1Z0-1151-25 exam dumps

1Z0-1151-25 practice question 81 of 133

Oracle Cloud Infrastructure 2025 Multicloud Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1151-25 Question 81

Single answer

Your organization is migrating an on-premises Oracle Database to Oracle Database@Azure. A private interconnect between Azure and Oracle Cloud Infrastructure has been established, but during final testing, the team finds that an Azure-based application cannot connect to the newly provisioned Oracle Database@Azure instance. Which action must you take first to enable secure connectivity from the Azure environment to Oracle Database@Azure?

  1. A

    Add a public IP address to the Oracle Database@Azure instance and connect over the Internet.

  2. B

    Modify the Oracle Database@Azure listener to accept unencrypted inbound connections from Azure.

  3. C

    Enable port redirection in Azure Firewall to forward application traffic directly to Oracle Database@Azure.

  4. D

    Update the Network Security Group (NSG) rules on the Oracle Database@Azure subnet to allow inbound traffic from the Azure VNet IP range.

Show answer and explanation

Correct answer: D

Explanation

While setting up Oracle Database@Azure, both the private interconnect and the correct Network Security Group (NSG) rules are essential for connectivity. The NSG rules on the Oracle Cloud Infrastructure side must explicitly permit inbound traffic from the Azure VNet IP range; without these rules, connections will be blocked regardless of the interconnect configuration. Refer to the official Oracle Database@Azure documentation on configuring network security groups and interconnect routing for further details on ensuring secure, private connectivity.

  • A. Incorrect.

    Option 1 is incorrect because adding a public IP address would bypass the secure interconnect and is not recommended for production environments. Oracle Database@Azure is designed to work with private connections through the OCI-Azure Interconnect rather than using a public endpoint.

  • B. Incorrect.

    Option 2 is incorrect because modifying the listener to accept unencrypted connections could introduce security risks. Additionally, the listener configuration alone doesn�t solve blocking issues if the Network Security Group rules aren�t set to allow inbound traffic from Azure subnets.

  • C. Incorrect.

    Option 3 is incorrect because traffic redirection at the Azure Firewall level doesn�t solve the underlying Network Security Group rules within OCI. The firewall can forward traffic to OCI, but if NSG rules block it, connectivity would still fail.

  • D. Correct.

    Option 4 is correct. Even with the interconnect established, you must ensure that the Network Security Group rules on the Oracle Database@Azure subnet in OCI allow inbound traffic from the application� Azure VNet IP range. This step is crucial in enabling the private, secure connection.

Timed practice exam

Take a 1Z0-1151-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam