Summer Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dealsixty

1z0-1124-25 Exam Dumps - Oracle Cloud Infrastructure Questions and Answers

Question # 24

When analyzing Flow Logs for a subnet, how can you filter logs to isolate traffic that was rejected due to a specific security list rule?

Options:

A.

By filtering on the "action" field with the value "REJECT" and the "securityListRule" field with the rule ID

B.

By filtering on the "status" field with the value "DENIED" and the "securityRule" field with the rule name

C.

By filtering on the "direction" field with the value "EGRESS" and the "port" field with the rule port

D.

By filtering on the "type" field with the value "SECURITY" and the "rule" field with the rule number

Buy Now
Question # 25

Which OCI component facilitates transitive routing between VCNs in different regions via a dedicated, private network backbone, while also enabling connectivity to on-premises networks?

Options:

A.

Local Peering Gateway (LPG)

B.

Dynamic Routing Gateway (DRG)

C.

Service Gateway

D.

Internet Gateway

Buy Now
Question # 26

When troubleshooting inter-region connectivity issues between VCNs peered via a Dynamic Routing Gateway (DRG), which OCI tool is most effective for verifying the routing configuration and identifying potential misconfigurations?

Options:

A.

Oracle Cloud Guard

B.

OCI Audit Logs

C.

DRG Route Tables

D.

Network Visualizer

Buy Now
Question # 27

When configuring inter-tenancy VCN peering, what is the purpose of the "peer ID" provided by the requesting tenancy to the accepting tenancy?

Options:

A.

To authenticate the requesting tenancy's root user.

B.

To uniquely identify the requesting tenancy's RPC.

C.

To specify the CIDR block of the requesting tenancy's VCN.

D.

To define the security rules for the peering connection.

Buy Now
Question # 28

You are designing a highly available application that requires low latency communication between OCI regions. You have two VCNs, VCN-A in Region 1 and VCN-B in Region 2. These VCNs have non-overlapping CIDR blocks and you want to establish a private, direct connection between them for optimal performance. Which of the following steps are necessary to establish this cross-region connectivity using the native OCI networking capabilities?

Options:

A.

Create a Remote Peering Connection (RPC) in each VCN, establish the peering, and update the route tables in each VCN to route traffic to the peer VCN’s CIDR block through the RPC.

B.

Configure an IPSec VPN tunnel between the VCNs and update the route tables in each VCN to route traffic to the peer VCN’s CIDR block through the IPSec VPN tunnel.

C.

Create a Service Gateway in each VCN, and configure a Dynamic Routing Gateway (DRG) toroute traffic between the Service Gateways.

D.

Create a NAT Gateway in each VCN and configure route rules to route traffic to the other NAT Gateway’s public IP address.

Buy Now
Question # 29

Which aspect of OCI’s security framework is essential for continuous monitoring and verification of packet flows, a core requirement of Zero Trust Packet Routing?

Options:

A.

Static routing configurations

B.

Default security lists

C.

Flow logs and audit trails

D.

Public IP address assignments

Buy Now
Question # 30

When establishing cross-tenancy connectivity using Remote Peering Connections (RPCs), which IAM policy statement is essential to grant the requesting tenancy the ability to initiate the connection?

Options:

A.

Allow group to manage virtual-network-family in tenancy=

B.

Allow group to use remote-peering-connections in tenancy=

C.

Allow group to inspect virtual-network-family in tenancy=

D.

Allow group to read remote-peering-connections in tenancy=

Buy Now
Question # 31

You are deploying a three-tier web application using Infrastructure as Code (IaC) and Oracle Kubernetes Engine (OKE) within a single VCN. The application consists of a public-facing web tier (running in OKE), an application tier, and a database tier. You want to ensure that only the web tier can access the application tier, and only the application tier can access the database tier. You are leveraging Network Security Groups (NSGs) for granular access control. Your IaC code successfully creates all the components, but you are experiencing connectivity issues. Specifically, Pods in the web tier cannot reach the application tier. Reviewing your IaC configuration, you realize the NSG assignments for the OKE cluster's node pool are misconfigured. Which of the following NSG configuration errors would most likely cause this connectivity issue?

Options:

A.

The NSG associated with the OKE node pool (web tier) allows ingress traffic from 0.0.0.0/0 on port 80, but egress traffic to the application tier's NSG is missing a rule allowing TCP traffic on port 8080 (the port the application tier is listening on).

B.

The NSG associated with the OKE node pool (web tier) is missing an ingress rule allowing traffic from the VCN CIDR on port 443. This is causing a routing problem within the VCN.

C.

The NSG associated with the application tier allows ingress traffic from the VCN CIDR, but the NSG associated with the OKE node pool (web tier) has no ingress rules at all. Therefore, the OKE nodes are not reachable.

D.

The NSG associated with the OKE node pool (web tier) only allows egress traffic to the internet and does not have a rule permitting egress traffic to the application tier's NSG on the required port (8080).

Buy Now
Question # 32

Your team is deploying a critical, highly available application that relies on accessing a MySQL Database Service instance within OCI. The application requires a stable and predictable endpoint for database connectivity, even during database failover events. Which endpoint configuration is most suitable to ensure seamless application connectivity in this high-availability scenario?

Options:

A.

Using the public IP address of the MySQL Database Service instance.

B.

Using a DNS hostname that resolves to the floating private IP address of the active MySQL Database Service instance.

C.

Using the private IP address of the primary MySQL Database Service instance directly.

D.

Using a Service Gateway to connect to the MySQL Database Service endpoint.

Buy Now
Question # 33

Your company has two FastConnect circuits connecting your on-premises network to OCI. You want to implement a BGP configuration that ensures that traffic from OCI to your on-premises network is load-balanced across both FastConnect circuits. Which BGP configuration would BEST achieve load balancing across the two FastConnect circuits?

Options:

A.

Configure different MED values on each FastConnect virtual circuit.

B.

Advertise the same prefixes with the same attributes (including AS Path) across both FastConnect circuits.

C.

Configure AS Path Prepending on one of the FastConnect virtual circuits.

D.

Configure local preference to be higher on one of the FastConnect virtual circuits.

Buy Now
Exam Code: 1z0-1124-25
Exam Name: Oracle Cloud Infrastructure 2025 Networking Professional
Last Update: Apr 29, 2025
Questions: 120
1z0-1124-25 pdf

1z0-1124-25 PDF

$34  $84.99
1z0-1124-25 Engine

1z0-1124-25 Testing Engine

$38  $94.99
1z0-1124-25 PDF + Engine

1z0-1124-25 PDF + Testing Engine

$54  $134.99