1Z0-1104-25 exam dumps

1Z0-1104-25 practice question 75 of 174

Oracle Cloud Infrastructure 2025 Security Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1104-25 Question 75

Single answer

Your organization hosts a business-critical e-commerce application across two Availability Domains (AD1 and AD2) in the same region. You must ensure that your application remains online even if one AD goes offline, and you also need to maintain end-to-end encryption all the way from the client to the backend instances to meet strict regulatory requirements. Which approach should you implement to fulfill these needs?

  1. A

    Deploy a private load balancer in AD1 with TCP-level health checks and SSL termination for backends in the same AD. Configure manual failover to AD2 when needed.

  2. B

    Use a regional public load balancer with SSL pass-through to backends in both AD1 and AD2, distributing requests across both ADs.

  3. C

    Deploy separate public load balancers in each AD with SSL termination and manage failover by manually changing DNS records when one AD is unavailable.

  4. D

    Use a single public load balancer in AD1 with HTTP health checks and re-encrypt traffic to backend servers in AD1 and AD2 using load balancer certificates.

Show answer and explanation

Correct answer: B

Explanation

Using a regional public load balancer is the recommended strategy for automatic high availability across multiple Availability Domains in Oracle Cloud Infrastructure (OCI). Configuring SSL pass-through ensures that data remains encrypted from the client through to the backend instances, meeting end-to-end encryption mandates. Refer to the OCI Load Balancer documentation (https://docs.oracle.com/en-us/iaas/Content/Balance/Concepts/balanceoverview.htm) for best practices on setting up regional load balancers with SSL to ensure both high availability and security compliance.

  • A. Incorrect.

    Option 1 is incorrect because it places the private load balancer in only one AD and requires manual intervention (manual failover to AD2). This setup does not provide automatic high availability and fails to ensure continuous operations if AD1 goes down.

  • B. Correct.

    Option 2 is correct. A regional public load balancer in OCI is a regional resource (covering multiple ADs), and using SSL pass-through means traffic remains encrypted from client to backend, satisfying end-to-end encryption requirements. It automatically distributes traffic to healthy backends in both AD1 and AD2, ensuring high availability if one AD fails.

  • C. Incorrect.

    Option 3 is incorrect because managing separate load balancers in each AD and relying on manual DNS updates can result in downtime during failover. This approach also complicates operational overhead and does not provide continuous high availability without manual steps.

  • D. Incorrect.

    Option 4 is incorrect because placing a single public load balancer in AD1 creates a single point of failure if that AD goes offline. Additionally, using HTTP health checks and re-encryption at the load balancer does not guarantee true end-to-end encryption from client to backend instances.

Timed practice exam

Take a 1Z0-1104-25 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam