1Z0-997-25 exam dumps

1Z0-997-25 practice question 60 of 175

Oracle Cloud Infrastructure 2025 Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-997-25 Question 60

Select 2

You are designing a multi-tier e-commerce application on Oracle Cloud Infrastructure (OCI). The application has a public-facing load balancer front end, application servers running in a private subnet, and a database tier in a separate private subnet. The goal is to ensure minimal exposure of backend workloads, secure administration, and thorough inspection of incoming traffic. Which two OCI security configurations should you implement to achieve these objectives?

  1. A

    Enable Oracle Cloud Guard to automatically isolate critical subnets from each other, preventing all internal lateral movement by default

  2. B

    Use OCI Web Application Firewall (WAF) in front of your public load balancer to inspect and filter malicious requests

  3. C

    Deploy a bastion host in a separate subnet for administrative access to the private application servers

  4. D

    Assign a public IP address to the database subnet to facilitate application server connections and reduce latency

Show answer and explanation

Correct answers: B, C

Explanation

In a secure multi-tier OCI architecture, backend resources such as application servers and databases should reside in private subnets with no direct public exposure. A bastion host and an OCI Web Application Firewall help achieve secure, limited ingress for both administrative tasks and incoming traffic. For more details, reference Oracle� official documentation on best practices for securing multi-tier applications: https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_guide.htm

  • A. Incorrect.

    Incorrect: Oracle Cloud Guard monitors OCI resources for security risks and offers insights for remediation, but it does not automatically isolate subnets or block all lateral movement by default. You still need to configure Security Lists, Network Security Groups (NSGs), or custom security policies to enforce network isolation.

  • B. Correct.

    Correct: Deploying an OCI WAF in front of your public load balancer is a recommended best practice to filter out malicious traffic (e.g., XSS, SQL injection) before it reaches your application servers. This adds a critical layer of protection for public-facing endpoints.

  • C. Correct.

    Correct: A bastion host in a separate subnet provides a secure entry point for administrators to access private resources. This prevents exposing SSH/RDP ports directly to the internet and ensures that administrative connections are controlled and audited.

  • D. Incorrect.

    Incorrect: Exposing the database by assigning it a public IP drastically increases the attack surface. The recommended approach is to keep databases on private subnets and allow communication only through the application tier or bastion hosts in conjunction with security groups.

Timed practice exam

Take a 1Z0-997-25 practice test under exam conditions

60 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam