1Z0-1072-25 exam dumps

1Z0-1072-25 practice question 82 of 318

Oracle Cloud Infrastructure 2025 Architect Associate. Associate level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1072-25 Question 82

Single answer

Your organization has set up an IPsec VPN connection from an on-premises data center to an Oracle Cloud Infrastructure (OCI) Virtual Cloud Network (VCN) using a Dynamic Routing Gateway (DRG). Although the tunnel is up, on-premises systems cannot reach compute instances in a private subnet of the VCN. Which single action should you take first to ensure end-to-end connectivity?

  1. A

    Enable Internet Gateway access and configure a default route in the public subnet� route table pointing to the Internet Gateway.

  2. B

    Create and configure a DRG route table rule to direct incoming on-premises traffic to the private subnet.

  3. C

    Configure a NAT Gateway for the private subnet to route inbound packets to on-premises systems.

  4. D

    Deploy a Service Gateway in each subnet to handle all inbound IPsec VPN traffic from the DRG.

Show answer and explanation

Correct answer: B

Explanation

To establish full connectivity over an IPsec VPN, you must configure proper routing rules in both the on-premises and OCI environments. In OCI, the DRG uses its own route tables to direct incoming traffic to specific subnets in the VCN. Reference the OCI documentation on 'Managing DRG Route Tables' to ensure any packets arriving via the VPN can reach the intended subnet.

  • A. Incorrect.

    Incorrect. An Internet Gateway is used for outbound internet traffic, not for tunneling on-premises traffic. Configuring a default route to the Internet Gateway is irrelevant to establishing internal connectivity from on premises.

  • B. Correct.

    Correct. When on-premises traffic arrives at the DRG, the DRG needs a route table entry to know where to forward the packets within the VCN. Without this rule, traffic will not be routed from the DRG to the private subnet.

  • C. Incorrect.

    Incorrect. A NAT Gateway is used for outbound connections to the internet from private subnets, not for inbound traffic from on premises. Adding a NAT Gateway does not solve routing issues for inbound VPN traffic.

  • D. Incorrect.

    Incorrect. A Service Gateway is used for private access to Oracle services such as Object Storage within OCI. It does not handle general on-premises to VCN traffic. Service Gateways do not replace the need for proper DRG routing.

Timed practice exam

Take a 1Z0-1072-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam