1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 51 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 51

Single answer

Your organization hosts a multi-tier application in Oracle Cloud Infrastructure (OCI) with a web tier in a public subnet and an application tier in a private subnet within the same Virtual Cloud Network (VCN). The application servers in the private subnet need to download operating system patches from external repositories on the public internet while blocking all inbound connections from external networks. Which solution should you implement to meet this requirement?

  1. A

    Attach an Internet Gateway to the VCN and update the private subnet route table to send 0.0.0.0/0 traffic to the Internet Gateway.

  2. B

    Configure a NAT Gateway for the VCN and add a default route (0.0.0.0/0) in the private subnet route table pointing to the NAT Gateway.

  3. C

    Use a Service Gateway in the private subnet to route 0.0.0.0/0 traffic to the Oracle Services Network for internet updates.

  4. D

    Peer the private subnet with the public subnet so the private hosts can use the public subnet� Internet Gateway.

Show answer and explanation

Correct answer: B

Explanation

NAT Gateways in OCI provide outbound-only access to external networks. By configuring the private subnet� route table to forward all external traffic to a NAT Gateway, the application servers can download patches from the public internet without allowing any inbound traffic from external sources. This is considered a best practice for secure, private subnets. Refer to Oracle� official documentation on Virtual Cloud Networks and NAT Gateways for details on configuring route rules and security lists.

  • A. Incorrect.

    Option 1 is incorrect because attaching an Internet Gateway and routing all private subnet traffic through it will allow inbound connections from the public internet, violating the requirement to block external inbound traffic to the private subnet.

  • B. Correct.

    Option 2 is correct. A NAT Gateway allows outbound internet traffic from the private subnet without permitting any inbound connections from external networks. You must update the route table of the private subnet so that 0.0.0.0/0 traffic goes to the NAT Gateway.

  • C. Incorrect.

    Option 3 is incorrect because a Service Gateway is used primarily for accessing Oracle services (e.g., Object Storage or OS Management Service) via the Oracle Services Network. It does not provide full internet access for non-Oracle public repositories.

  • D. Incorrect.

    Option 4 is incorrect because peering with the public subnet does not isolate inbound traffic. The public subnet� Internet Gateway would still expose the private subnet to external connections, contradicting the requirement.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam