Your customer is using an Oracle Cloud Infrastructure (OCI) compartment named Production that hosts several resources such as compute instances, DB Systems and File Systems. Each resource in the Production compartment is tagged.
The customer's security team wants to restrict access to DB Systems to only the authorized group of DBAs. Which OCI Tagging capability can be used to meet this requirement?

  • A. Tags Defaults with predefined values
  • B. Tag Defaults
  • C. Cost-Tracking Tags
  • D. Tag-based Access Control

Answer: D

Reference: https://docs.cloud.oracle.com/en-us/iaas/Content/Tagging/Tasks/managingaccesswithtags.htm#about


You are designing a networking infrastructure in multiple Oracle Cloud Infrastructure regions and require connectivity between workloads in each region. You have created a dynamic routing gateway (DRG) and a remote peering connection. However, your workloads are unable to communicate with each other.
What are two reasons for this? (Choose two.)

  • A. The security lists associated with subnets in each virtual cloud network (VCN) do not have the appropriate ingress rules
  • B. Identity and Access Management (IAM) policies have not been defined to allow connectivity across the two VCNs in different regions
  • C. A local peering gateway needs to be created in each VCN with a default route rule added in the route table forwarding the traffic to the local peering gateway
  • D. An Internet gateway needs to be created in each VCN with a default route rule added in the route table forwarding the traffic to the Internet Gateway
  • E. The route table associated with subnets in each VCN do not have a route rule defined to forward the traffic to their respective DRGs

Answer: AE

Setting Up a Remote Peering
Create the RPCs: Each VCN administrator creates an RPC for their own VCN's DRG. Share information: The administrators share the basic required information.
Set up the required IAM policies for the connection: The administrators set up IAM policies to enable the connection to be established.
Establish the connection: The requestor connects the two RPCs (see Important Remote Peering Concepts the definition of the requestor and acceptor).
Update route tables: Each administrator updates their VCN's route tables to enable traffic between the peered VCNs as desired.
Update security rules: Each administrator updates their VCN's security rules to enable traffic between the peered VCNs as desired.


You are running a mission-critical database application in Oracle Cloud Infrastructure (OCI). You take regular backups of your DB system to OCI object storage. Recently, you notice a failed database backup status in the console.
What step can you take to determine the cause of the backup failure?

  • A. Ensure that your database host can connect to OCI object storage.
  • B. Ensure the database archiving mode is set to NOARCHIVELOG.
  • C. Make sure that the database is not active and running while the backup is in progress.
  • D. Don't restart the dcsagent program even if it has a status of stop/waiting.

Answer: A

Database backups can fail for various reasons. Typically, a backup fails because either the database host cannot access the object store, or there are problems on the host or with the database configuration.
First need to determining the Problem
In the Console, a failed database backup either displays a status of Failed or hangs in the Backup in Progress or Creating state. If the error message does not contain enough information to point you to a solution, you can use the database CLI and log files to gather more data. Then, refer to the applicable section in this topic for a solution.
Database Service Agent Issues
Your Oracle Cloud Infrastructure Database makes use of an agent framework to allow you to manage your database through the cloud platform. Occasionally you might need to restart the dcsagent program if it has the status of stop/waiting to resolve a backup failure.
Object Store Connectivity Issues
Backing up your database to Oracle Cloud Infrastructure Object Storage requires that the host can connect to the applicable Swift endpoint. You can test this connectivity by using a Swift user.
Host Issues
One or more of the following conditions on the database host can cause backups to fail:
- Interactive Commands in the Oracle Profile
- The File System Is Full
- Incorrect Version of the Oracle Database Cloud Backup Module
- Changes to the Site Profile File (glogin.sql)
Database Issues
An improper database state or configuration can lead to failed backups.
- Database Not Running During Backup
- Archiving Mode Set to NOARCHIVELOG (When you provision a new database, the archiving mode is set to ARCHIVELOG by default. This is the required archiving mode for backup operations)
- Stuck Database Archiver Process and Backup Failures
- Temporary Tablespace Errors
- RMAN Configuration and Backup Failures
- RMAN Retention Policy and Backup Failures
- Loss of Objectstore Wallet File and Backup Failures
TDE Wallet and Backup Failures
- Incorrect TDE Wallet Location Specification
- Incorrect State of the TDE Wallet
- Incorrect Configuration Related to the TDE Wallet
- Missing TDE Wallet File
As this is not new provisioned database and already in the ARCHIVELOG , regular backups of DB system to OCI object storage in places, so the best answers are,
- Ensure that your database host can connect to the OCI object storage
- Restart the database service agent


Which service is NOT supported by Oracle Cloud Infrastructure CLI?

  • A. load balancer
  • B. compute
  • C. database
  • D. block volumes

Answer: D

References: https://docs.cloud.oracle.com/iaas/Content/API/Concepts/cliconcepts.htm#services


You have hired a new employee to run reports from the Autonomous Data Warehouse (ADW) and are not confident in their SQL writing ability.
Into which consumer group will you assign this individual to minimize the impact of their code?

  • A. Lowest
  • B. Medium
  • C. Highest
  • D. High
  • E. Low

Answer: E

in ADW, The tnsnames.ora file provided with the credentials zip file contains three database service names identifiable as high, medium, and low. The predefined service names provide different levels of performance and concurrency for Autonomous Data Warehouse.
high: The High database service provides the highest level of resources to each SQL statement resulting in the highest performance, but supports the fewest number of concurrent SQL statements. Any SQL statement in this service can use all the CPU and IO resources in your database. The number of concurrent SQL statements that can be run in this service is 3, this number is independent of the number of OCPUs in your database.
medium: The Medium database service provides a lower level of resources to each SQL statement potentially resulting a lower level of performance, but supports more concurrent SQL statements. Any SQL statement in this service can use multiple CPU and IO resources in your database. The number of concurrent SQL statements that can be run in this service depends on the number of OCPUs in your database.
low: The Low database service provides the least level of resources to each SQL statement, but supports the most number of concurrent SQL statements. Any SQL statement in this service can use a single CPU and multiple IO resources in your database. The number of concurrent SQL statements that can be run in this service can be up to 300 times the number of OCPUs.
The predefined service names provide different levels of performance and concurrency for Autonomous DB Choose whichever database service offers the best balance of performance and concurrency.
Use the low database service name. to minimize the impact of their SQLs to by low consumer group


You have compartments C and D under the root compartment in your Oracle Cloud Infrastructure (OCI) tenancy; compartment C contains a sub-compartment also named D. You are trying to move this
sub-compartment D to the parent compartment D like shown in the picture, but the move fails.
1Z0-1072-20 dumps exhibit
What is the reason for this error?

  • A. You need to move all the compartments in the hierarchy to the new parent compartment.
  • B. You cannot move a subcompartment to another parent compartment.
  • C. Both parent and child compartments cannot have the same name.
  • D. Sub-compartment D needs to be empty before it can be moved.

Answer: C

Reference: https://docs.cloud.oracle.com/en-us/iaas/Content/Identity/Tasks/managingcompartments.htm (restriction on moving compartments)


Which two statements are true about subnets within a VCN? (Choose two.)

  • A. You can have multiple subnets in an Availability Domain for a given VCN.
  • B. Private and Public subnets cannot reside in the same Availability Domain for a given VCN.
  • C. Subnets can have their IP addresses overlap with other subnets in another network for a given VCN.
  • D. Instances obtain their private IP and the associated security list from their subnets.

Answer: AD

References: https://cloud.oracle.com/en_US/bare-metal-network/vcn/faq


Which two statements are true when Oracle Data Guard is configured (using the Console) between two Virtual Machine DB Systems deployed in Oracle Cloud Infrastructure? (Choose two.)

  • A. Primary is a 1-node RAC DB system and Standby is a 2-node RAC DB system.
  • B. Primary is a 2-node RAC DB system and Standby is a 2-node RAC DB system.
  • C. Primary is a 1-node RAC DB system and Standby is a 1-node RAC DB system.
  • D. Primary is a 2-node RAC DB system and Standby is a 1-node RAC DB system.
  • E. Primary is a Bare Metal DB system and Standby is a 1-node RAC DB system.

Answer: AC

Reference: https://docs.cloud.oracle.com/en-us/iaas/Content/Database/Concepts/overview.htm


Which two are Regional resources in Oracle Cloud Infrastructure? (Choose two.)

  • A. Ephemeral public IPs
  • B. Compartments
  • C. Compute images
  • D. Dynamic groups
  • E. Block volume backups

Answer: BD

Reference: https://docs.cloud.oracle.com/en-us/iaas/Content/General/Concepts/regions.htm


A financial firm is designing an application architecture for its online trading platform that must have high availability and fault tolerance.
Their solutions architect configured the application to use an Oracle Cloud Infrastructure Object Storage bucket located in the US West (us-phoenix-1) region to store large amounts of financial data. The stored financial data in the bucket must not be affected even if there is an outage in one of the Availability Domains or a complete region.
What should the architect do to avoid any costly service disruptions and ensure data durability?

  • A. Create a new Object Storage bucket in another region and configure lifecycle policy to move data every 5 days.
  • B. Create a lifecycle policy to regularly send data from Standard to Archive storage.
  • C. Copy the Object Storage bucket to a block volume.
  • D. Create a replication policy to send data to a different bucket in another OCI region.

Answer: A


With regard to Oracle Cloud Infrastructure Load Balancing service, which two actions will occur when a backend server that is registered with a backend set is marked to drain connections?

  • A. All existing connections to this backend sever will be immediately closed.
  • B. Requests to this backend server are redirected to a user-defined error page.
  • C. All new connections to this backend server are disallowed.
  • D. Connections to this backend server will remain open until all in-flight requests are completed.
  • E. All connections to this backend server are forcibly closed after a timeout period.

Answer: CD

Reference: https://docs.cloud.oracle.com/en-us/iaas/Content/Balance/Reference/sessionpersistence.htm


Which DNS resource record type is used to point a host name to an IPv4 address?

  • A. ALIAS
  • B. A
  • C. CNAME
  • D. AAAA

Answer: B

References: https://docs.cloud.oracle.com/iaas/Content/DNS/Reference/supporteddnsresource.htm?tocpath=Services%7CDN


Which two statements are true about policies?

  • A. You can use read, write, manage, and inspect as verbs for defining a policy.
  • B. A policy is a document that specifies who can access which Oracle Cloud Infrastructure resources that your company has, and how.
  • C. Users need not do anything but still have to be added to a group with appropriate policies defined.
  • D. You can deny access to a group via policies.

Answer: BC


As an Oracle Cloud Infrastructure tenancy administrator, you created predefined lists of values and associated them with tag key definitions.
One of the users in your tenancy complains that she cannot see these predefined values. What is causing this issue?

  • A. The user is trying to use free-form tags.
  • B. Some of the predefined values are null.
  • C. The user is not part of an Identity and Access Management group that gives access to tagging.
  • D. The user has breached either the quota or service limit for using tags.

Answer: A

Reference: https://docs.cloud.oracle.com/en-us/iaas/Content/Tagging/Tasks/usingpredefinedvalues.htm


Which two are NOT an image source when launching a new compute instance? (Choose two.)

  • A. boot volume
  • B. custom image
  • C. Object Storage
  • D. bare metal instance

Answer: CD


Which five are the required parameters to launch an instance in Oracle Cloud Infrastructure? (Choose five.)

  • A. subnet
  • B. Availability Domain
  • C. Virtual Cloud Network
  • D. host name
  • E. instance shape
  • F. image operating system
  • G. private IP address

Answer: ABCEF

References: https://docs.cloud.oracle.com/iaas/Content/Compute/Concepts/computeoverview.htm


boot volume for a minimum of 15 days so you have to increase the boot
You have created a virtual cloud network (VCN) with three private subnets. Two of the subnets contain application servers and the third subnet contains a DB System. The application requires a shared file system so you have provisioned one using the file storage service (FSS). You also created the corresponding mount target in one of the application subnets. The VCN security lists are properly configured so that both application servers and the DB System can access the file system. The security team determines that the DB System should have read-only access to the file system.
What change would you make to satisfy this requirement?

  • A. Create an NFS export option that allows READ_ONLY access where the source is the CIDR range of the DB System subnet.
  • B. Connect via SSH to one of the application servers where the file system has been mounte
  • C. Use the Unix command chmod to change permissions on the file system directory, allowing the database user read only access.
  • D. Modify the security list associated with the subnet where the mount target reside
  • E. Change the ingress rules corresponding to the DB System subnet to be stateless.
  • F. Create an instance principal for the DB Syste
  • G. Write an Identity and Access Management (IAM) policy that allows the instance principal read-only access to the file storage service.

Answer: A

NFS export options enable you to create more granular access control than is possible using just security list rules to limit VCN access. You can use NFS export options to specify access levels
blocks connecting to file systems through exports in a mount target.


You are in the process of setting up a highly available student registration website on Oracle Cloud Infrastructure (OCI). You use a load balancer and a database service on OCI. You launch two compute instances each in a different subnet and add them to the back end set of a public load balancer. The load balancer is configured correctly and working. You then deploy the student registration application on these two compute instances. The application can communicate with the database service. However, when you type the URL of this student registration application in your browser, no web page appears.
What could be the cause?

  • A. The security lists of the subnets on which the two instances are located do not have “allow” rules for port 80 and 443.
  • B. The load balancer performed a health check on the application and found that compute instances were not in a healthy state and terminated the instances.
  • C. The client requested https access to the application and the load balancer service does not support end-to-end SSL from the client to the listener to the back-end set.
  • D. The Dynamic Routing Gateway is preventing the client traffic from your data center network from reaching the public IP of the load balancer.

Answer: A


When creating a subnet, one or more placeholder security lists are often associated with the subnet. Why?

  • A. Each operator needs its own security list.
  • B. Each protocol needs its own security list.
  • C. Each network endpoint or instance in the subnet needs its own security list.
  • D. It is not possible to add or remove security lists after a subnet is created.

Answer: C

References: https://docs.cloud.oracle.com/iaas/Content/Network/Concepts/securitylists.htm?tocpath=Services%7CNetworki


Which two methods are supported for migrating your on-premises Oracle database to an Oracle Autonomous Transaction Processing (ATP) database in Oracle Cloud Infrastructure? (Choose two.)

  • A. Load text files into ATP using SQL Developer.
  • B. Use RMAN duplicate.
  • C. Use Oracle Data Pump.
  • D. Transfer the physical database files and re-create the database.
  • E. Use database backup and restore.

Answer: CD

Reference: https://docs.oracle.com/en/solutions/migrate-to-atp/index.html#GUID-28E5A683-6DC6-4A07- BB1C-55F020D4C1CD


Which two are valid options when migrating a database from on-premise to Oracle Cloud Infrastructure? (Choose two.)

  • A. snapping or cloning storage form on-premise to Oracle Cloud Infrastructure
  • B. performing a backup to Oracle Cloud Infrastructure Object Storage, and then restoring to a database server on Oracle Cloud Infrastructure
  • C. performing RMAN backup to an on-premise storage device, and then shipping to Oracle Cloud Infrastructure
  • D. converting the Oracle database to a NoSQL database and migrating to Oracle Cloud Infrastructure by using rsync file copy

Answer: AC


Which three are capabilities of the dbaascli utility? (Choose three.)

  • A. Patching the primary database deployment
  • B. Open port 1521 in the VCN to allow for traffic to the listener
  • C. Start and open the database instance
  • D. Switchover and failover in an Oracle Guard configuration
  • E. Clone a DB

Answer: ACD

https://docs.oracle.com/en/cloud/paas/database-dbaas-cloud/csdbi/dbaascli.html Using the dbaascli utility, you can:
Change the password of a database user. Start and stop a database.
Start and stop the Oracle Net listener
Check the status of the Oracle Data Guard configuration.
Perform switchover and failover in an Oracle Data Guard configuration. Patch the database deployment.
Perform database recovery. Rotate the master encryption key.


Your company has been running several small applications in Oracle Cloud Infrastructure and is planning a proof-of-concept (POC) to deploy PeopleSoft.
If your existing resources are being maintained in the root compartment, what is the recommended approach for defining security for the upcoming POC?

  • A. Create a new compartment for the POC and grant appropriate permissions to create and manage resources within the compartment.
  • B. Provision all new resources into the root compartmen
  • C. Grant permissions that only allow for creation and management of resources specific to the POC.
  • D. Provision all new resources into the root compartmen
  • E. Use defined tags to separate resources that belong to different applications.
  • F. Create a new tenancy for the PO
  • G. Provision all new resources into the root compartmen
  • H. Grant appropriate permissions to create and manage resources within the root compartment.

Answer: A

If your organization is small, or if you are still in the proof-of-concept stage of evaluating OracleCloud Infrastructure, consider placing all of your resources in the root compartment (tenancy). This approach makes it easy for you to quickly view and manage all your resources. You can still write policies and create groups to restrict permissions on specific resources to only the users who need access.If you plan to maintain all your resources in the root compartment, we recommend setting up aseparate sandbox compartment to give users a dedicated space to try out features. In the sandbox compartment, you can grant users permissions to create and manage resources, whilemaintaining stricter permissions on the resources in your tenancy (root) compartment.


Which statement is NOT true about the Oracle Cloud Infrastructure Object Storage service?

  • A. Object storage resources can be shared across tenancies.
  • B. Immutable option for data stored in the Object Storage can be set via retention rules.
  • C. Object versioning is enabled at namespace level.
  • D. Object lifecycle rules can be used to either archive or delete objects.

Answer: B

Reference: https://docs.cloud.oracle.com/en-us/iaas/Content/Object/Tasks/usingversioning.htm


