Pass the Oracle Oracle Cloud Infrastructure 1z0-1124-25 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Your company is migrating an on-premises application to OCI. The application requires direct, low-latency access to an on-premises Microsoft SQL Server database. You’ve established a FastConnect connection between your on-premises network and an OCI VCN via a Dynamic Routing Gateway(DRG). You want to access this database from the OCI VCN. Which type of endpoint, in conjunction with appropriate routing, should you use to facilitate this connection?

Options:

A.

An Internet Gateway with a public endpoint on the SQL Server.


B.

A Service Gateway configured to access the on-premises SQL Server.


C.

No specific OCI endpoint is required. The on-premises SQL Server is accessed directly through the DRG and appropriate routing.


D.

A Private Endpoint within the VCN configured to connect to the private IP address of the on-premises SQL Server.


Questions # 22:

Your company is migrating several applications to OCI and requires a highly available and resilient VPN connection between your on-premises network and OCI. You need to ensure that if one VPN tunnel fails, traffic automatically fails over to a backup tunnel with minimal disruption. Which configuration would BEST achieve high availability and automatic failover for your OCI Site-to-Site VPN connection?

Options:

A.

Configure a single VPN connection with a single tunnel and rely on the underlying OCI infrastructure for automatic failover.


B.

Configure a single VPN connection with two tunnels, ensuring that both tunnels use different CPE IP addresses on the on-premises side.


C.

Configure two separate VPN connections, each with a single tunnel, pointing to different CPE IP addresses on the on-premises side. Advertise the same prefixes over both VPN connections using BGP.


D.

Configure a single VPN connection with two tunnels using the same CPE IP address.


Questions # 23:

You are implementing IPSec over FastConnect to connect to a third-party network that is also connected to OCI via FastConnect. Your company requires a high level of security and isolation between your network and the third-party’s network. Which of the following is the MOST secure approach to ensure network isolation when implementing IPSec over FastConnect in this scenario?

Options:

A.

Implement IPSec tunnels between your on-premises network and the third-party’s on-premises network, bypassing OCI.


B.

Use OCI Network Security Groups (NSGs) or security lists to strictly control traffic between your VCN and the third-party’s VCN.


C.

Utilize a third-party virtual firewall appliance deployed in OCI and configure IPSec tunnels through the firewall to both your on-premises network and the third-party’s network.


D.

Enable flow logs to monitor the traffic that is transmitted.


Questions # 24:

Your company needs to establish a secure connection between your on-premises network and OCI for a pilot project. The project has a limited budget and requires a quick setup, but also demands that the connection is encrypted. The long-term plan involves migrating to FastConnect, but that will take several months. Which OCI VPN solution would be most suitable for this short-term, budget-conscious, and security-aware scenario?

Options:

A.

Use a Dynamic Routing Gateway (DRG) with a Site-to-Site VPN connection configured using static routing.


B.

Deploy a third-party virtual appliance VPN solution from the OCI Marketplace within a public subnet and configure a VPN connection to your on-premises network.


C.

Use a Service Gateway to connect to a third-party VPN service available on the internet.


D.

Use a Dynamic Routing Gateway (DRG) with a Site-to-Site VPN connection configured using dynamic routing with BGP.


Questions # 25:

You are designing a highly available and scalable e-commerce application on OCI. The application requires load balancing for both HTTP/HTTPS traffic and TCP-based microservices communication. You need a solution that provides advanced traffic management capabilities, including content-based routing and path-based routing, and can also protect against common web exploits. Which OCI load balancing offering is the most suitable for this scenario, considering the need for web application firewall (WAF) integration?

Options:

A.

Network Load Balancer


B.

Application Load Balancer


C.

Flexible Load Balancer


D.

Load Balancing as a Service (LBaaS)


Questions # 26:

As a network security engineer, you are tasked with designing a highly secure architecture for a financial application running on OCI. You have deployed a Network Firewall to protect the application’s VCN. Due to regulatory compliance requirements, you need to ensure that no direct internet access is allowed to any compute instance within the application’s private subnet, even if it is misconfigured. You need to block all outbound traffic to the internet. Which Network Firewall rule action best accomplishes this goal?

Options:

A.

ALLOW with Destination IP address set to 0.0.0.0/0.


B.

DROP with Destination IP address set to the NAT Gateway IP address.


C.

REJECT with Destination IP address set to 0.0.0.0/0.


D.

ALLOW with Destination IP address set to the Service Gateway IP address.


Questions # 27:

You are designing a highly available web application on OCI. The application needs to be accessible globally with traffic being routed to the nearest region based on user location. Additionally, you need to implement sophisticated traffic management policies, such as A/B testing and weighted traffic distribution based on application version. You also require protection against DDoS attacks. Which OCI load balancing solution is best suited for these requirements?

Options:

A.

Regional Load Balancer


B.

Network Load Balancer


C.

Global Load Balancer with Traffic Management Steering Policies


D.

Flexible Load Balancer


Questions # 28:

You are tasked with setting up a secure connection from an OCI Compute instance running in a private subnet to a third-party API that is only accessible over the internet via a static public IP address. Your company policy prohibits exposing the compute instance directly to the internet. Which combination of VCN resources BEST facilitates this secure outbound connection to the third-party API?

Options:

A.

An Internet Gateway with a security list allowing outbound traffic to the third-party API’s IP address.


B.

A NAT Gateway and a security list allowing outbound traffic to the third-party API’s IP address.


C.

A Service Gateway configured with a Service CIDR label that includes the third-party API’s IP address.


D.

A Dynamic Routing Gateway (DRG) connected to a FastConnect circuit, with routes configured to direct traffic to the third-party API’s IP address.


Questions # 29:

In a multi-tier application architecture with separate public and private subnets, where should an OCI Bastion host be placed to provide secure access to resources in the private subnets without exposing them to the internet?

Options:

A.

Directly in the private subnet.


B.

In a dedicated public subnet specifically for Bastion hosts.


C.

In a separate VCN peered with the application VCN.


D.

Behind an Internet Gateway in the public subnet.


Questions # 30:

You are configuring a FastConnect connection between your on-premises network and OCI. You need to establish a BGP (Border Gateway Protocol) session to exchange routing information. You want to use private peering to securely connect to your private resources within OCI. What are the MINIMUM requirements for configuring BGP for private peering over FastConnect?

Options:

A.

A public AS number and a valid ASN for the OCI side.


B.

A private AS number for the on-premises side and a valid ASN for the OCI side.


C.

A public IP address range for BGP peering on the on-premises side and OCI side and an established DRG.


D.

A valid ASN for the on-premises side and the OCI side and a non-overlapping IP address range for BGP peering on both the on-premises and OCI side.


Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions