1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 123 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 123

Select 3

You have a publicly accessible domain named example.com hosted in an Oracle Cloud Infrastructure public DNS zone. Your development team wants a subdomain dev.example.com that is only resolvable internally within a specific VCN for testing new features. You must ensure example.com remains publicly available while dev.example.com is restricted to internal resolution. Which actions are necessary to fulfill these requirements?

  1. A

    Create a private DNS zone named dev.example.com, associate it with the relevant VCN, and define the necessary internal records.

  2. B

    Block external resolution of dev.example.com by creating a blackhole rule in the public zone settings.

  3. C

    Leave the public DNS zone for example.com as is, so the domain remains publicly resolvable to the outside world.

  4. D

    Perform periodic DNS zone transfers from the public zone example.com to the private zone dev.example.com to keep records synchronized.

  5. E

    Ensure the new private zone dev.example.com is accessible only via the custom DNS resolver in the associated VCN or subnets.

Show answer and explanation

Correct answers: A, C, E

Explanation

In Oracle Cloud Infrastructure, public DNS zones host records that are externally resolvable, whereas private DNS zones reside within a given VCN for internal resolution. To achieve the desired isolation, you create a private DNS zone for dev.example.com and associate it with the VCN to ensure that subdomain is not resolvable from the public internet. Meanwhile, you keep the existing public DNS zone for example.com intact so external queries remain unaffected. Refer to the Oracle Cloud Infrastructure DNS documentation for details on creating private zones and associating them with the correct VCNs.

  • A. Correct.

    CORRECT. Creating a private DNS zone for dev.example.com and associating it with the desired VCN is the recommended approach in OCI. This way, only resources within that VCN (or subnets you specify) can resolve dev.example.com. You also create any necessary internal records (A, CNAME, etc.) within this private zone.

  • B. Incorrect.

    INCORRECT. There is no built-in 'blackhole rule' feature in OCI's public DNS to block specific subdomains. To keep dev.example.com internal-only, you typically do not publicly delegate or publish this subdomain. You simply create a private zone in OCI without referencing it in the public zone, ensuring external resolution does not occur.

  • C. Correct.

    CORRECT. Leaving example.com in the public DNS zone allows external users to continue resolving the primary domain as usual. You do not need to modify or remove this public zone.

  • D. Incorrect.

    INCORRECT. Synchronizing records via zone transfers between a public zone (example.com) and a private subdomain (dev.example.com) is unnecessary. Public and private DNS zones are managed separately in OCI. You only create the needed records in each zone without transferring them back and forth.

  • E. Correct.

    CORRECT. By configuring dev.example.com as a private zone, you ensure that only clients within the specified VCN or subnets can resolve it. OCI� built-in DNS resolver handles these queries internally, keeping the subdomain inaccessible from the public internet.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam