無料2023年最新の1z0-1072-23問題集で100%合格保証には最新の サンプル [Q20-Q38]

Share

無料2023年最新の1z0-1072-23問題集で100%合格保証には最新の サンプル

準備1z0-1072-23問題解答無料更新には100%試験合格保証 [2023]


Oracle 1z0-1072-23 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Describe OCI compute image options
  • Configure DNS and Traffic Management
トピック 2
  • Configure Security Lists and Network Security Groups
  • Describe and configure OS Management
トピック 3
  • Understand Block Volume performance tiers
  • Understand Object Storage replication
トピック 4
  • Configure Volume Groups, Backups, Clones
  • Implement conditional and advanced policies
トピック 5
  • Implement and manage Virtual Cloud Networks
  • Describe and configure a layer-4 Network Load Balancer
トピック 6
  • Configure and manage Object Storage
  • Understand File System usage and metering

 

質問 # 20
Which THREE capabilities are available with the Oracle Cloud Infrastructure (OCI) DNS service?

  • A. Viewing all zones
  • B. Creating and managing Identity Access Management (IAM) policies
  • C. Creating and managing zones
  • D. Creating and managing security lists
  • E. Creating and managing records
  • F. Creating and managing WAF rules

正解:A、C、E

解説:
Explanation
Creating and managing records, creating and managing zones, and viewing all zones are three capabilities that are available with the OCI DNS service. Records are data elements that map domain names to IP addresses or other information. Zones are collections of records that correspond to a domain name or a subdomain name.
The OCI DNS service allows users to create and manage records and zones for their domains or subdomains, as well as view all zones in their tenancy. The other options are not capabilities of the OCI DNS service, but of other OCI services such as WAF, IAM, and Networking. References: [DNS Service], [Records], [Zones]


質問 # 21
You plan to launch a VM instance with the VM.Standard2.24 shape and Oracle Linux 8 platform image. You want to protect your VM instance from low-level threats, such as rootkits and bootkits that can infect the firmware and operating system and are difficult to detect.
What should you do?

  • A. Create a shielded instance.
  • B. Use in-transit encryption.
  • C. Create a burstable instance.
  • D. Use Vulnerability Scanning Service.

正解:A

解説:
The explanation is that shielded instances are VM instances that have additional security features to protect them from low-level threats, such as rootkits and bootkits that can infect the firmware and operating system and are difficult to detect. Shielded instances use verified boot, which ensures that only trusted software components are executed during the boot process. Shielded instances also use virtual trusted platform module (vTPM), which provides a secure storage for encryption keys and certificates. Shielded instances are available for Oracle Linux 8 platform images with VM.Standard2.* shapes.


質問 # 22
In which TWO ways does Cloud Guard help improve the overall security posture for your tenancy?

  • A. Masks sensitive data and monitors security controls on your Oracle databases.
  • B. Helps detect misconfigured resources, such as publicly accessible Object Storage buckets, instances, and restricted ports on security lists.
  • C. Prevents you from creating misconfigurations on your resources in Oracle Cloud Infrastructure (OCI).
  • D. Monitors unauthorized or suspicious user activity.
  • E. Allows you to centrally manage encryption keys.

正解:B、C、D

解説:
Explanation
Monitors unauthorized or suspicious user activity, prevents you from creating misconfigurations on your resources in OCI, and helps detect misconfigured resources, such as publicly accessible Object Storage buckets, instances, and restricted ports on security lists. The explanation is that Cloud Guard is a service that helps you improve the security posture of your tenancy by providing visibility into your cloud resources, identifying security misconfigurations and threats, and taking corrective actions to remediate them. Cloud Guard monitors user activity and resource configurations using data collectors and detectors, evaluates them against predefined or custom rules, generates problems and recommendations based on severity levels, and executes responders to fix the issues automatically or manually.


質問 # 23
You want a full-featured Identity-as-a-Service (IDaaS) solution that helps you manage workforce authentication and access to all of your Oracle and non-Oracle applications, whether they are SaaS apps, on-premises enterprise apps, or apps that are hosted in the cloud. Which IAM Identity Domain type should you create?

  • A. External User
  • B. Premium
  • C. Free
  • D. Oracle Apps Premium

正解:B

解説:
Premium is the IAM Identity Domain type that you should create if you want a full-featured IDaaS solution that helps you manage workforce authentication and access to all of your Oracle and non-Oracle applications. Premium Identity Domain provides users with access to Oracle Identity Cloud Service, which is an IDaaS solution that offers identity management, single sign-on, multifactor authentication, identity governance, and integration with third-party applications. The other options are not IAM Identity Domain types that provide a full-featured IDaaS solution. Reference: [Identity Domains], [Oracle Identity Cloud Service]


質問 # 24
A financial firm is designing an application architecture for its online trading platform that should have high availability and fault tolerance.
Their solutions architects configured the application to use an Oracle Cloud Infrastructure (OCI) Object Storage bucket located in the US West (us-phoenix-1) region to store large amounts of financial dat a. The stored financial data in the bucket should not be impacted even if there is an outage in one of the Availability Domains or a complete region.
What should the architect do to avoid any costly service disruptions and ensure data durability?

  • A. Create a replication policy to send data to a different bucket in another OCI region.
  • B. Create a lifecycle policy to regularly send data from the Standard to Archive storage.
  • C. Copy the Object Storage bucket to a block volume.
  • D. Create a new Object Storage bucket in another region and configure lifecycle policy to move data every 5 days.

正解:A

解説:
Create a replication policy to send data to a different bucket in another OCI region. The explanation is that replication is a feature of Object Storage that allows you to automatically copy objects from one bucket to another bucket, either in the same region or in a different region. Replication can help you improve data availability and durability, as well as meet compliance and disaster recovery requirements. To enable replication, you need to create a replication policy that specifies the source and destination buckets, the replication frequency, and the replication filters. Replication policies are evaluated every five minutes and copy any new or updated objects from the source bucket to the destination bucket.


質問 # 25
Which is NOT a valid Oracle Cloud Infrastructure (OCI) Virtual Cloud Network (VCN) approach?

  • A. Use OCI tags to tag VCN resources so that all resources follow organizational tagging/naming conventions.
  • B. Ensure not all IP addresses are allocated at once within a VCN or subnet; instead reserve some IP addresses for future use.
  • C. Ensure VCN CIDR prefix overlaps with other VCNs in your tenancy or withyour organizations private IPnetwork ranges.
  • D. Private subnets should ideally have individual route tables to control the flowof traffic within and outsideof VCN.

正解:C

解説:
Explanation
Ensure VCN CIDR prefix overlaps with other VCNs in your tenancy or with your organizations private IP network ranges. The explanation is that a VCN CIDR prefix is the range of IPv4 addresses that can be used within the VCN and its subnets. The VCN CIDR prefix should not overlap with other VCNs in your tenancy or with your organization's private IP network ranges, as this can cause routing conflicts and connectivity issues. You should choose a VCN CIDR prefix that is large enough to accommodate your current and future needs, but not too large to waste IP addresses. You can use any of the private IPv4 address ranges specified in RFC 1918 for your VCN CIDR prefix.


質問 # 26
Which is NOT a valid action within the Oracle Cloud Infrastructure (OCI) Block Volume service?

  • A. Restoring from a volume backup to a larger volume.
  • B. Expanding an existing volume in place with offline resizing.
  • C. Attaching a block volume to an instance in a different availability domain.
  • D. Cloning an existing volume to a new, larger volume.

正解:C

解説:
Explanation
Attaching a block volume to an instance in a different availability domain is not a valid action within the OCI Block Volume service. A block volume can only be attached to an instance in the same availability domain.
The other options are valid actions that can be performed with the Block Volume service. References: [Block Volume Actions]


質問 # 27
Which TWO are key benefits of setting up Site-to-Site VPN on Oracle Cloud Infrastructure (OCI)?

  • A. When setting up Site-to-Site VPN, customers can configure it to use static or dynamic routing (BGP).
  • B. When setting up Site-to-Site VPN, it creates a private connection that provides consistent network experience.
  • C. When setting up Site-to-Site VPN, customers can expect bandwidth above 2 Gbps.
  • D. When setting up Site-to-Site VPN, OCI provisions redundant VPN tunnels.

正解:A、D

解説:
Explanation
When setting up Site-to-Site VPN, customers can configure it to use static or dynamic routing (BGP). When setting up Site-to-Site VPN, OCI provisions redundant VPN tunnels. The explanation is that Site-to-Site VPN is a secure and encrypted connection between your on-premises network and your Virtual Cloud Network (VCN) in OCI over the public internet. When setting up Site-to-Site VPN, you can choose to use static routing or dynamic routing (Border Gateway Protocol or BGP) to exchange routes between your network and OCI.
OCI also provisions two redundant VPN tunnels for each Site-to-Site VPN connection to provide high availability and failover.


質問 # 28
You have an instance running in Oracle Cloud Infrastructure (OCI) that cannot be live-migrated during an infrastructure maintenance event. OCI schedules a maintenance due date within 14 to 16 days and sends you a notification.
What would happen if you choose not to proactively reboot the instance before the scheduled maintenance due date?

  • A. You will receive another notification to reboot within the next 14 days.
  • B. The instance is either reboot-migrated or rebuilt in place for you.
  • C. You will receive another notification to reboot within the next 7 days.
  • D. The instance will get terminated.

正解:B

解説:
If you choose not to proactively reboot the instance before the scheduled maintenance due date, the instance is either reboot-migrated or rebuilt in place for you. Reboot-migration is a process where OCI migrates your instance to a new physical host without changing its configuration or public IP address. Rebuild in place is a process where OCI shuts down your instance, performs maintenance on the physical host, and restarts your instance with the same configuration and public IP address. The other options are not correct. Reference: [Reboot-Migration], [Rebuild in Place]


質問 # 29
Your DevOps team needs to interconnect the on-premises network to the Oracle Cloud Infrastructure (OCI) resources, such as a managed database that resides in a private subnet. They indicate that they have a low budget and their bandwidth requirements are minimal, so you decide that a site-to-site VPN is the best option.
They provide you with their router public IP address. You need to create an object in OCI that represents this router. Which object would you create?

  • A. Customer Premises Equipment (CPE)
  • B. Dynamic Routing Gateway (DRG)
  • C. Internet Gateway
  • D. Bastion Host
  • E. Virtual Network Interface Card (vNIC)
  • F. IPSec Tunnel

正解:A

解説:
Customer Premises Equipment (CPE). The explanation is that CPE is an object in OCI that represents your on-premises router or VPN device that connects to your VCN via a site-to-site VPN. A site-to-site VPN is a secure and encrypted connection between your on-premises network and your VCN over the public internet. To set up a site-to-site VPN, you need to create a CPE object with your router's public IP address and other information, such as vendor and platform. You also need to create a Dynamic Routing Gateway (DRG) object in your VCN and attach it to your VCN. Then, you need to create an IPSec connection between your CPE and DRG, which will create two redundant VPN tunnels for high availability.


質問 # 30
Your DevOps team needs to interconnect the on-premises network to the Oracle Cloud Infrastructure(OCI)resources, such as a managed database that resides in a private subnet. Theyindicate that they have a lowbudget and their bandwidth requirements are minimal, so you decide that a site-to-site VPN is the best option.
They provide you with their router public IP address. You need to create an object in OCI that represents thisrouter. Which object would you create?

  • A. Customer Premises Equipment (CPE)
  • B. Dynamic Routing Gateway (DRG)
  • C. Internet Gateway
  • D. Bastion Host
  • E. Virtual Network Interface Card (vNIC)
  • F. IPSec Tunnel

正解:A

解説:
Explanation
Customer Premises Equipment (CPE). The explanation is that CPE is an object in OCI that represents your on-premises router or VPN device that connects to your VCN via a site-to-site VPN. A site-to-site VPN is a secure and encrypted connection between your on-premises network and your VCN over the public internet.
To set up a site-to-site VPN, you need to create a CPE object with your router's public IP address and other information, such as vendor and platform. You also need to create a Dynamic Routing Gateway (DRG) object in your VCN andattach it to your VCN. Then, you need to create an IPSec connection between your CPE and DRG, which will create two redundant VPN tunnels for high availability.


質問 # 31
You are backing up your on-premises data to the Oracle Cloud Infrastructure (OCI) Object Storage Service.
Your requirements are:
1. Backups need to be retained for at least full 31 days.
2. Data should be accessible immediately if and when needed after the backup.
Which OCI Object Storage tier is suitable for storing the backup to minimize cost?

  • A. Standard tier
  • B. Infrequent Access tier
  • C. Archive tier
  • D. Auto-Tiering tier

正解:B

解説:
Explanation
The explanation is that the Infrequent Access tier is suitable for storing data that is accessed less frequently but requires immediate access when needed. The Infrequent Access tier has lower storage costs than the Standard tier, but higher retrieval costs. The Infrequent Access tier also has a minimum storage duration of 30 days, which means that you will be charged for at least 30 days of storage even if you delete or move the data before that period.


質問 # 32
Which TWO statements about the Oracle Cloud Infrastructure (OCI) File Storage Service are accurate?

  • A. Customer can encrypt data in their file system using their own Vault encryption key.
  • B. Customer can encrypt the communication to a mount target via export options.
  • C. File systems use Oracle-managed keys by default.
  • D. Communication with file systems in a mount target is encrypted via HTTPS.
  • E. Mount targets use Oracle-managed keys by default.

正解:A、C

解説:
File systems use Oracle-managed keys by default. Customer can encrypt data in their file system using their own Vault encryption key. The explanation is that File Storage Service encrypts all data at rest using AES-256 encryption algorithm. By default, File Storage Service uses Oracle-managed keys to encrypt and decrypt data. However, you can also use your own Vault encryption key to encrypt data in your file system. To do so, you need to create a key in Vault and associate it with your file system when you create or update it.


質問 # 33
Which TWO components are optional while creating the Monitoring Query Language (MQL) expressions in the Oracle Cloud Infrastructure (OCI) Monitoring service?

  • A. Interval
  • B. Metric
  • C. Statistic
  • D. Dimensions
  • E. Grouping Function

正解:D、E

解説:
Dimensions and Grouping Function are two optional components while creating the Monitoring Query Language (MQL) expressions in the OCI Monitoring service. Dimensions are key-value pairs that provide additional information about a metric, such as region, compartment, or resource type. Grouping Function is a function that aggregates metric data across one or more dimensions, such as sum, count, or average. The other options are required components for MQL expressions. Reference: [Dimensions], [Grouping Function]


質問 # 34
What should be created before provisioning an Oracle Cloud Infrastructure (OCI) DB System?

  • A. Bucket in Object Storage
  • B. Virtual Cloud Network
  • C. Compartment
  • D. Compute Instance

正解:B

解説:
The explanation is that a Virtual Cloud Network (VCN) is a software-defined network that you set up in OCI to connect your cloud resources, such as compute instances and databases. A VCN provides you with complete control over your network environment, including selecting your own IP address range, creating subnets, route tables, gateways, security lists, etc. You need to create a VCN before provisioning an OCI DB System, as you need to specify which subnet in your VCN you want to launch your DB System in.


質問 # 35
Which of the following statements is true about cloning a volume in the Oracle Cloud Infrastructure (OCI) Block Volume service?

  • A. Creating a clone takes longer than creating a backup of a volume.
  • B. You need to detach a volume before cloning it.
  • C. You can clone a volume to another region.
  • D. You can change the block volume size when cloning a volume.

正解:D

解説:
You can change the block volume size when cloning a volume. The explanation is that cloning a volume is a way of creating an exact copy of an existing volume without creating a backup first. Cloning a volume is faster and cheaper than creating a backup and restoring it to a new volume. When you clone a volume, you can change the block volume size, performance, encryption settings, and tags of the new volume. You do not need to detach a volume before cloning it, as cloning does not affect the source volume or its attachments. You cannot clone a volume to another region, as cloning only works within the same region and availability domain. Creating a clone usually takes less time than creating a backup of a volume, as cloning does not involve transferring data to Object Storage.


質問 # 36
Which TWO statements are TRUE about Private IP addresses in Oracle Cloud Infrastructure (OCI)?

  • A. By default, the primary VNIC of an instance in a subnet has one primary private IP address and one secondary private IP address.
  • B. Each VNIC can only have one private IP address.
  • C. A private IP can have an optional public IP assigned to it if it resides in a public subnet.
  • D. By default, the primary VNIC of an instance in a subnet has one primary private IP address.

正解:C、D

解説:
By default, the primary VNIC of an instance in a subnet has one primary private IP address. A private IP can have an optional public IP assigned to it if it resides in a public subnet. The explanation is that a private IP address is an IPv4 address that is assigned to a VNIC and belongs to the CIDR block of the VCN or subnet. By default, the primary VNIC of an instance in a subnet has one primary private IP address, which is automatically assigned by OCI and cannot be changed. However, you can also assign secondary private IP addresses to a VNIC, either manually or automatically, up to a maximum of 31 per VNIC. A private IP address can have an optional public IP address assigned to it, which allows the instance to communicate with the internet. A public IP address can be either ephemeral or reserved, depending on whether you want to keep it after stopping or terminating the instance. A private IP address can only have a public IP address assigned to it if it resides in a public subnet, which means that the subnet's route table has a route rule that directs traffic to the internet gateway.


質問 # 37
Which of the following statements is true about cloning a volume in the Oracle Cloud Infrastructure (OCI) BlockVolume service?

  • A. Creating a clone takes longer than creating a backup of a volume.
  • B. You need to detach a volume before cloning it.
  • C. You can clone a volume to another region.
  • D. You can change the block volume size when cloning a volume.

正解:D

解説:
Explanation
You can change the block volume size when cloning a volume. The explanation is that cloning a volume is a way of creating an exact copy of an existing volume without creating a backup first. Cloning a volume is faster and cheaper than creating a backup and restoring it to a new volume. When you clone a volume, you can change the block volume size, performance, encryption settings, and tags of the new volume. You do not need to detach a volume before cloning it, as cloning does not affect the source volume or its attachments. You cannot clone a volume to another region, as cloning only works within the same region and availability domain. Creating a clone usually takes less time than creating a backup of a volume, as cloning does not involve transferring data to Object Storage.


質問 # 38
......

リアル問題集Oracle 1z0-1072-23試験問題 [更新されたのは2023年]:https://www.jpntest.com/shiken/1z0-1072-23-mondaishu

無料1z0-1072-23試験問題集合格させるお手軽に試験合格:https://drive.google.com/open?id=1zzG7VCn2y01ZYz6xdxZajODKfKNADCxa

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡