1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 72 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 72

Single answer

You have created a NAT Gateway in your Virtual Cloud Network (VCN) to allow instances in a private subnet to access the internet for operating system updates. However, the instances in the private subnet still cannot reach external repositories. Which step should you take to resolve this connectivity issue?

  1. A

    Create a route rule in the route table of the private subnet for 0.0.0.0/0 with the Internet Gateway as the target.

  2. B

    Create a route rule in the route table of the private subnet for 0.0.0.0/0 with the NAT Gateway as the target.

  3. C

    Enable internet access on the private subnet by attaching a public IP to each instance.

  4. D

    Add a local peering connection to share routing information between the private subnet and the NAT Gateway.

Show answer and explanation

Correct answer: B

Explanation

In Oracle Cloud Infrastructure, a NAT Gateway provides private subnets with secure outbound access to the internet for updates or downloads. To properly direct traffic, you need to add a default route rule (0.0.0.0/0) in the private subnet� route table, targeting the NAT Gateway. This way, the NAT Gateway securely translates outbound traffic without exposing the private subnet directly to the public internet. For further details, refer to the 'Setting Up a NAT Gateway' section in the OCI documentation.

  • A. Incorrect.

    Incorrect. Using an Internet Gateway route for a private subnet would bypass the NAT Gateway, exposing the subnet directly to the internet�defeating the purpose of having a private subnet and NAT configuration.

  • B. Correct.

    Correct. You must add or update a route rule directing all outbound traffic (0.0.0.0/0) from the private subnet to the NAT Gateway in the private subnet� route table. This ensures instances remain private while still having outbound access to external updates.

  • C. Incorrect.

    Incorrect. Assigning a public IP to instances in a private subnet is not recommended for secure environments, as it opens them to public traffic instead of funneling outbound traffic through the NAT Gateway.

  • D. Incorrect.

    Incorrect. Local peering is used to connect two VCNs within the same region, not for routing external internet-bound traffic via a NAT Gateway.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam