1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 111 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 111

Single answer

You have an on-premises data center connected to your Oracle Cloud Infrastructure (OCI) tenancy through a Dynamic Routing Gateway (DRG) using IPSec VPN. You�ve set up a hub VCN attached to the DRG, and a spoke VCN that is locally peered with the hub VCN. You want on-premises hosts to securely communicate with resources in the spoke VCN using transit routing. Which configuration ensures traffic will flow correctly from on-premises to the spoke VCN?

  1. A

    A. Create a single route rule in your on-premises network pointing to the DRG and let default routing handle traffic to the spoke VCN.

  2. B

    B. Configure route rules in the DRG route table to direct on-premises traffic to the hub VCN, configure the hub VCN's route table to use the local peering gateway for the spoke VCN subnets, and configure the spoke VCN's route table to send return traffic back to the local peering gateway for the on-premises CIDR.

  3. C

    C. Connect the on-premises data center directly to the spoke VCN using a second DRG attachment and leave the hub VCN route table unchanged.

  4. D

    D. Place both the hub and spoke VCNs under the same route table so all traffic automatically routes from on-premises through the DRG to the spoke VCN without any special settings.

Show answer and explanation

Correct answer: B

Explanation

Transit routing in OCI requires configuring route rules at multiple layers: the DRG route table, the hub VCN� route table, and the spoke VCN� route table or local peering gateway. Refer to the OCI documentation on 'Transit Routing Inside an Oracle Cloud Infrastructure VCN' for detailed steps and best practices on using route distributions and local peering gateways to facilitate secure, end-to-end connectivity.

  • A. Incorrect.

    A. Incorrect. Simply pointing on-premises routes to the DRG without additional updates to OCI route tables will not enable transit routing to the spoke VCN. You must configure specific route rules in OCI to forward traffic beyond the hub VCN.

  • B. Correct.

    B. Correct. In a transit routing scenario, you must configure route rules in the DRG route table (direct on-premises subnets to the hub VCN), in the hub VCN route table (route spoke subnet traffic to the local peering gateway), and in the spoke VCN route table to return traffic from the local peering gateway back to the on-premises CIDR range. This setup properly enables on-premises-to-spoke routing via the hub.

  • C. Incorrect.

    C. Incorrect. Attaching the spoke VCN directly to the DRG would bypass the hub-and-spoke design. If the goal is transit through the hub VCN, you do not need a second DRG attachment for the spoke VCN. You only need proper route rules in the existing configuration.

  • D. Incorrect.

    D. Incorrect. Each VCN and the DRG route table require their own route rules to handle transit routing. Merging them under a 'single route table' is not a valid OCI configuration and does not automatically solve the routing requirements to forward traffic from on-premises to the spoke VCN.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam