1Z0-1151-25 exam dumps

1Z0-1151-25 practice question 36 of 133

Oracle Cloud Infrastructure 2025 Multicloud Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1151-25 Question 36

Single answer

Your organization has two separate VCNs in the same Oracle Cloud Infrastructure region, each with a private subnet in different compartments. You need to allow instances in the private subnet of each VCN to communicate privately, without routing traffic over the public internet. Which approach should you use to accomplish this requirement?

  1. A

    Create a Remote Peering Gateway in each VCN, pair them, and update only the outbound security lists on each subnet to allow inbound traffic.

  2. B

    Create a Local Peering Gateway in each VCN, establish a local peering connection, and configure route tables and security rules to allow private subnet traffic on both VCNs.

  3. C

    Attach each VCN to the same Dynamic Routing Gateway (DRG) using separate IPsec tunnels, and rely on route propagation to connect the subnets without further configurations.

  4. D

    Configure Public Load Balancers in both VCNs and direct traffic through ephemeral public IP addresses for inter-VCN communication.

Show answer and explanation

Correct answer: B

Explanation

When connecting two VCNs in the same region, you typically use Local Peering Gateways. Each VCN must have an LPG, and you must create a local peering connection between them. Then, update the route tables to send traffic destined for the peer VCN� CIDRs to the local peering gateway, and configure security rules to allow traffic from the peer subnets. For detailed guidance, consult the Oracle Cloud Infrastructure Networking documentation on Local VCN Peering.

  • A. Incorrect.

    Incorrect: Remote Peering Gateway is for peering VCNs across different regions, not within the same region. Also, you must configure both route tables and security rules to allow bidirectional traffic, not only outbound.

  • B. Correct.

    Correct: For VCNs in the same region, a Local Peering Gateway (LPG) is required in each VCN. After creating and pairing the LPGs, you must update the route tables to direct traffic to the LPG and modify security rules (Network Security Groups or security lists) to allow traffic between the subnets.

  • C. Incorrect.

    Incorrect: While a DRG can connect VCNs to on-premises networks or other networks, simply attaching both VCNs to the same DRG via IPsec tunnels is not the recommended approach for traffic within the same region. Additionally, relying solely on route propagation may not properly configure the required routes and security rules for direct private subnet communication.

  • D. Incorrect.

    Incorrect: Rerouting traffic over the public internet (via public load balancers and public IP addresses) contradicts the requirement for private connectivity. This approach would expose traffic to public endpoints and incur extra overhead.

Timed practice exam

Take a 1Z0-1151-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam