1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 53 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 53

Single answer

Your company needs to apply critical security patches to an application running in a private subnet of your Virtual Cloud Network (VCN). To keep the subnet isolated, you want to ensure that instances in this private subnet can only initiate outbound connections to the internet and do not allow any inbound traffic from the internet. Which solution meets this requirement with the minimal exposure for your private subnet?

  1. A

    Expose the private subnet by attaching an Internet Gateway and relying on security list ingress rules

  2. B

    Use a NAT Gateway and configure the private subnet� route table to forward outbound traffic to it

  3. C

    Enable a Service Gateway for the private subnet and route all external requests through Oracle Services Network

  4. D

    Create a Local Peering Gateway between the private and public subnets to route outbound traffic over the public subnet

Show answer and explanation

Correct answer: B

Explanation

Using a NAT Gateway is the recommended way to allow systems on a private subnet in Oracle Cloud Infrastructure to initiate outbound connections for updates or patches while preventing inbound connections from the internet. The route table must be updated in the private subnet to forward traffic to the NAT Gateway for external access. Refer to Oracle Cloud Infrastructure documentation on 'NAT Gateways' for detailed setup and best practices.

  • A. Incorrect.

    Incorrect: Attaching an Internet Gateway to the private subnet would allow both outbound and inbound connections, which increases exposure. This approach contradicts the requirement to minimize exposure and restrict inbound traffic from the internet.

  • B. Correct.

    Correct: A NAT Gateway allows instances in the private subnet to initiate outbound connections without receiving inbound connections from the internet. Updating the subnet� route table to direct outbound traffic to the NAT Gateway achieves the goal of minimizing exposure.

  • C. Incorrect.

    Incorrect: A Service Gateway is specifically designed for access to Oracle Services (such as Object Storage) without traversing the public internet. It does not provide generic internet access and thus is not suitable for installing patches from external sources.

  • D. Incorrect.

    Incorrect: Local Peering Gateways facilitate communication between VCNs (or subnets in different regions) without routing to the internet. Peering with a public subnet doesn't allow secure outbound traffic to the internet from the private subnet in the desired manner and still risks exposure.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam