OCI 2025 Architect Associate Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 235 questions. Use the simulator for timed and flashcard mode. Or, view more alternate versions 1z0-1072-20 60 Questions 1Z0-1072-23 207 Questions.

Try Simulator

1Z0-1072-25 Sample Questions

  1. Question 1

    Q1

    A financial services company is architecting a highly available application on OCI. The application tier runs on a set of compute instances within a private subnet and must communicate with an Autonomous Transaction Processing (ATP) database. To ensure secure and private communication, the network architect has decided to use a Service Gateway. Which of the following IAM policies is required to allow instances in the VCN to make calls to the Oracle Services Network?

    Show answer & explanation

    Correct answer: B

    A Service Gateway provides a private connection path to supported Oracle services within the same region. However, connectivity is controlled by routing, not IAM policies. The essential configuration step is to add a route rule to the private subnet's route table that directs traffic destined for the Oracle Services Network (represented by a service CIDR label like 'All Services in Oracle Services Network') to the Service Gateway. IAM policies control what actions a principal can perform on resources, not the network path itself.

  2. Question 2

    Q2

    A media company uses OCI Object Storage to store large video files. To optimize costs, they have implemented a lifecycle policy to transition objects from the Standard tier to Infrequent Access after 30 days, and then to Archive after 90 days. An editor reports they are unable to access a 6-month-old video file directly via the standard S3-compatible API. What is the most likely reason for this issue?

    Show answer & explanation

    Correct answer: C

    Objects stored in the Archive tier are offline and cannot be accessed directly. They must first be restored, which makes a temporary copy available in the Standard tier for a specified duration. The lifecycle policy moved the 6-month-old file to the Archive tier after 90 days. The inability to access it directly is expected behavior for objects in this tier. The user must initiate a restore operation before they can download the object.

  3. Question 3

    Q3Multiple answers

    As a cloud architect, you are designing a secure environment for a new project. You need to ensure that a group of developers can only manage OCI resources (e.g., launch instances, create block volumes) if they are connected to the corporate network. Which combination of IAM features should you use to enforce this requirement? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    Network Sources allow you to define a set of allowed IP addresses, such as the public IP range of a corporate network. This is the first required component.

    An IAM policy is needed to grant permissions. To enforce the location constraint, you must add a 'where' clause to the policy that references the created Network Source (e.g., 'where request.networkSource.name = 'corp_network'').

  4. Question 4

    Q4

    A consultant is reviewing an OCI tenancy's compute configuration. They notice that several development instances are frequently being stopped and started, resulting in the loss of their public IP addresses. This is causing issues with DNS records and developer access. What is the most cost-effective and efficient way to ensure these instances retain a consistent public IP address across reboots?

    Show answer & explanation

    Correct answer: B

    By default, compute instances are assigned ephemeral public IPs, which are released when the instance is stopped. To maintain a consistent IP address, you should use a reserved public IP. OCI allows you to convert an existing ephemeral public IP to a reserved one, which can then be unassigned and reassigned to instances as needed, persisting through reboots. This is the most direct and efficient solution.

  5. Question 5

    Q5

    A large enterprise is migrating a legacy, monolithic application to OCI. The application requires a shared file system accessible by multiple compute instances for reading and writing configuration and log files. The performance requirement is moderate, but high durability and automated backups are critical. Which OCI storage service is the most appropriate choice for this use case?

    Show answer & explanation

    Correct answer: C

    The OCI File Storage service is a fully managed, enterprise-grade NFS service that provides a durable, scalable, and secure shared file system. It is designed for use cases where multiple clients need concurrent access to a common file system, which perfectly matches the requirements of the legacy application. It also supports automated snapshots for backups.

  6. Question 6

    Q6

    You are tasked with designing a networking architecture that connects two VCNs in different OCI regions (US East and EU Frankfurt) to enable a disaster recovery strategy. The connection must be private, reliable, and provide predictable performance. Which OCI networking component should be used to establish this connection?

    Show answer & explanation

    Correct answer: C

    A Remote Peering Connection (RPC) is the specific OCI component used to connect two VCNs in different regions. It allows resources in the VCNs to communicate using private IP addresses over Oracle's private network backbone, providing a secure and reliable connection suitable for disaster recovery scenarios.

  7. Question 7

    Q7

    A DevOps team is deploying a containerized application on OCI using an instance pool. They need to grant the application running on the instances permission to write logs to an OCI Object Storage bucket without storing or managing long-lived user credentials on the instances. What is the most secure method to achieve this?

    Show answer & explanation

    Correct answer: B

    This is the most secure and recommended method. By creating a dynamic group with a matching rule for the instance pool's OCID, all instances in that pool become members. You can then write an IAM policy that grants this dynamic group permission to manage objects in the target bucket. Applications on the instances can then use instance principals to be authenticated and authorized to call OCI services without needing to handle credentials.

  8. Question 8

    Q8

    A new compute instance is launched using a standard Oracle Linux image. A developer attempts to use the OS Management service to apply the latest security patches but finds the instance is not visible in the OS Management console. What is a prerequisite that might have been missed during the instance provisioning?

    Show answer & explanation

    Correct answer: B

    For an instance to be managed by the OS Management service, the Oracle Cloud Agent must be installed and running, and specifically, the OS Management Service Agent plugin must be enabled. While Oracle Linux images typically include the agent, it must be active and able to communicate with the OCI services. Connectivity via a Service Gateway (for private subnets) or Internet Gateway is also required, but the agent itself is the primary prerequisite for visibility in the console.

  9. Question 9

    Q9

    True or False: When configuring a Network Security Group (NSG), the rules defined within it are automatically applied to all Virtual NICs (VNICs) within the same subnet as the NSG.

    Show answer & explanation

    Correct answer: B

    This statement is false. Unlike Security Lists which apply to all VNICs in a subnet, Network Security Groups (NSGs) must be explicitly associated with a VNIC. An NSG acts as a virtual firewall for a chosen set of VNICs, allowing you to define security rules based on application tier or workload rather than subnet boundaries.

  10. Question 10

    Q10

    A database administrator needs to create a point-in-time, crash-consistent backup of a group of Block Volumes that are attached to a running database server. The database's data, redo logs, and archive logs are on separate Block Volumes. What OCI feature should be used to ensure all volumes are backed up at the exact same moment?

    Show answer & explanation

    Correct answer: C

    A Volume Group is designed for this exact purpose. It allows you to group multiple Block Volumes together and perform coordinated, time-consistent operations on them. Creating a backup of the Volume Group ensures that a crash-consistent backup of all member volumes is taken at the same point in time, which is critical for database recovery.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 1Z0-1072-25 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 502 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon