Skip to content

1Z0-1072-23 OCI 2023 Architect Associate Practice Questions

Prepare for 1Z0-1072-23 with more than an answer.

207 questions in the full set20 sample questionsUpdated Jan 23, 2026

Unlock the full exam and previous versions

  • v1OCI 2025 Architect Associate 235 questions Locked
  • 1z0-1072-20Legacy OCI 2020 Architect Associate 60 questions Locked
  • 1Z0-1072-23Legacy OCI 2023 Architect Associate 207 questions Current
Exam fee
$245 USD
Level
Associate
Valid for
Oracle Cloud certifications do not expire, but recertification is recommended to stay current
Domains covered on the exam 4
  1. Identity and Access Management20%
  2. Networking35%
  3. Compute20%
  4. Storage25%
  1. 1

    Your company has a hub-and-spoke network topology in OCI. The hub VCN is connected to your on-premises data center via FastConnect. Several spoke VCNs are peered with the hub VCN using Local Peering Gateways (LPGs). The spoke VCNs need to communicate with the on-premises network. What networking component is essential for enabling this traffic flow?

    Show answer details

    Correct answer: B

    This scenario describes a classic use case for transit routing. By default, VCN peering is not transitive. To allow spokes to communicate with the on-premises network through the hub, you must use a Dynamic Routing Gateway (DRG) in the hub. The DRG acts as the central router, and you must configure its route tables to direct traffic between the FastConnect connection, the hub VCN, and the peered spoke VCNs.

  2. 2

    A company wants to migrate a virtualized, on-premises Oracle Linux server to OCI. The server is running on VMware and has a custom kernel and specific drivers not present in the standard Oracle-provided images. What is the correct launch mode to select when importing this custom image to ensure it boots and operates correctly in OCI?

    Show answer details

    Correct answer: C

    Emulated mode is the correct choice for images that require legacy drivers or have custom kernel configurations that are not compatible with OCI's native paravirtualized drivers. Emulation provides a more traditional virtual hardware environment, which increases compatibility for older or highly customized operating systems, even though it may come with a slight performance penalty compared to paravirtualized mode.

  3. 3

    Case Study: Global Retail Corporation (GRC)

    Company Background: GRC is a large retail company with a significant on-premises footprint. They are undertaking a phased migration to Oracle Cloud Infrastructure (OCI) to improve scalability and reduce data center costs. Their primary goal is to establish a secure and resilient network foundation in OCI before migrating critical applications.

    Current Situation: GRC has provisioned a VCN (10.10.0.0/16) in the us-ashburn-1 region. They have established a 10 Gbps FastConnect connection from their primary data center to OCI via a Dynamic Routing Gateway (DRG). They have deployed a shared services VCN for security tools and a production VCN for their e-commerce application. These VCNs are peered with a central hub VCN where the DRG is attached.

    Requirements:

    1. A disaster recovery (DR) site must be established in the us-phoenix-1 region.
    2. The DR site must have a redundant, high-bandwidth connection back to the primary on-premises data center.
    3. The production VCN in us-ashburn-1 must be able to communicate with a new DR VCN in us-phoenix-1 for data replication.
    4. All inter-VCN traffic, both within and across regions, must not traverse the public internet.

    Problem: The network architect needs to design the connectivity for the DR site that meets all requirements. Which architectural design provides the necessary connectivity and redundancy?

    Show answer details

    Correct answer: B

    This solution correctly addresses all requirements. 1) A second FastConnect to Phoenix provides the redundant, high-bandwidth on-premises connection. 2) A new DRG in Phoenix is necessary for connectivity. 3) A Remote Peering Connection between the DRGs in Ashburn and Phoenix provides a private, high-bandwidth path over the OCI backbone for inter-region VCN communication, fulfilling the data replication and no-internet-traversal requirements.

  4. 4

    A database administrator is provisioning a new Block Volume for an Oracle Database that will host a high-transaction, performance-sensitive OLTP application. The primary requirement is to achieve the highest possible IOPS and lowest latency. Which Block Volume performance tier should be selected?

    Show answer details

    Correct answer: D

    The Ultra High Performance (UHP) tier is specifically designed for the most I/O-demanding workloads, such as high-performance Oracle Databases. It provides the highest IOPS and throughput per GB of all the available performance tiers, making it the correct choice for this performance-sensitive OLTP application.

  5. 5

    A security architect needs to ensure that compute instances within a specific compartment can make API calls to the OCI Vault service to retrieve secrets, without storing any long-lived credentials (like API keys) on the instances themselves. This mechanism must be secure and automatic. Which IAM feature should be used to accomplish this?

    Show answer details

    Correct answer: B

    Instance Principals allow compute instances to be authorized actors (principals) that can make API calls. You create a Dynamic Group with a matching rule that includes all instances in the specified compartment. Then, you write an IAM policy granting that Dynamic Group permission to access the Vault service. This allows instances to securely obtain short-lived credentials automatically, without needing to store static keys.

  6. 6

    The OCI OS Management service is used to automate patching for a fleet of Oracle Linux instances. Which of the following tasks can be performed by the OS Management service? (Select THREE)

    Show answer details

    Correct answer: A, C, D

    This is a core function of the OS Management service, allowing administrators to apply security, bug fix, and enhancement updates.

    The service provides detailed inventory management, showing all packages installed on each managed instance.

    Administrators can define their own software sources (repositories) to manage third-party or custom software packages alongside standard OS packages.

  7. 7

    You are troubleshooting a network connectivity issue using the Network Path Analyzer. The analysis is from a VM in Subnet-A (10.0.1.0/24) to another VM in Subnet-B (10.0.2.0/24) within the same VCN. The tool reports that the path is 'INDETERMINATE'. Upon inspecting the details, you see the last successful hop is the source VM's VNIC, and the next hop fails. What is the most likely configuration error?

    graph TD subgraph VCN [VCN 10.0.0.0/16] subgraph Subnet-A [Subnet-A 10.0.1.0/24] VM-A[VM-A 10.0.1.5] end subgraph Subnet-B [Subnet-B 10.0.2.0/24] VM-B[VM-B 10.0.2.10] end end VM-A -->|Fails Here| RouteTable-A{Route Table for Subnet-A} RouteTable-A -->|Missing Route to 10.0.2.0/24| VM-B
    Show answer details

    Correct answer: B

    For traffic to flow between subnets within a VCN, there must be appropriate route rules. The Network Path Analyzer showing a failure immediately after the source VNIC indicates a routing problem. The Route Table for Subnet-A must know how to reach Subnet-B. By default, VCNs have an implicit rule for local traffic, but if this was removed or a custom route table is in use, a missing route to 10.0.2.0/24 would cause the path to be indeterminate.

  8. 8

    A financial services company is deploying a three-tier web application in OCI. The compliance team has mandated that network traffic between the web and application tiers must be strictly controlled, allowing only specific TCP ports. Additionally, the security posture must be easily auditable and scalable as more application servers are added. Which OCI networking security feature should be used to meet these requirements most effectively?

    Show answer details

    Correct answer: B

    Network Security Groups (NSGs) are the optimal choice here. They operate at the VNIC level, allowing for granular, stateful firewall rules to be defined for a specific set of resources (like the application tier) regardless of the subnet they reside in. This application-centric model is more scalable and easier to audit than subnet-wide Security Lists when managing traffic between specific application tiers.

  9. 9

    A data analytics firm uses OCI File Storage Service (FSS) to share large datasets among a cluster of compute instances. The performance of data processing jobs has degraded. Initial investigation reveals that the FSS is experiencing high IOPS and throughput, but the compute instances are underutilized. You need to propose a solution to improve performance without changing the compute instance shapes. What is the most direct way to enhance the FSS performance?

    Show answer details

    Correct answer: B

    OCI File Storage performance is primarily determined by the mount target, not the size of the file system. Creating multiple mount targets for the same file system (ideally in different Availability Domains for high availability) and distributing the compute instance connections among them is the standard method to scale out performance and overcome the throughput limits of a single mount target.

  10. 10

    You are designing an IAM policy to grant a group of junior administrators the ability to manage compute instances within a specific compartment named 'Staging'. However, you must prevent them from terminating any instance that has a defined tag Protection: 'Critical'. Which two IAM policy statements, when combined, would achieve this goal? (Select TWO)

    Show answer details

    Correct answer: A, D

    This statement grants the necessary broad permissions to manage instances (start, stop, create, etc.) within the specified compartment.

    This statement explicitly denies the terminate permission specifically on instances that have the required tag. IAM Deny statements always override Allow statements, making this the correct way to create the exception.

Create an account to continue.