Oracle 1z0-1072-22練習テストPDF試験材料
1z0-1072-22解答1z0-1072-22無料サンプルには全てリアル試験合格させます
オラクル1z0-1072-22認定試験は、クラウドインフラストラクチャーの分野において専門知識を証明したい専門家を対象としています。この認定試験は、Oracle Cloud Infrastructureを使用したクラウドベースのソリューションの実装と管理に関する知識とスキルを検証したい個人を対象としています。この試験は、クラウドソリューションに取り組んだ経験のある個人で、この分野でのキャリアをさらに進めたいと考えている人を対象としています。
Oracle 1z0-1072-22試験は、Oracle Cloud Infrastructureを使用してアプリケーションを構築および展開するための候補者の能力を試験するために設計されています。この試験は、複数選択問題から構成され、それぞれがクラウドインフラストラクチャの特定の領域に焦点を当てています。セクションには、Compute、Networking、Storage、Database、Identity and Access Management、Security、Monitoring and Analyticsが含まれます。
質問 # 128
Which two are required to create an IPSec VPN connection? (Choose two.)
- A. compute instance
- B. security list
- C. static route CIDR
- D. name
正解:B、C
質問 # 129
Your IT team has asked you to provision an Autonomous Database in Oracle Cloud Infrastructure (OCI), but they want it to operate similar to what you have currently on-premises.
What are the TWO prerequisites for successfully deploying an Autonomous Dedicated Database in OCI?
- A. Exadata Infrastructure
- B. Object Storage
- C. Autonomous Container Database
- D. Identity and Access Management (1AM) Policies
正解:A、D
質問 # 130
You have compartments C and D under the root compartment in your Oracle Cloud Infrastructure (OCI) tenancy; compartment C contains asub-compartment also named D.
You are trying to move this sub-compartment D to the parent compartment D like shown in the picture, but the move fails.
What is the reason for this error?
- A. Sub-compartment D needs to be empty before it can be moved.
- B. You need to move all the compartments in the hierarchy to thenew parent compartment.
- C. You cannot move a subcompartment to another parent compartment.
- D. Both parent and child compartments cannot have the same name.
正解:D
解説:
Reference:https://docs.cloud.oracle.com/en-us/iaas/Content/Identity/Tasks/managingcompartments.htm (restriction on moving compartments)
質問 # 131
D18912E1457D5D1DDCBD40AB3BF70D5D
You are a system administrator of your company and you are asked to manage updates and patches across all your compute instances running Oracle Linux in Oracle CloudInfrastructure (OCI). As part of your task, you need to apply all the latest kernel security updates to all instances.
Which OCI service will allow you to complete this task?
- A. Storage Gateway
- B. OS Management
- C. Resource Manager
- D. Streaming
- E. Registry
正解:B
解説:
Reference:https://blogs.oracle.com/cloud-infrastructure/os-management-with-oracle-cloud-infrastructure
質問 # 132
Which statement is true about OracleCloud Infrastructure FastConnect?
- A. For private peering, FastConnect extends your existing infrastructure toa virtual cloud network
- B. The FastConnect provider network offers only 1 Gbps port connection speed increments
- C. For private peering, FastConnect extends your existing infrastructure to allow you to consume object storage from your on-premises data center
- D. For public peering, a dynamic routing gateway must be configured and attached to the virtual cloud network (VCN)
正解:A
解説:
Explanation
With FastConnect, you can choose to use , or both.
Private peering: To extend your existing infrastructure into a virtual cloud network (VCN) in Oracle Cloud Infrastructure (for example, to implement a hybrid cloud, or a lift and shift scenario). Communication across the connection is with IPv4 private addresses (typically RFC 1918).
Public peering: To access public services in Oracle Cloud Infrastructure without using the internet. For example, Object Storage, the Oracle Cloud InfrastructureConsole and APIs, or public load balancers in your VCN. Communication across the connection is with IPv4 public IP addresses. Without FastConnect, the traffic destined for public IP addresses would be routed over the internet.
質問 # 133
Which ofthe following statements is true about the Oracle Cloud Infrastructure (OCI) Object Storage serverside encryption?
- A. Encryption of data encryption keys with a master encryption key is optional.
- B. Customer-provided encryption keys are always stored inOCI Vault service.
- C. Each object in a bucket is always encrypted with the same data encryption key.
- D. Encryption is enabled by default and cannot be turned off.
正解:B
解説:
Reference:https://docs.cloud.oracle.com/en-us/iaas/Content/Object/Tasks/usingyourencryptionkeys.htm
質問 # 134
Which two Oracle Cloud Infrastructure services use a Dynamic Routing Gateway?
- A. Local Peering
- B. OCI IPSec VPN Connect
- C. Internet Gateway
- D. OCI FastConnect Public Peering
- E. OCI FastConnect Private Peering
正解:B、E
解説:
Explanation
You can think of a DRG as a virtual router that provides a path for private traffic (that is, traffic that uses private IPv4 addresses) between your VCN and networks outside the VCN's region.
You use a DRG when connecting your existing on-premises network to your virtual cloud network (VCN) with one (or both) of these:
IPSec VPN
Oracle Cloud Infrastructure FastConnect (Private Only)
You also use a DRG when peering a VCN with a VCN in adifferent region:
Remote VCN Peering (Across Regions)
質問 # 135
Which two options are true for Autonomous Transaction Processing (ATP) database? (Choose two.)
- A. You canadd more Pluggable Database for consolidating multiple databases in ATP
- B. You can scale storage up or down in ATP
- C. You can scale CPU up or down in ATP
- D. You can add new ORACLE_HOME for bringing older versions of on-premises databases to ATP
- E. You can add/remove Diskgroup in ATP
正解:B、C
解説:
Explanation
You can scale up/down your Autonomous Database to scale both in terms ofcompute and storage only when needed, allows people to pay per use.
Oracle allows you to scale compute and storage independently, no need to do it together. these scaling activities fully online (no downtime required) in Details page Autonomous Database click Scale Up/Down. Click on arrow to select a value for CPU Core Count or Storage (TB).
Or Select auto scaling to allow the system to automatically use up to three times more CPU and IO resources to meet workload demand, compared to the database operatingwith auto scaling disabled.
質問 # 136
Your application front end consists of several Oracle Cloud Infrastructure compute instances behind a public load balancer. You have configured the load balancer to perform health checks on these instances.
What will happen if an instance fails to pass the configured health checks?
- A. The instance is replaced automatically by the load balancer.
- B. The load balancer stops sending traffic to that instance.
- C. The instance is terminated automatically by the load balancer.
- D. The instance is taken out of the back end set by the load balancer.
正解:B
解説:
One or more of the backend servers reports as unhealthy.
A backend server might be unhealthy or the health check might be misconfigured.
質問 # 137
You have hired a new employee to run reports from the Autonomous Data Warehouse (ADW) and are not confident in their SQL writing ability.
Into which consumer group will you assign this individual to minimize the impact of their code?
- A. High
- B. Medium
- C. Low
- D. Highest
- E. Lowest
正解:C
解説:
Explanation
in ADW, The tnsnames.ora file provided with the credentials zip file contains three database service names identifiable as high, medium, and low. The predefined service names provide differentlevels of performance and concurrency for Autonomous Data Warehouse.
high: The High database service provides the highest level of resources to each SQL statement resulting in the highest performance, but supports the fewest number of concurrent SQL statements. Any SQL statement in this service can use all the CPU and IO resources in your database. The number of concurrent SQL statements that can be run in this service is 3, this number is independent of the number of OCPUs in your database.
medium: The Medium database service provides a lower level of resources to each SQL statement potentially resulting a lower level of performance, but supports more concurrent SQL statements. Any SQL statement in this service can use multiple CPU and IO resources in yourdatabase. The number of concurrent SQL statements that can be run in this service depends on the number of OCPUs in your database.
low: The Low database service provides the least level of resources to each SQL statement, but supports the most number of concurrent SQL statements. Any SQL statement in this service can use a single CPU and multiple IO resources in your database. The number of concurrent SQL statements that can be run in this service can be up to 300 times the number of OCPUs.
The predefinedservice names provide different levels of performance and concurrency for Autonomous DB Choose whichever database service offers the best balance of performance and concurrency.
Use the low database service name. to minimize the impact of their SQLs to by low consumer group
質問 # 138
For what business need should you use Database Cloud Service (DBCS) instead of Oracle database on a compute instance?
- A. to implement Oracle RAC for high availability
- B. to bring your own license on a compute service
- C. to lower license and infrastructure cost
- D. to build an Oracle database on a compute service
正解:A
質問 # 139
You have been tasked with creating one virtual cloud network (VCN) each for two line of business (LOB) applications. LOB A and LOB B will need to communicate with each other. To ensure that you can utilize VCN peering, which network CIDR ranges should be used?
- A. VCN A (172.16.0.0/24) and VCN B (172.16.0.0/28)
- B. VCN A (10.0.0.0/16) and VCN B (10.0.16.0/24)
- C. VCN A (10.0.2.0/16) and VCN B (10.0.2.0/25)
- D. VCN A (10.0.0.0/16) and VCN B (10.1.0.0/16)
正解:D
解説:
VCN A (10.0.0.0/16) will use a range of IPS from 10.0.0.0 to 10.0.255.255 and VCN B (10.1.0.0/16) will use a range of IPS from 10.1.0.0 to 10.1.255.255 so will not be any Overlap between 2 VCNs
質問 # 140
Which two statements are true about restoring a volume from a block volume backup in Oracle Cloud Infrastructure Block Volume service?
- A. You can only restore a volume to the same availability domain in which the original block volume resides.
- B. You can restore a block volume backup to a larger volume size.
- C. You can restore only one volume from a manual block volume backup.
- D. You can restore a volume to any availability domain within the same region where the backup is stored.
- E. You can restore a volume from any full volume backup but not from an Incremental backup.
正解:B、D
解説:
Reference https://docs.cloud.oracle.com/en-us/iaas/Content/Block/Tasks/restoringavolumefromabackup.htm
質問 # 141
You have created a new compartment called Production to host some production apps. You have also created users in your tenancy and added them to a Group called "production group". Your users are still unable to access the Production compartment. How can you resolve this situation?
- A. Every compartment you create comes with a predefined set of policies, so no further action is needed
- B. Write an IAM Policy for "production_group" granting it access to the production compartment
- C. Your users get automatic access to all compartments, so no further action is needed
- D. Write an IAM Policy for each specific user granting them access to the production compartment
正解:B
解説:
Explanation
When creating a compartment, you must provide a name for it (maximum 100 characters, including letters, numbers, periods, hyphens, and underscores) that is unique within its parent compartment. You must also provide a description, which is a non-unique, changeable description for the compartment, from 1through 400 characters.
After creating a compartment, you need to write at least one policy for it, otherwise no one can access it (except administrators or users who have permissions set at the tenancy level). When creating a compartment inside anothercompartment, the compartment inherits access permissions from compartments higher up its hierarchy.
When you create an access policy, you need to specify which compartment to attach it to. This controls who can later modify or delete the policy. Dependingon how you've designed your compartment hierarchy, you might attach it to the tenancy, a parent, or to the specific compartment itself.
質問 # 142
How can you provide users access to an existing compartment?
- A. by granting users access to a compartment when the compartment is created
- B. by adding users to a compartment. All users in the compartment will have access to the objects in the compartment.
- C. by granting access directly to the user when the user is created
- D. by adding users to a group and defining a policy to provide the group access to the compartment
正解:D
解説:
A policy is a document that specifies who can access which Oracle Cloud Infrastructure resources that your company has, and how. A policy simply allows a group to work in certain ways with specific types of resources in a particular compartment In general, here's the process an IAM administrator in your organization needs to follow:
Define users, groups, and one or more compartments to hold the cloud resources for your organization.
Create one or more policies, each written in the policy language.
Place users into the appropriate groups depending on the compartments and resources they need to work with.
Provide the users with the one-time passwords that they need in order to access the Console and work with the compartments. For more information,
質問 # 143
You are a network architect of an application running on Oracle Cloud Infrastructure (OCI). Your security team has informed you about a security patch that needs to be applied immediately to one of the backend web servers. What should you do to ensure that the OCI load balancer does not forward traffic to this backend server during maintenance?
- A. Edit the security list associated with the subnet to avoid traffic connectivity to this backend serve
- B. Drain all existing connections to this backend server and mark the backend web server offline
- C. Create another OCI load balancer for the backend web servers, which are active and handling traffic
- D. Stop the load balancer for maintenance and restart the load balancer after the maintenance is finished
正解:B
解説:
A load balancer improves resource utilization, facilitates scaling, and helps ensure high availability. You can configure multiple load balancing policies and application-specific health checks to ensure that the load balancer directs traffic only to healthy instances. The load balancer can reduce your maintenance window by draining traffic from an unhealthy application server before you remove it from service for maintenance.
The Load Balancing service considers a server marked drain available for existing persisted sessions. New requests that are not part of an existing persisted session are not sent to that server.
Edit Drain State: Opens a dialog box in which you can change the drain state.
If you set the server's drain status to true, the load balancer stops forwarding new TCP connections and new non-sticky HTTP requests to this backend server.
This setting allows an administrator to take the server out of rotation for maintenance purposes.
e. Edit Offline State: Opens a dialog box in which you can change the offline status.
If you set the server's offline status to true, the load balance forwards no ingress traffic to this backend server.
質問 # 144
You are tasked with creating a highly available clustered application on Oracle Cloud Infrastructure consisting ofthree nodes. The round-trip latency between nodes must be less than 500 us (micro-seconds) and your cluster should be resilient to hardware failure.
What is the recommended deployment strategy?
- A. Deploy the cluster nodes in a single region and deploy each node into a different AD.
- B. Deploy the cluster nodes in a single region and deploy each node in different fault domains within a single AD.
- C. Deploy the cluster nodes in a single region and deploy each node into a different AD. Select the same fault domain in each AD to ensure consistency.
- D. Deploy the cluster nodes in two separate regions and take advantage of multiple availability domains (ADs) in each region.
正解:B
質問 # 145
Which three actions are required to configure a highly available and secure hybrid network between Oracle Cloud and your data center? (Choose three.)
- A. Create dynamic routing gateways in more than one AD within your region.
- B. Define a default route table entry for the VCN that directs all traffic to the data center network to a single DRG.
- C. Define a non-overlapping IP Address Space between the data center and the cloud.
- D. Create two or more CPEs that map to the private IP addresses of the customer routers used in the IPSec VPN Tunnel.
- E. Configure each of the CPEs to leverage each of the IPSec Tunnels created by the connection process.
正解:C、D、E
解説:
https://docs.cloud.oracle.com/iaas/Content/Network/Tasks/configuringCPE.htm
質問 # 146
Which two statements about Oracle CloudInfrastructure File Storage Service are accurate? (Choose two.)
- A. File systems use Oracle-managed keys by default.
- B. Communication with file systems in a mount target is encrypted via HTTPS.
- C. Customer can encrypt the communication to a mount target via export options.
- D. Mount targets use Oracle-managed keys by default.
- E. Customer can encrypt data in their file system using their own Vault encryption key.
正解:D、E
解説:
Reference:https://docs.cloud.oracle.com/en-us/iaas/Content/File/Concepts/filestorageoverview.htm
質問 # 147
You are designing a two-tier web application in Oracle Cloud Infrastructure (OCI). Your clients want to access the web servers from anywhere, but want to prevent access to the database servers from the Internet.
Which is the recommended way to design the network architecture?
- A. Create public subnets for web servers and private subnets for database servers in your VCN, and associate separate security lists and route tables for each subnet.
- B. Create a single public subnet for your web servers and database servers, and associate only your web servers to internet gateway.
- C. Create public subnets for web servers and private subnets for database servers in your virtual cloud network (VCN), and associate separate internet gateways for each subnet.
- D. Create public subnets for web servers and associate a dynamic routing gateway with that subnet, and a private subnet for database servers with no association to dynamic gateway.
正解:A
解説:
When you create a subnet, by default it's considered public, which means instances in that subnet are allowed to have public IP addresses. Whoever launches the instance chooses whether it will have a public IP address. You can override that behavior when creating the subnet and request that it be private, which means instances launched in the subnet are prohibited from having public IP addresses. Network administrators can therefore ensure that instances in the subnet have no internet access, even if the VCN has a working internet gateway, and security rules and firewall rules allow the traffic.
There are two optional gateways (virtual routers) that you can add to your VCN depending on the type of internet access you need:
Internet gateway: For resources with public IP addresses that need to be reached from the internet (example: a web server) or need to initiate connections to the internet.
NAT gateway: For resources without public IP addresses that need to initiate connections to the internet (example: for software updates) but need to be protected from inbound connections from the internet.
Just having an internet gateway alone does not expose the instances in the VCN's subnets directly to the internet. The following requirements must also be met:
The internet gateway must be enabled (by default, the internet gateway is enabled upon creation).
The subnet must be public.
The subnet must have a route rule that directs traffic to the internet gateway.
The subnet must have security list rules that allow the traffic (and each instance's firewall must allow the traffic).
The instance must have a public IP address.
質問 # 148
Which twostatements are true about Oracle Cloud Infrastructure Compute Service? (Choose two.)
- A. You can share custom images across tenancies and regions.
- B. You cannot launch a bare metal server in Oracle Cloud Infrastructure Compute Service.
- C. You can launch a virtual or bare metal instance by using the same LaunchInstance API.
- D. You can attach a block volume in an Availability Domain other than your compute instance.
正解:A、C
解説:
Explanation
References:
Regions and Availability DomainsVolumes are only accessible to instances in the same availability domain .
You cannot move a volume between availability domains or regions.
FYI: https://docs.cloud.oracle.com/iaas/Content/Block/Concepts/overview.htm
質問 # 149
You have an application running on Oracle Cloud Infrastructure. You identified that the read and write operations are slowing your application down enough to impair user access. The application is currently using a VM.Standard 1.2 compute without any block storage attached to it.
Which two options allow you to increase disk performance? (Choose two.)
- A. Terminate the compute instance and create a backup of the boot volume. Create a new compute instance using a VM Dense IO shape and restore the backup.
- B. Terminate the compute instance preserving the boot volume. Create a new compute instance using a VM Dense IO shape using the boot volume preserved.
- C. Terminate the compute instance preserving the boot volume. Create a new compute instance using a VM Standard shape and attach a new block volume to host your application.
- D. Create a backup of the boot volume. Create a new compute instance using a VM Dense IO shape and restore the backup.
正解:B、C
解説:
You can permanently terminate (delete) instances that you no longer need.By default, the instance's boot volume is deleted when you terminate the instance, however you can preserve the boot volume associated with the instance, so that you can attach it to a different instance as a data volume, or use it to launch a new instance.
You can use a boot volume backup to create an instance or you can attach it to another instance as a data volume. However before you can use a boot volume backup, you need to restore it to a boot volume.
質問 # 150
Which statement is true about interconnecting Virtual Cloud Network (VCN)?
- A. VCNs support transitive peering.
- B. The only way to interconnect VCNs is through peering.
- C. VCNs must be in the same tenancy to be peered.
- D. Peering VCNs should not have overlapping CIDR blocks.
正解:D
質問 # 151
Where do you findthe tnsnames.ora for your Autonomous Data Warehouse (ADW) database?
- A. The tnsnames.ora file is included in credentials.zip file that you download from service console of ADW
- B. The ADW database will place the tnsnames.ora file in an object storage bucket
- C. You can download tnsnames.ora from Oracle Cloud Infrastructure web console under ADW details page
- D. You are automatically prompted to download the tnsnames.ora file upon creation of the ADW database
正解:A
解説:
Explanation
https://docs.oracle.com/en/cloud/paas/autonomous-data-warehouse-cloud/user/connect-intorduction.html#GUID To download client credentials from the Autonomous Transaction Processing Service Console:
- From the Service Console click the Administration link.
-Click Download Client Credentials (Wallet).
- On the Download Client Credentials (Wallet) page, enter a wallet password in the Password field and confirm the password in the Confirm Password field. The password must be at least 8 characters long and must include at least 1 letter and either 1 numeric character or 1 special character. This password protects the downloaded Client Credentials wallet.
- Click Download to save the client security credentials zip file. By default the filename is:
Wallet_databasename.zip. You can save this file as any filename you want. You must protect this file to prevent unauthorized database access.
The zip file includes the following:
tnsnames.ora and sqlnet.ora: Network configuration files storing connect descriptors and SQL*Net client side configuration.
cwallet.sso and ewallet.p12: Auto-open SSO wallet and PKCS12 file. PKCS12 file is protected by the wallet password provided in the UI.
keystore.jks and truststore.jks: Java keystore and truststore files. They are protected by the wallet password provided while downloading the wallet.
ojdbc.properties: Contains the wallet related connection property required for JDBC connection. This should be in the same path as tnsnames.ora.
質問 # 152
You are responsible for creating and maintaining an enterprise application that consists of multiple storage volumes across multiple compute instances in Oracle Cloud Infrastructure (OCI).
The storage volumes include boot volumes and block volumes for your data storage. You need to create backups of these storage volumes in the most time-efficient manner.
How can you meet this requirement?
- A. Group together multiple storage volumes in a volume group and create volume group backups.
- B. Create clones of all boot volumes and block volumes one at a time.
- C. Create on-demand full backups of block volumes, and create custom images from the boot volumes.
- D. Create on-demand full backups of boot volumes, and copy data in block volumes to Object Storage using OCI CLI.
正解:A
質問 # 153
......
1z0-1072-22[2023年12月] 最新リリース] 試験問題あなたを必ず合格させます:https://www.passtest.jp/Oracle/1z0-1072-22-shiken.html
Oracle 1z0-1072-22試験の基礎問題と解答:https://drive.google.com/open?id=1CMQnBfCyqeOvzPPndNwpIngeKymP2F6S