Oracle Cloud Infrastructure 2025 DevOps Professional Free Sample Questions

20 free sample questions222 in the full practice test

Try simulator

1Z0-1109-25 Sample Questions

  1. Question 1

    A financial services company is implementing a blue-green deployment strategy for a critical, stateful microservice running on an OKE cluster. The deployment pipeline must ensure zero downtime and provide an immediate rollback capability if post-deployment health checks fail. The current process involves manually updating a Kubernetes service selector to switch traffic. Which OCI DevOps Deployment Pipeline stage configuration is the most effective and automated way to manage the traffic shift between the blue and green environments?

    Answer and explanation

    Correct answer: D

    The OCI DevOps Deployment Pipeline includes a dedicated 'Traffic Shift' stage for managing blue-green and canary deployments on OKE. This stage is the most effective and automated method as it natively handles the controlled redirection of traffic between backend sets (representing the blue and green deployments) associated with a Kubernetes Service of type LoadBalancer. It provides fine-grained control and integrates seamlessly with validation and rollback stages. Using shell scripts or CLI commands introduces manual scripting overhead and is less robust than the purpose-built stage. Redeploying the service manifest is a valid but less controlled approach compared to the Traffic Shift stage.

  2. Question 2

    Multiple answers

    A DevOps team is managing a large-scale microservices application on OKE. They are experiencing intermittent latency issues and need to trace requests as they propagate across multiple services. To achieve this, they decide to implement a service mesh. Which of the following are primary benefits of integrating OCI Service Mesh into their OKE cluster? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    OCI Service Mesh provides deep observability into traffic between microservices. It automatically collects metrics, logs, and distributed traces, allowing teams to monitor and debug communication without instrumenting the application code itself.

    A core feature of OCI Service Mesh is enhancing security by automatically encrypting all traffic between services within the mesh using mutual TLS (mTLS). This enforces a zero-trust security model at the network layer.

  3. Question 3

    A DevOps engineer is configuring an OCI build pipeline that requires access to a private Maven repository hosted on-premises. The on-premises network is connected to the OCI VCN via FastConnect. To ensure the build process can resolve dependencies securely without traversing the public internet, what is the recommended approach for the build runner?

    Answer and explanation

    Correct answer: B

    For secure access to on-premises resources, the correct approach is to use a private build runner. This runner, hosted on an OCI compute instance within your VCN, can leverage the existing FastConnect circuit. By placing it in a private subnet with appropriate route table entries pointing to the DRG, it can communicate directly and securely with the on-premises Maven repository without any public internet exposure. Oracle-managed runners operate outside your VCN and cannot access private on-premises endpoints.

  4. Question 4

    During a security audit, it was discovered that a development team is storing database credentials as plain text in their build_spec.yaml file. This is a major security violation. You are tasked with resolving this issue by using the most secure and recommended OCI practice. What is the correct approach?

    Answer and explanation

    Correct answer: B

    The most secure and standard OCI practice is to use OCI Vault for secrets management. Credentials should be stored as secrets in a Vault. The build pipeline should be granted access via an IAM policy attached to its dynamic group. The build_spec.yaml can then reference these secrets securely using the ${vaultVariables. } variable substitution syntax, ensuring that credentials are never exposed in plain text within the source code or build specifications.

  5. Question 5

    True or False: When using OCI Resource Manager to provision an OKE cluster, you can use the drift detection feature to identify differences between the live cluster's configuration and the state defined in your Terraform configuration, but you must manually apply the changes to resolve the drift.

    Answer and explanation

    Correct answer: B

    This statement is false. While OCI Resource Manager's drift detection feature can identify discrepancies, you do not have to apply the changes manually. After a drift is detected, you can run a Terraform 'Apply' job directly from the Resource Manager console to bring the infrastructure back into alignment with the configuration file, thus automating the resolution process.

  6. Question 6

    A developer is writing a Dockerfile for a new Python microservice. To minimize the final image size and reduce the attack surface, they want to use a multi-stage build. The first stage will build the application dependencies, and the final stage will copy only the necessary artifacts into a minimal base image. Which Dockerfile command is essential for transferring the built artifacts from the builder stage to the final production stage?

    Answer and explanation

    Correct answer: C

    In a multi-stage Dockerfile, the COPY command with the --from flag is used to copy files or directories from a previous stage (referenced by its name or index) into the current stage. This is the fundamental mechanism for creating a lean production image by selectively transferring only the necessary compiled code, dependencies, or other artifacts, leaving behind the build tools and intermediate files.

  7. Question 7

    An organization is deploying a multi-tier application on an OKE cluster with public-facing web servers and private backend services. For security reasons, network traffic between the web and backend pods must be strictly controlled, allowing only specific ingress traffic on port 8080. Which Kubernetes resource should be implemented to enforce this policy?

    Answer and explanation

    Correct answer: C

    A NetworkPolicy is a Kubernetes-native firewalling resource used to control traffic flow at the IP address or port level (OSI layer 3 or 4). To enforce traffic rules between pods, you would create a NetworkPolicy that selects the backend pods and defines an ingress rule allowing traffic only from the web server pods on the specified port (8080). This provides granular, declarative network segmentation within the cluster.

  8. Question 8

    A DevOps team needs to automate notifications for their OCI deployment pipeline. They want to send a message to a Slack channel whenever a deployment to the production environment fails. Which combination of OCI services should they use to build this automation?

    Answer and explanation

    Correct answer: B

    This is the standard, event-driven approach in OCI. OCI DevOps services emit events for pipeline state changes. An OCI Events rule can be configured to filter for the specific 'Deployment Succeeded' or 'Deployment Failed' event type. The action for this rule would be to send the event to an OCI Notifications topic. An OCI Function, which contains the logic to format and send a message to the Slack webhook URL, can subscribe to this topic, triggering the notification.

  9. Question 9

    An e-commerce company experiences significant traffic spikes during holiday seasons. Their application runs on an OKE cluster, and they need to ensure the application can scale automatically to handle the load. The application pods' CPU utilization is a reliable indicator of load. Which Kubernetes controller is designed to automatically adjust the number of running pods in a deployment based on observed CPU utilization?

    Answer and explanation

    Correct answer: C

    The Horizontal Pod Autoscaler (HPA) is the Kubernetes component responsible for automatically scaling the number of pods in a ReplicaSet, Deployment, or StatefulSet. It periodically checks metrics such as CPU utilization or custom metrics against a target value defined in the HPA configuration and increases or decreases the number of replicas accordingly. The Cluster Autoscaler scales the number of nodes, and the VPA adjusts the resource requests/limits of individual pods.

  10. Question 10

    A team is adopting Infrastructure as Code using Terraform to manage their OCI resources. They need to provision a VCN, multiple subnets, and a compute instance. To ensure the compute instance is only created after the subnets are available, what Terraform mechanism should be used?

    Answer and explanation

    Correct answer: B

    Terraform automatically builds a dependency graph by analyzing the references between resources. When the subnet_id argument in the oci_core_instance resource references an attribute of the oci_core_subnet resource (e.g., oci_core_subnet.mysubnet.id), Terraform understands that the subnet must be created before the instance. This is known as an implicit dependency and is the preferred method. The depends_on meta-argument is for creating explicit dependencies when there is no direct reference between resources.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 222 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon