1Z0-1072-25 OCI 2025 Architect Associate Practice Questions
Prepare for 1Z0-1072-25 with more than an answer.
Unlock the full exam and previous versions
- v1OCI 2025 Architect Associate 235 questions Current
- 1z0-1072-20Legacy OCI 2020 Architect Associate 60 questions Locked
- 1Z0-1072-23Legacy OCI 2023 Architect Associate 207 questions Locked
- Exam fee
- $245 USD
- Level
- Associate
- Valid for
- Ongoing - subject to Cloud Recertification policy
Domains covered on the exam 4
- Compute20%
- Networking35%
- Storage25%
- Identity and Access Management20%
- 1
A network engineer is troubleshooting a connectivity issue between a web server in a public subnet and a database server in a private subnet within the same VCN. The engineer uses the Network Path Analyzer to test the connection. The analysis fails. Which of the following are potential root causes that the Network Path Analyzer would identify? (Select THREE)
Show answer details
Correct answer: A, C, D
If the route table associated with the public subnet doesn't have a rule to direct traffic to the private subnet's CIDR block, the packets will be dropped. Network Path Analyzer checks route tables along the path.
Network Path Analyzer inspects both Security Lists and Network Security Groups. If the database subnet's security list blocks incoming traffic from the web server's source CIDR on the database port, the path analysis will report a failure.
Similar to security lists, if an NSG is applied to the database server's VNIC and it doesn't have a rule to permit the traffic, the connection will be blocked, and Network Path Analyzer will identify this as the point of failure.
- 2
A company has deployed a critical application using an instance pool. To handle variable traffic, they have configured a metric-based autoscaling policy based on CPU utilization. During a recent high-traffic event, the autoscaling policy failed to add new instances, causing a service degradation. Upon investigation, it was found that the instance pool was at its maximum configured size. Which setting should have been checked and adjusted to prevent this issue?
Show answer details
Correct answer: B
The autoscaling configuration defines the minimum, maximum, and initial number of instances for an instance pool. The autoscaling policy can only add instances up to the specified maximum. If the pool is already at its maximum size, no further scale-out events will occur, regardless of the metric thresholds being met. The maximum number of instances should be set high enough to accommodate peak load.
- 3
Case Study: Global Retail Co.
Global Retail Co. is a multinational corporation planning a major migration of its on-premises e-commerce platform to Oracle Cloud Infrastructure (OCI). The primary goals are to improve scalability, enhance security, and establish a robust disaster recovery (DR) solution between their primary region in US Ashburn (IAD) and a DR region in UK London (LHR).
The current on-premises architecture consists of web servers, application servers, and a large Oracle database. The migrated OCI architecture will use a public load balancer, web application servers in an instance pool with autoscaling, application servers in a separate instance pool, and an Autonomous Transaction Processing (ATP) database. All compute instances will use custom images for standardized configurations. Data includes customer information, product catalogs, and large image files for product listings.
Security is paramount. The company wants to implement a defense-in-depth strategy. All traffic from the internet must be inspected for common web exploits. Communication between the web and application tiers must be strictly controlled. The application servers must be able to securely access other OCI services, like Object Storage, without storing credentials on the instances.
For disaster recovery, the company requires a Recovery Point Objective (RPO) of less than 15 minutes for their block storage and database. The large product image files, stored in Object Storage, must also be replicated to the DR region. The failover process should be as automated as possible, leveraging DNS to redirect traffic to the London region if Ashburn becomes unavailable.
Based on the case study, which combination of services provides the most effective defense-in-depth security for the web tier?
graph TD subgraph "OCI Region: US Ashburn (Primary)" Internet([Internet]) --> WAF[Web Application Firewall] WAF --> PubLB[Public Load Balancer] PubLB --> WebPool[Web Tier Instance Pool] WebPool --> AppPool[App Tier Instance Pool] AppPool --> ATP[Autonomous DB] AppPool --> OS[Object Storage] endShow answer details
Correct answer: C
This option provides a comprehensive defense-in-depth strategy. The WAF inspects incoming traffic at Layer 7 for exploits. The Public Load Balancer terminates SSL and distributes traffic. The Security List provides a broad, subnet-level firewall. The NSG adds a granular, VNIC-level firewall specifically for the web tier, allowing for more precise control over traffic between tiers. This layered approach best meets the stringent security requirements.
- 4
Case Study: Global Retail Co.
Global Retail Co. is a multinational corporation planning a major migration of its on-premises e-commerce platform to Oracle Cloud Infrastructure (OCI). The primary goals are to improve scalability, enhance security, and establish a robust disaster recovery (DR) solution between their primary region in US Ashburn (IAD) and a DR region in UK London (LHR).
The current on-premises architecture consists of web servers, application servers, and a large Oracle database. The migrated OCI architecture will use a public load balancer, web application servers in an instance pool with autoscaling, application servers in a separate instance pool, and an Autonomous Transaction Processing (ATP) database. All compute instances will use custom images for standardized configurations. Data includes customer information, product catalogs, and large image files for product listings.
Security is paramount. The company wants to implement a defense-in-depth strategy. All traffic from the internet must be inspected for common web exploits. Communication between the web and application tiers must be strictly controlled. The application servers must be able to securely access other OCI services, like Object Storage, without storing credentials on the instances.
For disaster recovery, the company requires a Recovery Point Objective (RPO) of less than 15 minutes for their block storage and database. The large product image files, stored in Object Storage, must also be replicated to the DR region. The failover process should be as automated as possible, leveraging DNS to redirect traffic to the London region if Ashburn becomes unavailable.
To meet the disaster recovery requirements for the application server's boot volumes and the product image files, which two replication methods should be implemented?
Show answer details
Correct answer: B
OCI provides native cross-region replication features for both Block Volume and Object Storage. Block Volume cross-region replication can achieve an RPO of less than an hour (and often better), meeting the requirement. Object Storage cross-region replication asynchronously copies objects to a bucket in another region, satisfying the need to replicate the product images. These are the direct, managed solutions for the specified data types.
- 5
You are designing a solution that requires uploading very large files (over 100 GB) to an OCI Object Storage bucket. To improve performance and reliability, you decide to use multipart uploads. Which statement accurately describes a key benefit of using multipart uploads?
Show answer details
Correct answer: B
A primary benefit of multipart uploads is the ability to upload object parts independently and in parallel. This can significantly improve throughput compared to uploading the entire object in a single stream, especially for large files and high-bandwidth networks. It also provides resilience, as a failure of one part's upload only requires re-uploading that part, not the entire object.
- 6
A system administrator needs to connect to a compute instance in a private subnet for troubleshooting. There is no VPN or FastConnect to the VCN, and the company security policy prohibits bastion hosts. Which OCI service provides secure, temporary, and audited shell access to the instance without requiring a public IP or a bastion?
Show answer details
Correct answer: B
The OCI Bastion service is a fully managed service that provides secure and ephemeral access to private resources. It creates a session that allows an administrator to connect to a private instance via SSH without exposing the instance to the public internet or requiring the setup and maintenance of a separate bastion host. All sessions are time-limited and can be audited, meeting the security requirements.
- 7
When comparing an OCI Load Balancer and a Network Load Balancer (NLB), what is a key capability of the Load Balancer that is NOT available with the NLB?
Show answer details
Correct answer: D
The key differentiator is the OSI layer at which they operate. The Load Balancer operates at Layer 7 (Application) and can inspect HTTP/HTTPS traffic. This allows it to perform advanced functions like SSL/TLS termination, cookie-based session persistence, and URL-based routing. The Network Load Balancer operates at Layer 4 (Transport) and makes routing decisions based on IP address and port, without visibility into the application-level data. Therefore, it cannot terminate SSL.
- 8
A financial services company is architecting a highly available application on OCI. The application tier runs on a set of compute instances within a private subnet and must communicate with an Autonomous Transaction Processing (ATP) database. To ensure secure and private communication, the network architect has decided to use a Service Gateway. Which of the following IAM policies is required to allow instances in the VCN to make calls to the Oracle Services Network?
Show answer details
Correct answer: B
A Service Gateway provides a private connection path to supported Oracle services within the same region. However, connectivity is controlled by routing, not IAM policies. The essential configuration step is to add a route rule to the private subnet's route table that directs traffic destined for the Oracle Services Network (represented by a service CIDR label like 'All Services in Oracle Services Network') to the Service Gateway. IAM policies control what actions a principal can perform on resources, not the network path itself.
- 9
A media company uses OCI Object Storage to store large video files. To optimize costs, they have implemented a lifecycle policy to transition objects from the Standard tier to Infrequent Access after 30 days, and then to Archive after 90 days. An editor reports they are unable to access a 6-month-old video file directly via the standard S3-compatible API. What is the most likely reason for this issue?
Show answer details
Correct answer: C
Objects stored in the Archive tier are offline and cannot be accessed directly. They must first be restored, which makes a temporary copy available in the Standard tier for a specified duration. The lifecycle policy moved the 6-month-old file to the Archive tier after 90 days. The inability to access it directly is expected behavior for objects in this tier. The user must initiate a restore operation before they can download the object.
- 10
As a cloud architect, you are designing a secure environment for a new project. You need to ensure that a group of developers can only manage OCI resources (e.g., launch instances, create block volumes) if they are connected to the corporate network. Which combination of IAM features should you use to enforce this requirement? (Select TWO)
Show answer details
Correct answer: B, C
Network Sources allow you to define a set of allowed IP addresses, such as the public IP range of a corporate network. This is the first required component.
An IAM policy is needed to grant permissions. To enforce the location constraint, you must add a 'where' clause to the policy that references the created Network Source (e.g., 'where request.networkSource.name = 'corp_network'').
