1Z0-997-25 exam dumps

1Z0-997-25 practice question 127 of 175

Oracle Cloud Infrastructure 2025 Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-997-25 Question 127

Select 2

Your organization runs a critical Oracle Database@Google Cloud instance for data storage while hosting front-end applications on Oracle Cloud Infrastructure (OCI). You have decided to set up Oracle Interconnect for Google Cloud for a secure, private, and low-latency connection between the two clouds. Which two configuration steps must you implement to ensure successful communication and restrict network access to only the necessary subnets?

  1. A

    Set up a BGP session for dynamic routing over the Interconnect from your OCI Virtual Cloud Network (VCN) to the Google Cloud subnets hosting the database.

  2. B

    Attach an Internet Gateway in the same VCN and forward all traffic to the Google Cloud database subnets through that gateway.

  3. C

    Restrict incoming traffic on the Google Cloud side to only the OCI subnets by updating the Google Cloud firewall and route tables for the Interconnect path.

  4. D

    Deploy a NAT Gateway in OCI to relay all database traffic from the VCN to the Google Cloud database.

Show answer and explanation

Correct answers: A, C

Explanation

When configuring Oracle Interconnect for Google Cloud to communicate with your Oracle Database@Google Cloud instance, you must establish dynamic routing to exchange route information over a private connection. Setting up a BGP session on both sides is essential to ensure each environment can see the proper subnets. Additionally, restricting your Google Cloud firewall and route tables to only accept OCI subnets over the Interconnect helps secure the environment. An Internet Gateway or NAT Gateway would be used for public internet access or outbound traffic to public endpoints, which is not required in this private interconnection scenario. Refer to the Oracle Cloud Infrastructure documentation and Google Cloud documentation on configuring private peering for more details.

  • A. Correct.

    Option 1 is correct. A BGP session is required to advertise and learn routes dynamically between OCI and Google Cloud over the private Interconnect, ensuring that only relevant subnets have access to the database.

  • B. Incorrect.

    Option 2 is incorrect. An Internet Gateway is not needed to access resources over the private Interconnect. The entire purpose of the Interconnect is to establish a private peering path without routing traffic over the public internet.

  • C. Correct.

    Option 3 is correct. In Google Cloud, you must update firewall rules and pertinent routing policies to only allow traffic from specific OCI VCN subnets, thereby limiting the attack surface and ensuring security.

  • D. Incorrect.

    Option 4 is incorrect. A NAT Gateway is used to allow private subnets to initiate outbound connections to the internet, which is not needed for private connectivity over the Interconnect.

Timed practice exam

Take a 1Z0-997-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam