1Z0-1123-25 exam dumps

1Z0-1123-25 practice question 15 of 150

Oracle Cloud Infrastructure 2025 Migration Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1123-25 Question 15

Single answer

Your organization is migrating a multi-tier application from on-premises to Oracle Cloud Infrastructure (OCI). The application consists of multiple subnets across two Virtual Cloud Networks (VCNs) in the same OCI region. You want to ensure that traffic between these VCNs stays on OCI� internal backbone, minimizing egress costs and reducing exposure to the public internet. Which OCI networking service or feature should you configure to enable secure, private communication between these VCNs within the same region?

  1. A

    Configure Local Peering Gateways to connect the two VCNs privately in the same region

  2. B

    Use a Dynamic Routing Gateway (DRG) to route private traffic between the two VCNs

  3. C

    Implement a NAT Gateway to allow private traffic to flow between the VCNs

  4. D

    Establish a Service Gateway to communicate privately between the VCNs

Show answer and explanation

Correct answer: A

Explanation

To connect two VCNs in the same region for private traffic, you should use Local Peering Gateways. This setup ensures that traffic remains within the OCI private network rather than transiting through the public internet. Refer to the OCI documentation on local and remote VCN peering for additional details and best practices.

  • A. Correct.

    Local Peering Gateways enable direct, private peering between two VCNs within the same region. This method ensures traffic remains in OCI� private backbone, avoiding the public internet and additional egress costs.

  • B. Incorrect.

    Using a DRG is primarily intended for connecting on-premises networks or remote VCNs (in another region) to an OCI VCN. It is not the most straightforward method for peering two VCNs in the same region, making it unsuitable for this use case.

  • C. Incorrect.

    NAT Gateways provide outbound internet access from a private subnet without exposing private IP addresses. They do not facilitate VCN-to-VCN communication, so this is not the correct choice for internal traffic between VCNs in the same region.

  • D. Incorrect.

    Service Gateways allow private access to OCI public services, such as Object Storage, without using the internet. They do not provide VCN-to-VCN connectivity, so this option does not fulfill the requirement.

Timed practice exam

Take a 1Z0-1123-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam