region. As part of the infrastructure planning, the architecture team has mandated the following: - The deployment must use Capacity Reservations to guarantee compute availability. - The following instance types must be provisioned: 10 VM.Standard2.2 and 6 VM.Standard.E4.Flex - To comply with the company's High Availability (HA) policy, no single point of failure is acceptable - instances must be distributed across a minimum of two Availability Domains. - To reduce management overhead, you must use the fewest number of capacity reservations possible. Given the architectural constraints of OCI Capacity Reservations and the HA requirements above, what is the minimum number of capacity reservations you must create?. One. Two. Four. Three. A cloud architect is evaluating the capabilities of Oracle Cloud Infrastructure (OCI) Object Storage as part of the organization's cloud migration planning. While reviewing the service documentation, they want to ensure that all assumptions about the service are accurate before finalizing the migration plan. Which of the following statements about the OCI Object Storage service is NOT true?. Object Versioning is enabled at the namespace level. Immutable option for data stored in Object Storage can be set via retention rules. Object Storage resources can be shared across tenancies. Object Lifecycle rules can be used to either archive or delete objects. A solution architect at a financial services company is designing a highly available, multi-tier application architecture on Oracle Cloud Infrastructure (OCI). As part of the network design, the architect needs to define the public IP addressing strategy for compute instances that will serve internet client traffic. Which TWO statements should the architect consider TRUE when designing the Public IP addressing plan for the OCI-based architecture?. Public IP addresses can be ephemeral or reserved. By default, an instance in a public subnet has one primary public IP address. You can assign a given instance multiple public IPs across one or more VNICs. You must use OCI-provided public IP addresses. You cannot bring your own IP addresses to OCI. You are managing Oracle Cloud Infrastructure (OCI) File Storage for your organization. You create a new file system and add a 5 GB file to it. Shortly after, you take a snapshot of the file system without making any further changes to the data. After the hourly update cycle is complete, what will be the total meteredBytes reported by the OCI File Storage service?. 7.5 GB. 6 GB. 10 GB. 5 GB. You are part of a cloud architecture team that manages hundreds of OCI Compute instances across multiple regions. Your team wants to use the OCI run command feature to automate patching scripts and configuration tasks across instances - including some that have no public IP addresses or open inbound ports, and some running Windows Server. Before rolling it out, you review the technical constraints. Which statement about the OCI Compute run command feature is TRUE?. You cannot run commands on an instance if the instance does not have SSH access or open inbound ports. The Compute Instance Run Command plugin must be enabled and running before the feature can be used. The run command feature does not require any Oracle Cloud Agent plugins to be enabled and running. The run command feature is not supported on compute instances that use the Windows Server platform images. You are managing block storage on Oracle Cloud Infrastructure (OCI) and need to clone an existing block volume to set up a test environment. Before proceeding, you review the clone capabilities of the OCI Block Volume service. Which of the following statements accurately reflects what you can expect when cloning the volume?. The volume must be detached from the production instance before it can be cloned. The cloned volume will be created in a different region, allowing you to isolate the test environment geographically. You can increase the size of the cloned volume during the clone process to accommodate the additional test data. Cloning the volume will take longer than creating a backup. You are a cloud architect at a retail company reviewing OCI compute costs for internal payroll and expense reporting applications. You find that CPU utilization hovers around 10–15% for most of the month, spiking only during the last week when payroll runs and expense deadlines hit. You are evaluating whether burstable instances are suitable for these workloads. Which TWO statements are correct regarding the Oracle Cloud Infrastructure (OCI) burstable instances?. Burstable instances cost more than regular instances with the same total OCPU count. Burstable instances are designed for scenarios where an instance is typically idle and has low CPU utilization with occasional spikes in usage. Burstable instances are designed for scenarios where an instance is not typically idle and has high CPU utilization. Burstable instances are charged according to the baseline OCPU. Baseline utilization is a fraction of each CPU core, either 25% or 75%. A solutions architect is migrating on-premises Linux workloads to OCI using the Bring Your Own Image (BYOI) approach. The existing VMs run a modern Linux kernel (version 4.x) and the architect wants to ensure the best possible performance after migration. Which combination of image format and launch mode should the architect select?. OVA format, uploaded to Block Storage, launched in emulated mode. VMDK or QCOW2 format, uploaded to Object Storage, launched in emulated mode. VMDK or QCOW2 format, uploaded to Object Storage, launched in paravirtualized mode. VDI format, uploaded to Object Storage, launched in paravirtualized mode. DOCUMENTATION CROSS-CHECK — EDITORIAL NOTES (not part of the original questions) Second block, question 14 (cross-region block volume replica): The bank answer is correct. Activate the replica to create a new volume from it; the activation creates the new volume by cloning the replica. Oracle documentation: https://docs.oracle.com/en-us/iaas/Content/Block/Tasks/create-activate-replica-bv-volume.htm Second block, question 33 (Network Path Analyzer): The bank answer is correct. NPA analyzes routing and security configuration; it does not send actual traffic or monitor live traffic. Oracle documentation: https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/path_analyzer.htm Public IP question: The original stem says “Which TWO,” but Oracle documentation supports three true options: ephemeral or reserved public IPs; a default public IP for instances launched in a public subnet unless disabled; and multiple public IP objects across one or more VNICs. The “cannot bring your own IP” option is false. All three true options are marked in this answer key. Oracle documentation: https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/managingpublicIPs.htm Oracle BYOIP documentation: https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/BYOIP.htm. |





