Oracle Cloud Infrastructure 2025 Cloud Ops Professional Free Sample Questions

20 free sample questions213 in the full practice test

Try simulator

1Z0-1067-25 Sample Questions

  1. Question 1

    A financial services company is using OCI Resource Manager to deploy a complex, multi-VCN architecture. The lead DevOps engineer needs to ensure that sensitive outputs, such as a database administrator's initial password, are not displayed in the stack's log files or stored in the state file in plain text. Which Terraform language feature should be used in the configuration to achieve this?

    Answer and explanation

    Correct answer: B

    The correct way to prevent a Terraform output value from being displayed in logs is to mark it as sensitive. By setting the sensitive = true argument in the output block, Terraform will redact the value from CLI output. OCI Resource Manager respects this flag and will also hide the value in its logs and state file displays, providing the necessary security for sensitive information.

  2. Question 2

    An operations team is managing a large fleet of compute instances across several compartments. They need to retrieve a list of all instances that are tagged with "environment"="production" but only display their OCID, display name, and lifecycle state. Which OCI CLI command correctly accomplishes this using a JMESPath query?

    Answer and explanation

    Correct answer: D

    This command correctly queries for instances across all sub-compartments of the root tenancy compartment (-c --compartment-id-in-subtree true). The JMESPath query then filters this list ([?"freeform-tags".environment==production]) for instances with the specified freeform tag. Finally, it projects (.{...}) the results to show only the OCID (id:id), display name (name:"display-name"), and lifecycle state (state:"lifecycle-state").

  3. Question 3

    Multiple answers

    A cloud engineer is writing an Ansible playbook to automate the patching of a fleet of Oracle Linux instances in OCI. The playbook needs to connect to the instances, apply the latest security patches using yum, and then reboot the instance only if a kernel update was applied. Which TWO Ansible modules are essential for this task? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    The ansible.builtin.yum module is used to manage packages with the yum package manager on Red Hat-based systems like Oracle Linux. It can be used to install, update, or remove packages, and is the correct module for applying security patches.

    The ansible.builtin.reboot module is specifically designed to reboot a machine and wait for it to come back up. This is essential for applying kernel updates, and it can be used conditionally based on the result of the yum update task.

  4. Question 4

    A startup is deploying a new application on OCI compute instances and wants to automate the installation of their monitoring agent and the configuration of the firewall upon first boot. The configuration steps are identical for all instances and are defined in a shell script stored in an OCI Object Storage bucket. What is the most efficient method to execute this script using cloud-init?

    Answer and explanation

    Correct answer: A

    This is the most efficient and secure method. A pre-authenticated request (PAR) provides a temporary, secure URL to access the script without needing to configure complex IAM policies or credentials on the instance. The cloud-init user data can then contain a simple runcmd that downloads the script via curl and pipes it to a shell for execution, fully automating the process.

  5. Question 5

    A media company is experiencing significant cost overruns in their OCI tenancy, primarily related to Object Storage. The finance department wants to understand which specific department, identified by a cost-tracking tag named Department, is responsible for the majority of storage costs over the last quarter. How can a Cloud Ops professional generate this report using the Cost Analysis tool?

    Answer and explanation

    Correct answer: C

    The Cost Analysis tool allows for powerful filtering and grouping. To solve this, the professional must first set the correct time frame (last 90 days/quarter). Then, they must filter the results to only include the relevant service (Object Storage). Finally, to break down the costs by department, they must use the Group by feature and select the specific cost-tracking tag key (Department). This will produce a report showing the Object Storage costs attributed to each department tag value.

  6. Question 6

    An e-commerce platform runs its primary database on a high-performance compute instance with a 1 TB block volume. During peak sales events, the database experiences I/O bottlenecks, leading to slow transaction times. The current block volume is set to the 'Balanced' performance level. What is the most effective and immediate action to mitigate the I/O bottleneck without causing downtime for the database?

    Answer and explanation

    Correct answer: B

    OCI Block Volume service allows dynamic performance scaling. You can change the performance setting of an attached block volume without detaching it, meaning there is no downtime. Moving from 'Balanced' to 'Higher Performance' will increase the IOPS and throughput available to the volume, directly addressing the I/O bottleneck experienced by the database.

  7. Question 7

    True or False: A compartment quota policy, once set, prevents users from creating any new resources in that compartment if any one of the specified limits in the policy statement is reached.

    Answer and explanation

    Correct answer: A

    This statement is true. Compartment quotas are hard limits. If a quota policy is in effect for a compartment, any user action that would exceed a limit defined in that policy will be denied. This is a key governance feature to control resource consumption and costs within specific organizational units or projects.

  8. Question 8

    A global logistics company is designing a highly available application on OCI. The application consists of a web tier running on an instance pool. To ensure resilience and responsiveness, the application must automatically scale out when CPU utilization averages above 70% for 5 minutes, and scale in when it drops below 30% for 10 minutes. Which OCI service is used to define these specific scaling triggers?

    Answer and explanation

    Correct answer: C

    The Autoscaling Configuration service is where you define the policies that govern how an instance pool scales. This includes creating metric-based scaling policies that monitor performance metrics like CPU or memory utilization, defining the thresholds (e.g., >70% or <30%), and specifying the cooldown periods and number of instances to add or remove.

  9. Question 9

    A healthcare provider needs to implement a robust disaster recovery (DR) plan for their critical patient data stored in an OCI Block Volume. The Recovery Point Objective (RPO) is 1 hour, and the Recovery Time Objective (RTO) is 4 hours. The primary region is US East (Ashburn) and the DR region is US West (Phoenix). Which OCI feature should be implemented to meet these DR requirements?

    Answer and explanation

    Correct answer: B

    Cross-region asynchronous replication for block volumes is the native OCI solution designed specifically for this DR scenario. It continuously replicates data to a destination region with a typical RPO of less than a minute, easily meeting the 1-hour requirement. In a DR event, the replica volume can be activated in the DR region, allowing for rapid recovery that meets the 4-hour RTO.

  10. Question 10

    A retail company uses OCI Object Storage to store transaction logs. For compliance reasons, logs must be retained for 7 years. However, they only need to be accessed frequently for the first 30 days. After 30 days, they should be moved to a more cost-effective storage tier, and after one year, they should be moved to the most cost-effective long-term storage. Which OCI mechanism automates this process?

    Answer and explanation

    Correct answer: B

    Object Storage Lifecycle Policies are designed for this exact purpose. You can define rules that automatically perform actions on objects based on their age. A policy can be created with two rules: one to move objects from the Standard tier to the Infrequent Access tier after 30 days, and a second rule to move them from Infrequent Access to the Archive tier after 365 days. A final rule can be set to delete objects after 7 years.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 213 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon