1Z0-1067-25 exam dumps

1Z0-1067-25 practice question 10 of 138

Oracle Cloud Infrastructure 2025 Cloud Ops Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1067-25 Question 10

Select 2

You recently created a compute instance with a public IP address in a newly created Virtual Cloud Network (VCN) that has only default components. However, you are unable to SSH into that instance from the public internet. Which three steps must you manually verify or perform to allow inbound SSH traffic?

  1. A

    Manually create an Internet Gateway in your VCN.

  2. B

    Set up a NAT Gateway to handle inbound SSH connections from the public internet.

  3. C

    Add a route rule for 0.0.0.0/0 to the Internet Gateway in your VCN� route table.

  4. D

    Create an ingress rule for TCP port 22 in the security list or network security group associated with the instance.

Show answer and explanation

Correct answers: B, C

Explanation

When deploying core services manually, allowing external access to your newly created instances requires ensuring an Internet Gateway is present, creating a route rule for traffic destined for the public internet (0.0.0.0/0) to point to the Internet Gateway, and configuring your security lists or network security groups to allow inbound SSH on port 22. A NAT Gateway is used for outbound connections, not inbound. For detailed guidance, refer to Oracle Cloud Infrastructure networking documentation at https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/overview.htm.

  • A. Incorrect.

    Correct: You must create an Internet Gateway to enable external inbound traffic into your VCN. By default, a newly created VCN does not include an Internet Gateway.

  • B. Correct.

    Incorrect: A NAT Gateway supports outbound internet access for resources in private subnets, not inbound connections from the public internet.

  • C. Correct.

    Correct: You must explicitly route all internet-bound traffic (0.0.0.0/0) to the Internet Gateway in your route table. Without this route, inbound traffic is dropped.

  • D. Incorrect.

    Correct: Security lists or network security groups need an ingress rule for port 22 (SSH). By default, the security list does not permit arbitrary inbound SSH traffic.

Timed practice exam

Take a 1Z0-1067-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam