1Z0-1109-25 Oracle Cloud Infrastructure 2025 DevOps Professional Practice Questions
Prepare for 1Z0-1109-25 with more than an answer.
- Exam fee
- $245 USD
- Level
- Professional
- Valid for
- Cloud Recertification Policy applies
Domains covered on the exam 6
- Understand DevOps principles and effectively work with containerization services15%
- Using Code and Templates for Provisioning and Configuring Infrastructure10%
- Configuring and Managing Continuous Integration and Continuous Delivery (CI/CD)30%
- Managing Containers using Container Orchestration Engine30%
- Enabling DevSecOps10%
- Implementing Monitoring and Observability (O&M)5%
- 1
A global retail company is building a new e-commerce platform using a microservices architecture. They plan to host this on Oracle Cloud Infrastructure. The key requirements are high availability across multiple geographic regions, independent scalability for each service, and technology stack flexibility for different development teams.
To meet these requirements, the architecture team has decided on a container-based approach. Each microservice will be packaged as a Docker container. They will use OCI DevOps services for their CI/CD pipelines, storing container images in Oracle Cloud Infrastructure Registry (OCIR). For orchestration, they will use managed Kubernetes clusters.
The main challenge is ensuring that application deployments are consistent across all environments (development, staging, production) and that the infrastructure itself can be version-controlled and replicated easily. The operations team is small, so they need a solution that minimizes manual configuration and allows them to manage the entire application lifecycle, from infrastructure to application code, declaratively.
Given these requirements, which approach provides the most comprehensive and declarative solution for managing both the OCI infrastructure and the Kubernetes application deployments?
Show answer details
Correct answer: C
This approach addresses all requirements comprehensively. OCI Resource Manager with Terraform provides a declarative, version-controllable method for provisioning the entire infrastructure (VCN, OKE clusters, etc.), ensuring consistency and repeatability. Helm charts are the industry standard for packaging and managing Kubernetes applications, allowing for templating, versioning, and dependency management. Integrating Helm deployments into an OCI DevOps pipeline automates the application lifecycle on the provisioned infrastructure, creating a full-stack, declarative solution.
- 2
A developer needs to connect to a private OKE cluster's Kubernetes API endpoint from their local machine for troubleshooting. The cluster does not have a public IP address, and corporate policy prohibits exposing it to the internet. Which OCI service provides the most secure and straightforward method to establish this connection?
Show answer details
Correct answer: B
OCI Bastion is a fully managed service that provides secure access to private resources. For accessing a private Kubernetes API endpoint, the 'Port Forwarding' session type is ideal. It creates a secure tunnel from the developer's local machine to the Bastion service, which then forwards the connection to the specified private IP and port of the OKE API endpoint. This allows the developer to configure their
kubeconfigto point tolocalhoston the forwarded port, enablingkubectlcommands to work seamlessly and securely without exposing the cluster. - 3
Which OCI DevOps Artifact type should be used to represent a collection of Kubernetes manifests that will be deployed to an OKE cluster using a 'Deploy to OKE' pipeline stage?
Show answer details
Correct answer: C
The OCI DevOps service has a specific artifact type named 'Kubernetes manifest'. This type is designed to point to a YAML file or a directory of YAML files (packaged as a .zip or .tar.gz) stored in the OCI Artifact Registry. When configuring a 'Deploy to OKE' stage in a deployment pipeline, you select an artifact of this type, and the pipeline will use its contents to execute a
kubectl applyagainst the target cluster. - 4
A DevOps engineer is troubleshooting a failing OCI build pipeline. The logs for a 'Managed Build' stage indicate a 'permission denied' error when the build script tries to write to a temporary directory. The build is running as a non-root user inside the container. What is the most likely cause of this issue in the
build_spec.yamlconfiguration?Show answer details
Correct answer: C
OCI Managed Build runners execute commands within a specific working directory, typically
/workspace/. The non-root user running the build has write permissions within this directory. A 'permission denied' error during file operations strongly suggests the script is trying to write to a system-level directory (e.g.,/tmp,/opt) where the user does not have the necessary permissions. The solution is to ensure all temporary files and build outputs are written to paths relative to the working directory. - 5
An organization wants to mirror a GitHub repository to an OCI DevOps Code Repository to trigger OCI-native build pipelines. They need to ensure that pushes to the main branch in GitHub are automatically reflected in the OCI repository. Which feature of OCI DevOps Code Repositories should they configure?
Show answer details
Correct answer: B
OCI DevOps Code Repositories have a built-in 'Mirroring' feature that allows them to automatically sync with an external Git repository, such as one on GitHub or Bitbucket. By configuring the OCI repository as a mirror of the GitHub repository, any commits pushed to the source (GitHub) will be automatically fetched and updated in the OCI mirror, enabling the use of OCI-native CI/CD triggers and workflows.
- 6
A team is managing their infrastructure with Terraform and OCI Resource Manager. They have a production stack that was applied successfully. A team member, trying to fix an issue, makes a direct change to a network security group using the OCI Console. Which OCI Resource Manager feature should be used to detect this manual change and report the discrepancy?
Show answer details
Correct answer: B
The 'Drift Detection' feature in OCI Resource Manager is specifically designed for this purpose. It compares the current state of the resources defined in the stack's Terraform configuration with the actual deployed resources in OCI. It then generates a report detailing any discrepancies (or 'drift'), such as the manual change made to the network security group via the console. This allows teams to identify and remediate out-of-band changes to maintain the integrity of their Infrastructure as Code.
- 7
A media company uses OKE to run a video processing application. Certain processing tasks are computationally intensive and perform best on nodes with GPUs. To ensure these specific tasks are scheduled only on GPU-enabled worker nodes, what Kubernetes scheduling features should be used?
Below is a diagram illustrating the desired scheduling logic.
graph TD subgraph OKE_Cluster subgraph GPU_NodePool GPU_Node1[Node (Taint: gpu=true:NoSchedule)] GPU_Node2[Node (Taint: gpu=true:NoSchedule)] end subgraph CPU_NodePool CPU_Node1[Node] CPU_Node2[Node] end end VideoPod[Video Processing Pod (Toleration: gpu=true:NoSchedule NodeSelector: feature=gpu)] -->|Scheduled Onto| GPU_Node1 WebAppPod[Web App Pod] -->|Cannot Schedule| GPU_Node1 WebAppPod -->|Scheduled Onto| CPU_Node2Show answer details
Correct answer: B
This combination provides a complete solution.
- Taints are applied to the GPU nodes (e.g.,
gpu=true:NoSchedule). This prevents any pod without a matching toleration from being scheduled there. - Tolerations are added to the video processing pods, allowing them to be scheduled on the tainted GPU nodes.
- Node Selector or Node Affinity is added to the video processing pods to explicitly request scheduling on nodes with a specific label (e.g., a label indicating they have a GPU). This ensures they are not just allowed on GPU nodes but are actively scheduled there. This two-part mechanism both reserves the specialized nodes and directs the appropriate workloads to them.
- Taints are applied to the GPU nodes (e.g.,
- 8
A financial services company is implementing a blue-green deployment strategy for a critical, stateful microservice running on an OKE cluster. The deployment pipeline must ensure zero downtime and provide an immediate rollback capability if post-deployment health checks fail. The current process involves manually updating a Kubernetes service selector to switch traffic. Which OCI DevOps Deployment Pipeline stage configuration is the most effective and automated way to manage the traffic shift between the blue and green environments?
Show answer details
Correct answer: D
The OCI DevOps Deployment Pipeline includes a dedicated 'Traffic Shift' stage for managing blue-green and canary deployments on OKE. This stage is the most effective and automated method as it natively handles the controlled redirection of traffic between backend sets (representing the blue and green deployments) associated with a Kubernetes Service of type LoadBalancer. It provides fine-grained control and integrates seamlessly with validation and rollback stages. Using shell scripts or CLI commands introduces manual scripting overhead and is less robust than the purpose-built stage. Redeploying the service manifest is a valid but less controlled approach compared to the Traffic Shift stage.
- 9
A DevOps team is managing a large-scale microservices application on OKE. They are experiencing intermittent latency issues and need to trace requests as they propagate across multiple services. To achieve this, they decide to implement a service mesh. Which of the following are primary benefits of integrating OCI Service Mesh into their OKE cluster? (Select TWO)
Show answer details
Correct answer: B, C
OCI Service Mesh provides deep observability into traffic between microservices. It automatically collects metrics, logs, and distributed traces, allowing teams to monitor and debug communication without instrumenting the application code itself.
A core feature of OCI Service Mesh is enhancing security by automatically encrypting all traffic between services within the mesh using mutual TLS (mTLS). This enforces a zero-trust security model at the network layer.
- 10
A DevOps engineer is configuring an OCI build pipeline that requires access to a private Maven repository hosted on-premises. The on-premises network is connected to the OCI VCN via FastConnect. To ensure the build process can resolve dependencies securely without traversing the public internet, what is the recommended approach for the build runner?
Show answer details
Correct answer: B
For secure access to on-premises resources, the correct approach is to use a private build runner. This runner, hosted on an OCI compute instance within your VCN, can leverage the existing FastConnect circuit. By placing it in a private subnet with appropriate route table entries pointing to the DRG, it can communicate directly and securely with the on-premises Maven repository without any public internet exposure. Oracle-managed runners operate outside your VCN and cannot access private on-premises endpoints.
