1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 177 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 177

Single answer

You are investigating suspicious inbound traffic from a known malicious IP address targeting a compute instance in your private subnet. To reduce overhead, you only want to capture packets originating from that IP. Which approach should you use when configuring your Virtual Test Access Point (VTAP) and capture filter within Oracle Cloud Infrastructure (OCI)?

  1. A

    Create a VTAP on the instance� VNIC, define a capture filter that specifies the malicious IP as the source address, set the traffic direction to INGRESS (inbound), and attach this filter to the VTAP.

  2. B

    Create a VTAP for the entire VCN without any capture filter, then rely on a third-party analysis tool to drop irrelevant traffic afterward.

  3. C

    Configure a capture filter by referencing your route table rules to match packets from the malicious IP and attach it directly to the route table.

  4. D

    Create a VTAP on the internet gateway, specify a capture filter for all inbound traffic on ephemeral ports, and rely on inferred IP addresses for matching.

Show answer and explanation

Correct answer: A

Explanation

To selectively capture traffic in Oracle Cloud Infrastructure, you must configure a VTAP and attach a capture filter that specifies relevant parameters like source or destination IP, port, and packet direction. By correctly targeting the instance VNIC and using the malicious IP address as the filter criterion, you ensure that only suspicious inbound packets are forwarded to your analysis tool. For more details, refer to the OCI documentation on VTAPs and capture filter configurations.

  • A. Correct.

    Correct. Specifying the malicious IP address as the source in the capture filter, along with setting the flow direction to inbound (INGRESS), ensures that only traffic from that specific IP is collected. Attaching the filter to the VTAP on the affected VM� VNIC limits the scope in a precise and efficient way.

  • B. Incorrect.

    Incorrect. Creating a VTAP without a capture filter will capture all traffic and potentially introduce unnecessary overhead and complexity in downstream analysis. It defeats the purpose of selectively capturing only malicious traffic.

  • C. Incorrect.

    Incorrect. Capture filters are attached to VTAPs, not directly to route tables. While route tables govern traffic routing, they do not directly control packet capture or filtering at the packet level.

  • D. Incorrect.

    Incorrect. Attaching the VTAP at the internet gateway level and filtering on ephemeral ports alone is too broad and may miss targeted traffic. Malicious IP addresses may not always communicate through specific ephemeral ports, making this approach less reliable.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam