1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 172 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 172

Select 2

You have a compute instance in a private subnet that must reach an on-premises application over an IPSec VPN. The connection is failing. You run the Network Path Analyzer in Oracle Cloud Infrastructure to trace the path, and it shows that traffic is dropped at the gateway. Which two actions should you take to further troubleshoot and resolve the connectivity issue based on Network Path Analyzer findings?

  1. A

    Check the private subnet� route table to verify that the traffic is routed through the DRG towards your on-premises network

  2. B

    Create a separate NAT Gateway and route all private subnet traffic to the internet for reaching on-premises systems

  3. C

    Update the security lists or network security groups to allow the necessary protocols and ports for VPN traffic

  4. D

    Rebuild the IPSec VPN without specifying any routing rules in the private subnet route table

  5. E

    Review Flow Logs to confirm if the traffic is matching the correct route and security settings

Show answer and explanation

Correct answers: A, C

Explanation

Network Path Analyzer identifies issues by showing potential drop points in the path from the source to the target. In this scenario, the analysis indicates that traffic is dropped at the gateway, suggesting improper routing or a security rule. Correct steps involve verifying that the VCN� route table directs traffic to the DRG for on-premises access and ensuring security lists or network security groups permit the necessary VPN ports. Configuring a NAT Gateway or rebuilding the VPN without correcting routing/security issues would not fix the drop. Flow Logs can provide additional detail but only after ensuring routes and security are in place. For further details, consult Oracle Cloud Infrastructure documentation on Network Path Analyzer and routing configuration.

  • A. Correct.

    Option 1: Correct. If the route table is missing or misconfigured (e.g., not pointing to the DRG), traffic to on-premises will not be forwarded correctly. Verifying and correcting this route is a key step.

  • B. Incorrect.

    Option 2: Incorrect. A NAT Gateway is for outbound internet traffic from a private subnet, not for VPN traffic to on-premises. Network Path Analyzer results indicating drops at the gateway suggest a routing or security configuration problem, not a need for NAT to the internet.

  • C. Correct.

    Option 3: Correct. Network Path Analyzer might indicate a security rule issue. Ensuring the appropriate ports and protocols (e.g., UDP 500 and 4500) are allowed for VPN and IPSec traffic is often necessary.

  • D. Incorrect.

    Option 4: Incorrect. Simply rebuilding the IPSec VPN without fixing the underlying routing issues in the private subnet will not address the original drop. You still need valid routes in the private subnet's route table to ensure traffic can leave the VCN correctly.

  • E. Incorrect.

    Option 5: Incorrect. While reviewing Flow Logs can be helpful, it is typically done in conjunction with verifying route table entries and security rules first. Flow Logs alone will not address a drop caused by an invalid route or blocked port. As a standalone action, it does not directly resolve the drop indicated by Network Path Analyzer.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam