1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 50 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 50

Select 2

Your organization runs a multi-tier application on Oracle Cloud Infrastructure (OCI). The middle-tier application servers are placed in a private subnet and require occasional outbound internet connectivity for patch updates. However, you must ensure no inbound traffic from the public internet can reach these servers. Which two steps must you take to satisfy this requirement?

  1. A

    Create a NAT Gateway in the VCN.

  2. B

    Create an Internet Gateway and add an ingress rule to the subnet's security list for inbound HTTP traffic.

  3. C

    Add a route table rule for the private subnet that sends outbound traffic to the NAT Gateway.

  4. D

    Assign public IP addresses to the application servers.

Show answer and explanation

Correct answers: A, C

Explanation

To enable outbound internet connectivity from a private subnet in OCI without allowing inbound traffic, you must deploy a NAT Gateway and configure the subnet� route table to forward outbound traffic to that NAT Gateway. This approach ensures the servers can reach the internet for downloads or updates while remaining inaccessible from external networks. Refer to the Oracle Cloud Infrastructure Networking documentation for details on configuring NAT Gateways and route rules (https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/managingnatgateway.htm).

  • A. Correct.

    Correct. A NAT Gateway allows instances in a private subnet to initiate connections to the internet without exposing them to inbound connections.

  • B. Incorrect.

    Incorrect. While an Internet Gateway would provide internet connectivity, it also allows inbound traffic. This conflicts with the requirement to keep the subnet private and disallow external inbound connections.

  • C. Correct.

    Correct. You must configure the private subnet's route table to direct relevant outbound traffic (for example, 0.0.0.0/0) to the NAT Gateway so that instances can reach the internet for patch updates.

  • D. Incorrect.

    Incorrect. Assigning public IPs to the servers directly would expose them to inbound traffic, violating the security requirement.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam