OCI 2023 Architect Associate Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 207 questions. Use the simulator for timed and flashcard mode. Or, view more alternate versions 1Z0-1072-25 235 Questions 1z0-1072-20 60 Questions.

Try Simulator

1Z0-1072-23 Sample Questions

  1. Question 1

    Q1

    A financial services company is deploying a three-tier web application in OCI. The compliance team has mandated that network traffic between the web and application tiers must be strictly controlled, allowing only specific TCP ports. Additionally, the security posture must be easily auditable and scalable as more application servers are added. Which OCI networking security feature should be used to meet these requirements most effectively?

    Show answer & explanation

    Correct answer: B

    Network Security Groups (NSGs) are the optimal choice here. They operate at the VNIC level, allowing for granular, stateful firewall rules to be defined for a specific set of resources (like the application tier) regardless of the subnet they reside in. This application-centric model is more scalable and easier to audit than subnet-wide Security Lists when managing traffic between specific application tiers.

  2. Question 2

    Q2

    A data analytics firm uses OCI File Storage Service (FSS) to share large datasets among a cluster of compute instances. The performance of data processing jobs has degraded. Initial investigation reveals that the FSS is experiencing high IOPS and throughput, but the compute instances are underutilized. You need to propose a solution to improve performance without changing the compute instance shapes. What is the most direct way to enhance the FSS performance?

    Show answer & explanation

    Correct answer: B

    OCI File Storage performance is primarily determined by the mount target, not the size of the file system. Creating multiple mount targets for the same file system (ideally in different Availability Domains for high availability) and distributing the compute instance connections among them is the standard method to scale out performance and overcome the throughput limits of a single mount target.

  3. Question 3

    Q3Multiple answers

    You are designing an IAM policy to grant a group of junior administrators the ability to manage compute instances within a specific compartment named 'Staging'. However, you must prevent them from terminating any instance that has a defined tag Protection: 'Critical'. Which two IAM policy statements, when combined, would achieve this goal? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    This statement grants the necessary broad permissions to manage instances (start, stop, create, etc.) within the specified compartment.

    This statement explicitly denies the terminate permission specifically on instances that have the required tag. IAM Deny statements always override Allow statements, making this the correct way to create the exception.

  4. Question 4

    Q4

    A startup is deploying a containerized application using OCI Container Engine for Kubernetes (OKE). For cost optimization, they plan to use a mix of VM instances and preemptible (spot) instances for their worker nodes. The application has some stateful components that require persistent storage. Which OCI storage service should be configured with the CSI (Container Storage Interface) plugin to provide reliable, high-performance, and network-attached block storage for the Kubernetes pods?

    Show answer & explanation

    Correct answer: C

    The OCI Block Volume service is the correct choice for providing persistent, network-attached block storage to Kubernetes pods via the CSI plugin. It allows a pod to mount a PersistentVolume that is backed by an OCI Block Volume. This ensures that the data persists even if the pod (or the preemptible instance it's running on) is terminated and rescheduled elsewhere.

  5. Question 5

    Q5

    A global e-commerce platform is hosted in the OCI Frankfurt region. To provide faster page loads for customers in North America and Asia, the architect decides to use the OCI Traffic Management service. They need to configure a steering policy that directs users to the geographically closest of three endpoints: one in Frankfurt, one in Ashburn, and one in Tokyo. If one endpoint fails its health check, traffic should automatically be redirected to the next closest healthy endpoint. Which Traffic Management steering policy should be implemented?

    Show answer & explanation

    Correct answer: C

    Geolocation Steering is the policy designed for this exact use case. It allows you to define rules that route DNS queries to different endpoints based on the geographic location of the request's source. It also incorporates health checks and allows for failover to other pools, ensuring that if the primary geographic endpoint is down, traffic is sent to the next most appropriate one.

  6. Question 6

    Q6

    During a routine audit, it was discovered that a developer inadvertently launched a large number of high-cost GPU compute instances in a development compartment, leading to a significant budget overrun. To prevent this from recurring, the cloud administrator needs to implement a control that automatically prevents the creation of resources that would exceed a predefined budget for that compartment. Which OCI feature should be used?

    Show answer & explanation

    Correct answer: C

    Compartment Quotas are specifically designed to control resource consumption. By setting a quota on the number of GPU instances (or a specific shape) within the 'development' compartment, you can prevent users from creating resources beyond that limit. This is a preventative control, whereas Budgets with alerts are a detective control (they notify you after the spend has occurred or is forecasted to occur).

  7. Question 7

    Q7

    True or False: When using an OCI NAT Gateway in a public subnet, you must also add a route rule to the private subnet's route table that directs traffic destined for the internet to the NAT Gateway.

    Show answer & explanation

    Correct answer: A

    This statement is true. A NAT Gateway allows instances in a private subnet to initiate outbound connections to the internet but prevents inbound connections. For this to work, the route table associated with the private subnet must have a rule with a destination of 0.0.0.0/0 and the target set to the NAT Gateway.

  8. Question 8

    Q8

    An architect is tasked with designing a highly available and fault-tolerant compute architecture. The application requires that if an entire Availability Domain (AD) fails, the application remains operational with minimal performance degradation. The application servers are stateless. What is the most cost-effective and resilient OCI compute configuration to achieve this?

    Show answer & explanation

    Correct answer: C

    This is the most effective solution. A single instance pool can be configured to span multiple ADs. This ensures that instances are automatically distributed for high availability. When combined with an autoscaling policy, if one AD fails and its instances become unhealthy, the autoscaling service will automatically launch new instances in the remaining healthy ADs to maintain the desired capacity, ensuring resilience and consistent performance.

  9. Question 9

    Q9

    A media company stores large video files in an OCI Object Storage Standard tier bucket for processing. After 30 days, these files are accessed infrequently but must be available for retrieval within two hours. After 180 days, they are rarely accessed and can tolerate a retrieval time of up to four hours. To optimize storage costs, what is the correct lifecycle policy configuration?

    Show answer & explanation

    Correct answer: C

    This configuration correctly maps the requirements to OCI's storage tiers. The Infrequent Access tier is for data accessed less often but requires rapid retrieval (milliseconds to seconds), fitting the 30-day requirement. Archive Storage is for long-term retention with longer retrieval times (a few hours), fitting the 180-day requirement. The policy should move to Infrequent Access after 30 days, and then to Archive after a total of 180 days (30 + 150).

  10. Question 10

    Q10

    You are troubleshooting a connectivity issue between a compute instance in a private subnet and the OCI Object Storage service endpoint. The instance needs to upload backup files. You have confirmed that the instance has the correct IAM permissions. A Service Gateway is attached to the VCN, and the private subnet's security list allows all egress traffic. What is the most likely missing configuration piece?

    Show answer & explanation

    Correct answer: A

    A Service Gateway provides a private path to OCI services, but it requires a corresponding route rule. The route table associated with the private subnet must have a rule that specifies the target as the Service Gateway and the destination as 'All Services in Oracle Services Network' (which includes Object Storage). Without this rule, the instance does not know how to route the traffic to the service endpoint over the private OCI backbone.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 1Z0-1072-23 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 502 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon