1Z0-1072-23 Sample Questions

1Z0-1072-23 Sample Questions & Answers

Centers on virtual cloud networks, their connectivity and DNS traffic steering, well ahead of the rest, plus block, object and file storage choices, identity and access management, and scaling compute instances along with their images.

Launch the full 1Z0-1072-23 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Identity and Access Management · Create and manage IAM domains, users, groups, and compartments

    During a routine audit, it was discovered that a developer inadvertently launched a large number of high-cost GPU compute instances in a development compartment, leading to a significant budget overrun. To prevent this from recurring, the cloud administrator needs to implement a control that automatically prevents the creation of resources that would exceed a predefined budget for that compartment. Which OCI feature should be used?

    Show answer & explanation

    Correct answer: C

    Compartment Quotas are specifically designed to control resource consumption. By setting a quota on the number of GPU instances (or a specific shape) within the 'development' compartment, you can prevent users from creating resources beyond that limit. This is a preventative control, whereas Budgets with alerts are a detective control (they notify you after the spend has occurred or is forecasted to occur).

  2. Question 2Beginner

    Networking · Configure Virtual Cloud Network Routing and Gateways

    True or False: When using an OCI NAT Gateway in a public subnet, you must also add a route rule to the private subnet's route table that directs traffic destined for the internet to the NAT Gateway.

    Show answer & explanation

    Correct answer: A

    This statement is true. A NAT Gateway allows instances in a private subnet to initiate outbound connections to the internet but prevents inbound connections. For this to work, the route table associated with the private subnet must have a rule with a destination of 0.0.0.0/0 and the target set to the NAT Gateway.

  3. Question 3Intermediate

    Compute · Configure Autoscaling

    An architect is tasked with designing a highly available and fault-tolerant compute architecture. The application requires that if an entire Availability Domain (AD) fails, the application remains operational with minimal performance degradation. The application servers are stateless. What is the most cost-effective and resilient OCI compute configuration to achieve this?

    Show answer & explanation

    Correct answer: C

    This is the most effective solution. A single instance pool can be configured to span multiple ADs. This ensures that instances are automatically distributed for high availability. When combined with an autoscaling policy, if one AD fails and its instances become unhealthy, the autoscaling service will automatically launch new instances in the remaining healthy ADs to maintain the desired capacity, ensuring resilience and consistent performance.

  4. Question 4Intermediate

    Storage · Implement Object Storage versioning, life cycle management and retention rules

    A media company stores large video files in an OCI Object Storage Standard tier bucket for processing. After 30 days, these files are accessed infrequently but must be available for retrieval within two hours. After 180 days, they are rarely accessed and can tolerate a retrieval time of up to four hours. To optimize storage costs, what is the correct lifecycle policy configuration?

    Show answer & explanation

    Correct answer: C

    This configuration correctly maps the requirements to OCI's storage tiers. The Infrequent Access tier is for data accessed less often but requires rapid retrieval (milliseconds to seconds), fitting the 30-day requirement. Archive Storage is for long-term retention with longer retrieval times (a few hours), fitting the 180-day requirement. The policy should move to Infrequent Access after 30 days, and then to Archive after a total of 180 days (30 + 150).

  5. Question 5Intermediate

    Networking · Configure Virtual Cloud Network Routing and Gateways

    You are troubleshooting a connectivity issue between a compute instance in a private subnet and the OCI Object Storage service endpoint. The instance needs to upload backup files. You have confirmed that the instance has the correct IAM permissions. A Service Gateway is attached to the VCN, and the private subnet's security list allows all egress traffic. What is the most likely missing configuration piece?

    Show answer & explanation

    Correct answer: A

    A Service Gateway provides a private path to OCI services, but it requires a corresponding route rule. The route table associated with the private subnet must have a rule that specifies the target as the Service Gateway and the destination as 'All Services in Oracle Services Network' (which includes Object Storage). Without this rule, the instance does not know how to route the traffic to the service endpoint over the private OCI backbone.

  6. Question 6Advanced

    Identity and Access Management · Configure Dynamic Groups, Network Sources, and Tag-Based Access Control

    A new DevOps team has been created to manage a specific project. The team members need to be able to launch and manage compute instances, but only if the instances are tagged with the project's cost center tag CostCenter: 'ProjectX'. They should not be able to perform any action on instances without this specific tag. Which IAM feature is required to implement this level of granular control?

    Show answer & explanation

    Correct answer: C

    This requirement is a classic use case for tag-based access control, which is implemented using conditions within an IAM policy. A policy can be written to Allow group DevOpsTeam to manage instance-family where target.resource.tag.CostCenter = 'ProjectX'. This condition ensures the policy only applies to actions where the target resource (the instance) has the specified tag.

  7. Question 7Intermediate

    Compute · Configure compute instances

    An administrator needs to perform urgent maintenance on a production compute instance. They need to connect to the instance's serial console to troubleshoot a boot issue, but the instance has no public IP address and is in a private subnet. Which OCI feature provides secure, temporary access to the serial console without exposing the instance to the public internet?

    Show answer & explanation

    Correct answer: B

    The Instance Console Connection feature is designed specifically for this purpose. It provides a secure, web-based VNC or serial console connection directly to the instance from the OCI Console. This works for instances in private subnets and does not require a public IP, bastion host, or any changes to the VCN's security rules.

  8. Question 8Intermediate

    Storage · Deploy and manage Block Storage

    A hospital is migrating its patient record system to OCI. Due to regulatory compliance (e.g., HIPAA), all block volume data must be encrypted with a customer-managed encryption key, not an Oracle-managed key. The hospital's security team must have full control over the key's lifecycle, including rotation and revocation. Which OCI service must be used in conjunction with the Block Volume service to meet this requirement?

    Show answer & explanation

    Correct answer: B

    OCI Vault provides the Key Management Service (KMS) that allows customers to create and manage their own encryption keys. When creating a block volume, you can specify a custom master encryption key from a Vault that you control. This gives you full authority over the key's lifecycle, satisfying strict compliance requirements for customer-managed encryption.

  9. Question 9Advanced

    Networking · Implement transit routing scenarios

    Your company has a hub-and-spoke network topology in OCI. The hub VCN is connected to your on-premises data center via FastConnect. Several spoke VCNs are peered with the hub VCN using Local Peering Gateways (LPGs). The spoke VCNs need to communicate with the on-premises network. What networking component is essential for enabling this traffic flow?

    Show answer & explanation

    Correct answer: B

    This scenario describes a classic use case for transit routing. By default, VCN peering is not transitive. To allow spokes to communicate with the on-premises network through the hub, you must use a Dynamic Routing Gateway (DRG) in the hub. The DRG acts as the central router, and you must configure its route tables to direct traffic between the FastConnect connection, the hub VCN, and the peered spoke VCNs.

  10. Question 10Intermediate

    Compute · Describe OCI compute image options

    A company wants to migrate a virtualized, on-premises Oracle Linux server to OCI. The server is running on VMware and has a custom kernel and specific drivers not present in the standard Oracle-provided images. What is the correct launch mode to select when importing this custom image to ensure it boots and operates correctly in OCI?

    Show answer & explanation

    Correct answer: C

    Emulated mode is the correct choice for images that require legacy drivers or have custom kernel configurations that are not compatible with OCI's native paravirtualized drivers. Emulation provides a more traditional virtual hardware environment, which increases compatibility for older or highly customized operating systems, even though it may come with a slight performance penalty compared to paravirtualized mode.

Ready for the real thing?

The full 1Z0-1072-23 simulator has every exam-style question, timed mode, and instant scoring.