1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 58 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 58

Select 2

Your team is deploying a two-tier web application on Oracle Cloud Infrastructure (OCI). The front-end server must be publicly accessible for incoming internet traffic, while the back-end server must remain inaccessible from the internet yet still be able to download software updates. Which two configurations should you implement to meet these requirements?

  1. A

    Place the back-end server in a private subnet with no public IP address and use a NAT Gateway for outbound internet connectivity.

  2. B

    Assign a public IP address to the back-end server and keep it in the public subnet to simplify installation of updates.

  3. C

    Deploy the front-end server in a private subnet and attach an Internet Gateway directly to that subnet for inbound requests.

  4. D

    Host the front-end server in a public subnet with a route table pointing to an Internet Gateway, limiting inbound traffic via security rules.

Show answer and explanation

Correct answers: A, D

Explanation

In OCI, front-end servers that must be reachable from the internet belong in a public subnet with an Internet Gateway route. Back-end servers should be secured in a private subnet without public IP addresses, using a NAT Gateway for outbound requests such as patching or updates. This design isolates critical workloads while still allowing necessary outbound traffic. Refer to the Oracle Cloud Infrastructure documentation on networking (https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/managingVCNs.htm) for further details on configuring public and private subnets, route tables, and gateways.

  • A. Correct.

    Option 1 is correct. A private subnet without a public IP ensures the back-end server is not directly exposed to the internet. Using a NAT Gateway allows outbound-only internet connections, enabling system updates or other outbound requests without opening inbound access.

  • B. Incorrect.

    Option 2 is incorrect. Assigning a public IP to the back-end server places it on the public internet, violating the requirement to keep the server inaccessible from outside. While it simplifies patching, it defeats the security purpose of a private subnet.

  • C. Incorrect.

    Option 3 is incorrect. Placing the front-end server in a private subnet with an Internet Gateway does not provide a proper route for inbound traffic. Private subnets do not directly route traffic from the internet, and attaching an Internet Gateway to a private subnet is not a recommended design or best practice in OCI.

  • D. Correct.

    Option 4 is correct. A public subnet configured with a route to an Internet Gateway enables the front-end server to accept inbound traffic. Restricting inbound access to the required ports (e.g., HTTPS) using security lists or network security groups aligns with OCI� best practice for public-facing hosts.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam