Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Oracle Oracle Cloud Infrastructure 1z0-1084-26 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

Your organization is deploying a high-performance distributed deep learning training workload that requires GPU-enabled bare metal Compute instances connected through an ultra-low-latency Oracle Cloud Infrastructure (OCI) RDMA cluster network. To maximize processing efficiency and comply with strict corporate OS requirements, your team must use a custom, pre-hardened Oracle Linux operating system image that is not supported by default node pools. The containerized training jobs must be orchestrated and scheduled using your existing Container Engine for Kubernetes (OKE) control plane.

Which worker node deployment model must you implement?

Options:

A.

Managed Node Pools


B.

Virtual Node Pools


C.

Self-Managed Nodes


D.

Instance-Pool Nodes


Expert Solution
Questions # 32:

Which statement about microservices is FALSE?

Options:

A.

They are typically designed around business capabilities.


B.

It is fairly common for them to communicate with HTTP.


C.

Multiple microservices can run in one process.


D.

They are independently deployable.


Expert Solution
Questions # 33:

Your team has deployed a high-throughput order processing microservice that consumes messages from an OCI Stream with 8 partitions. To handle peak operational hours, you have scaled out your deployment to run 12 identical microservice consumer instances under a single named consumer group. During execution, you notice that 4 of the 12 consumer instances remain completely idle and are not assigned any stream data. Which OCI Streaming architectural rule explains this behavior?

Options:

A.

The instances are idling because a single consumer group cannot support more than 8 active consumer instances regardless of partition count.


B.

The instances are idling because each partition in a stream can be consumed by at most one consumer instance within a single consumer group.


C.

The instances are idling because you must configure OCI Service Connector Hub to explicitly map each of the 12 consumer instances to its own partition.


D.

The instances are idling because OCI Streaming requires a dedicated stream pool for every four active consumer instances in a consumer group.


Expert Solution
Questions # 34:

Your organization mandates that all containerized workloads deployed to Oracle Cloud Infrastructure (OCI) Container Engine for Kubernetes (OKE) must utilize Kubernetes NetworkPolicy resources, such as Calico, to enforce strict micro-segmentation of traffic. You have deployed these workloads to an enhanced OKE cluster using virtual node pools to minimize infrastructure maintenance. During testing, you discover that the Calico installation fails because NetworkPolicy resources and third-party CNI policy integrations are completely unsupported on this specific node configuration. How should you resolve this security implementation challenge while continuing to use VCN-Native Pod Networking?

Options:

A.

Reconfigure your virtual node pools to use the Flannel overlay plugin, which natively implements network policy isolation on virtual nodes.


B.

Upgrade your OKE virtual nodes to Kubernetes version 1.30 or higher, which enables native, agentless NetworkPolicy support on virtual nodes.


C.

Define an OCI IAM policy that grants the OKE workload identity access to manage network security lists at the virtual node level.


D.

Migrate your workloads to managed node pools within the OKE cluster, where VCN-Native Pod Networking supports Calico for NetworkPolicy enforcement.


Expert Solution
Questions # 35:

Which open source engine is used by Oracle Cloud Infrastructure (OCI) to power Oracle Functions?

Options:

A.

Knative


B.

Kubeless


C.

Apache OpenWhisk


D.

Fn Project


Expert Solution
Questions # 36:

What is the maximum allowable size for a secret bundle stored in the Oracle Cloud Infrastructure (OCI) Vault service?

Options:

A.

10 KB


B.

25 KB


C.

50 KB


D.

100 KB


Expert Solution
Questions # 37:

You have been asked to update an OKE cluster to a network configuration that has the least attack surface while the deployed applications are still directly available for access from the Internet. Which is a valid OKE cluster network configuration that meets this requirement? (Choose the best answer.)

Options:

A.

Private subnets for nodes, the Kubemetes API endpoint, and load balancers


B.

Private subnets for nodes; public subnets for the Kubemetes API endpoint and load balancers


C.

Private subnets for nodes and the Kubemetes API endpoint; public subnets for load balancers


D.

Private subnet for the Kubemetes API endpoint; public subnets for nodes and load balancers


Expert Solution
Questions # 38:

To enforce mutual TLS (mTLS) authentication for clients of your microservices, your team has chosen to leverage the Oracle Cloud Infrastructure (OCI) API Gateway service to create new API Deployments that will direct requests to your microservices. Which is NOT valid regarding the mTLS options in OCI API Gateway?

Options:

A.

Custom CA or custom CA bundles can be added to your gateway ' s trust store ONLY if they already exist in the OCI Certificates service.


B.

Adding a custom certificate authority (CA) or custom CA bundle to your gateway ' s trust store for mTLS is optional unless you need to reject certificates that do not contain particular values (such as a domain name).


C.

The mTLS request policy can only be enabled at the API deployment specification level, which then applies globally to ALL routes in that deployment.


D.

Once the mTLS request policy is enabled, ALL requests with valid certificates are routed to the backend unless you have defined one or more particular values (such as a domain name).


Expert Solution
Questions # 39:

Which of the following step is NOT required for setting up the Container Engine for Kubernetes (OKE) cluster access using a local installation of kubectl?

Options:

A.

Generate Auth token from the OCI console to access the OKE cluster using kubectl.


B.

Install and configure the Oracle Cloud Infrastructure (OCI) CLI.


C.

Set up the kubeconfig file.


D.

Generate an API signing key pair (if you do not already have one) and upload the public key of the API signing key pair.


Expert Solution
Questions # 40:

Which statement is NOT valid regarding the OCI Vulnerability Scanning service (VSS) for container images stored in Oracle Cloud Infrastructure Registry (OCIR)?

Options:

A.

A single container repository can be assigned to multiple scan targets in OCI Vulnerability Scanning to enforce different scan recipes.


B.

When a container scan target is created, the service scans a specified initial number of images, one by default, in the target repositories.


C.

Vulnerability reports for the scanned images are saved in the compartment containing the scan target, rather than the repository compartment.


D.

To run container image scans, you must explicitly grant the OCI Vulnerability Scanning service IAM permission to pull images from the registry.


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions