1Z0-997-25 Oracle Cloud Infrastructure 2025 Architect Professional Practice Questions
Prepare for 1Z0-997-25 with more than an answer.
Unlock the full exam and previous versions
- v1Oracle Cloud Infrastructure 2025 Architect Professional 250 questions Current
- 1z0-997-20Legacy OCI 2020 Architect Professional 48 questions Locked
- Exam fee
- $245 USD
- Level
- Professional
- Valid for
- Follows Oracle Cloud Recertification policy
Domains covered on the exam 7
- Architecting Cloud-Native Solutions15%
- Designing High Availability and Disaster Recovery Solutions20%
- Implementing Security Solutions15%
- Implementing and Operating Databases in OCI20%
- Designing and Evaluating Multicloud and Hybrid Solutions15%
- Migrating Workloads to OCI10%
- Implementing Observability Solutions5%
- 1
A startup is deploying a new SaaS application on OCI using a microservices architecture. They need to implement an Infrastructure as Code (IaC) pipeline. The requirement is to detect if any infrastructure resources have been modified manually in the console (configuration drift) and automatically notify the DevOps team.
Which OCI Resource Manager feature should be scheduled to run periodically to meet this requirement?
Show answer details
Correct answer: C
OCI Resource Manager provides a native Drift Detection feature that compares the current state of resources in the tenancy against the state defined in the Terraform state file. This can be scheduled or run on demand to identify manual changes.
- 2
You are designing the network topology for an Oracle Cloud VMware Solution (OCVS) SDDC. The requirement is to allow the VMware workloads (overlay network) to communicate with the OCI native services (like Object Storage) and on-premises networks.
Which OCVS component acts as the bridge between the VMware NSX-T overlay network and the OCI VCN underlay network?
Show answer details
Correct answer: C
In OCVS, the NSX-T Edge nodes have uplinks that map to specific OCI VLANs (Uplink VLANs). These VLANs facilitate the routing of traffic from the NSX-T overlay segments out to the OCI VCN and beyond (NAT Gateway, DRG, etc.).
- 3
A large e-commerce retailer wants to migrate their on-premises Oracle Database to OCI. They cannot afford any significant downtime during the migration. They have chosen Oracle Zero Downtime Migration (ZDM).
Which ZDM migration method should be selected to allow for continuous data replication during the migration process until the final switchover?
Show answer details
Correct answer: A
Physical Online Migration uses Oracle Data Guard. It instantiates a standby database in OCI and keeps it synchronized with the primary on-premises database via redo transport. Switchover involves minimal downtime (seconds/minutes), meeting the requirement.
- 4
You are implementing OCI Network Firewall to secure traffic between a Web subnet and a Database subnet. You want to block any traffic that matches known malware signatures or botnet command-and-control patterns, regardless of the port used.
Which Network Firewall policy component is specifically designed to handle this deep packet inspection requirement?
Show answer details
Correct answer: D
The IDPS profile in OCI Network Firewall performs deep packet inspection to identify and block threat signatures, such as malware and botnet activity, which standard 5-tuple ACLs cannot detect.
- 5
You are designing a multicloud solution where the application frontend runs on AWS EC2 and the backend database is an Oracle Autonomous Database on OCI. You have configured a VPN connection between AWS VPC and OCI VCN. However, you are experiencing high latency and connection drops.
Which architecture change would provide the MOST stable, low-latency, and high-bandwidth connection for this production workload?
Show answer details
Correct answer: C
Using dedicated circuits (FastConnect + Direct Connect) avoids the public internet completely, providing consistent low latency, high bandwidth, and SLA-backed reliability, which is superior to VPN.
- 6
A global retail enterprise is designing a cloud-native e-commerce platform on Oracle Cloud Infrastructure (OCI). The application utilizes microservices deployed on Oracle Container Engine for Kubernetes (OKE). The architecture requires that pods have direct visibility of the client source IP addresses for geo-fencing and audit logging purposes without using
X-Forwarded-Forheaders. The solution must also support mixed-protocol traffic (TCP and UDP) on the same load balancer IP. Which OCI Load Balancer configuration meets these strict networking requirements?Show answer details
Correct answer: D
The OCI Network Load Balancer (NLB) operates at Layer 4 and is non-proxying by design, which inherently preserves the client source IP address when traffic is forwarded to the backend. It also supports both TCP and UDP protocols. Setting
externalTrafficPolicy: Localon the Kubernetes Service ensures that traffic is only routed to nodes running the specific pod, preventing SNAT (Source Network Address Translation) that would obscure the source IP. - 7
You are the lead architect for a financial institution migrating a legacy high-frequency trading application to OCI. The application requires a database with single-digit millisecond latency, automated failover with zero data loss (RPO=0), and the ability to scale CPU resources up to 3x during market opening hours automatically. Which database solution and configuration should you select?
Show answer details
Correct answer: C
ATP on Shared Infrastructure provides the required performance. Auto Scaling allows the CPU count to scale up to 3x the base count automatically based on workload. Autonomous Data Guard in the same region (synchronous replication) ensures RPO=0 and automated failover for high availability.
- 8
A multinational corporation is implementing a hub-and-spoke network topology in OCI. They require a centralized inspection point for all North-South (Internet) and East-West (Spoke-to-Spoke) traffic. They have chosen OCI Network Firewall for this purpose. You need to configure the routing to ensure traffic flows correctly through the firewall in the Hub VCN.
Which THREE routing configurations are required to achieve this? (Select THREE)
Show answer details
Correct answer: C, D, E
Traffic leaving the Spoke must be directed to the Hub VCN via the DRG attachment to reach the firewall.
When traffic arrives at the Hub VCN from a Spoke (via DRG), the VCN Ingress Route Table intercepts it and forwards it to the Firewall's private IP for inspection before it can be routed elsewhere.
After the firewall inspects and allows the traffic, the traffic must be routed from the firewall's subnet back to the DRG to reach the destination Spoke VCN.
