1Z0-1067-25 Oracle Cloud Infrastructure 2025 Cloud Ops Professional Practice Questions
Prepare for 1Z0-1067-25 with more than an answer.
- Exam fee
- $245 USD
- Time limit
- 90 minutes
- Questions on the exam
- Not Applicable
- Passing score
- 68% (scale 0-100%)
- Level
- Professional
- Valid for
- 18 months
Domains covered on the exam 6
- Deploying and Managing Resources20%
- Utilizing Configuration Management Tools15%
- Optimizing Cost and Performance20%
- Implementing Reliability and Business Continuity20%
- Managing Identity and Security15%
- Implementing Observability10%
- 1
A Network Load Balancer (NLB) is distributing traffic to a backend set of virtual machine instances. An administrator notices that traffic is still being sent to an instance that has a crashed application process, even though the VM itself is running. The current health check is a TCP check on port 80. What is the most effective way to ensure the NLB marks this instance as unhealthy and stops sending it traffic?
Show answer details
Correct answer: B
A simple TCP check only verifies that the port is open, not that the application serving on that port is healthy. The application process can crash while the underlying OS keeps the port listener active. By switching to an HTTP health check that targets a specific health endpoint (like /health), the load balancer can verify the application's actual state. If the application is down and cannot return a 200 OK status code, the instance will be correctly marked as unhealthy.
- 2
A new team has been onboarded to manage a development project within their own compartment. The tenancy administrator needs to prevent the team from spending more than $500 per month. If the forecast spend reaches 80% of this limit ($400), an alert must be sent to the team's manager. Which TWO OCI features must be configured to enforce this policy? (Select TWO)
Show answer details
Correct answer: A, C
Budgets are used to track spending against a set limit. Creating a budget scoped to the specific development compartment with a $500 monthly limit is the correct way to monitor their expenditure.
Within the Budget service, you can configure Alert Rules. Setting an alert to trigger when the forecast spend reaches 80% of the budget amount will meet the requirement to notify the manager proactively.
- 3
A gaming company is deploying a new multiplayer game server on OCI. The server architecture requires a backend that can handle millions of long-lived, non-HTTP connections from game clients. The primary requirement is extremely low latency and high throughput at Layer 4 (TCP/UDP). Source and destination IP preservation is critical for the game's logic. Which OCI load balancing solution is the optimal choice for this workload?
Show answer details
Correct answer: B
The Network Load Balancer (NLB) is specifically designed for high-performance, low-latency Layer 4 (TCP/UDP) traffic. It operates in a pass-through mode, preserving the source and destination IP addresses, which is a key requirement. Its non-proxy architecture makes it ideal for long-lived connections and latency-sensitive applications like gaming servers.
- 4
A Cloud Ops engineer is troubleshooting a networking issue where a compute instance in a private subnet cannot reach the internet to download software patches. The VCN has a NAT Gateway and a Service Gateway. The route table for the private subnet has the following rules:
- Destination: 0.0.0.0/0, Target: NAT Gateway
- Destination: OCI Services Network, Target: Service Gateway
The security list for the private subnet allows all egress traffic. What is the most likely cause of the issue?
Show answer details
Correct answer: D
For a NAT Gateway to function, it must reside in a public subnet and have a route to the internet via an Internet Gateway. The private subnet correctly routes internet-bound traffic (0.0.0.0/0) to the NAT Gateway. However, the NAT Gateway itself must then be able to route that traffic out to the internet. This requires a rule in the public subnet's route table with destination 0.0.0.0/0 and the target set to the Internet Gateway. The absence of this rule is the most common cause of this issue.
- 5
A new team has been onboarded to manage a development project within its own compartment. They require full control over their compute, block storage, and VCN resources. However, to maintain tenancy security posture, they must be prevented from modifying any IAM policies, users, or groups. Which TWO IAM policy statements, when combined, would satisfy these requirements according to the principle of least privilege? (Select TWO)
graph TD Admin[Tenancy Admin] -->|Manages| IAM[IAM Policies] IAM -->|Deny| DevTeam[Dev Team Group] Admin -->|Grants| DevTeam DevTeam -->|Allow| ManageResources[Manage Compute, VCN, Storage] subgraph DevCompartment [Development Compartment] ManageResources endShow answer details
Correct answer: B, C
- 6
A financial services company is using OCI Resource Manager to deploy a complex, multi-VCN architecture. The lead DevOps engineer needs to ensure that sensitive outputs, such as a database administrator's initial password, are not displayed in the stack's log files or stored in the state file in plain text. Which Terraform language feature should be used in the configuration to achieve this?
Show answer details
Correct answer: B
The correct way to prevent a Terraform output value from being displayed in logs is to mark it as sensitive. By setting the
sensitive = trueargument in the output block, Terraform will redact the value from CLI output. OCI Resource Manager respects this flag and will also hide the value in its logs and state file displays, providing the necessary security for sensitive information. - 7
An operations team is managing a large fleet of compute instances across several compartments. They need to retrieve a list of all instances that are tagged with
"environment"="production"but only display their OCID, display name, and lifecycle state. Which OCI CLI command correctly accomplishes this using a JMESPath query?Show answer details
Correct answer: D
This command correctly queries for instances across all sub-compartments of the root tenancy compartment (
-c --compartment-id-in-subtree true). The JMESPath query then filters this list ([?"freeform-tags".environment==production]) for instances with the specified freeform tag. Finally, it projects (.{...}) the results to show only the OCID (id:id), display name (name:"display-name"), and lifecycle state (state:"lifecycle-state"). - 8
A cloud engineer is writing an Ansible playbook to automate the patching of a fleet of Oracle Linux instances in OCI. The playbook needs to connect to the instances, apply the latest security patches using
yum, and then reboot the instance only if a kernel update was applied. Which TWO Ansible modules are essential for this task? (Select TWO)Show answer details
Correct answer: A, B
The
ansible.builtin.yummodule is used to manage packages with the yum package manager on Red Hat-based systems like Oracle Linux. It can be used to install, update, or remove packages, and is the correct module for applying security patches.The
ansible.builtin.rebootmodule is specifically designed to reboot a machine and wait for it to come back up. This is essential for applying kernel updates, and it can be used conditionally based on the result of the yum update task. - 9
A startup is deploying a new application on OCI compute instances and wants to automate the installation of their monitoring agent and the configuration of the firewall upon first boot. The configuration steps are identical for all instances and are defined in a shell script stored in an OCI Object Storage bucket. What is the most efficient method to execute this script using cloud-init?
Show answer details
Correct answer: A
This is the most efficient and secure method. A pre-authenticated request (PAR) provides a temporary, secure URL to access the script without needing to configure complex IAM policies or credentials on the instance. The cloud-init user data can then contain a simple
runcmdthat downloads the script viacurland pipes it to a shell for execution, fully automating the process. - 10
A media company is experiencing significant cost overruns in their OCI tenancy, primarily related to Object Storage. The finance department wants to understand which specific department, identified by a cost-tracking tag named
Department, is responsible for the majority of storage costs over the last quarter. How can a Cloud Ops professional generate this report using the Cost Analysis tool?Show answer details
Correct answer: C
The Cost Analysis tool allows for powerful filtering and grouping. To solve this, the professional must first set the correct time frame (last 90 days/quarter). Then, they must filter the results to only include the relevant service (Object Storage). Finally, to break down the costs by department, they must use the
Group byfeature and select the specific cost-tracking tag key (Department). This will produce a report showing the Object Storage costs attributed to each department tag value.
