1Z0-1067-21 Free Update With 100% Exam Passing Guarantee [2021]
[Dec-2021] Verified Oracle Exam Dumps with 1Z0-1067-21 Exam Study Guide
NEW QUESTION 31
Your company has restructured its HR departments. As part of this change, you also need to re-organize compartments within Oracle Cloud Infrastructure (OCI) to align them to the company's new organizational structure. The following change is required:
Compartment Team_x needs to be moved under a new parent compartment, Project_B The tenancy has the following policies defined for compartments Project_A and Project_B: Policy1: Allow group G1 to manage instance-family in compartment HR:Project_A Policy2: Allow group G2 to manage instance-family in compartment HR:Project_B Which two statements describe the impacts after the compartment Team_x is moved? (Choose two.)
- A. Group G2 can now manage instance-families in compartment Project_A but not in compartment Team_x
- B. Group G2 can now manage instance-families in compartment Project_B and compartment Team_X
- C. Group G1 can now manage instance-families in compartment Project_A but not in compartment Team_x
- D. Group G2 can now manage instance-families in compartment Project_B, compartment Project_A and compartment Team_X
- E. Group G1 can now manage instance-families in compartment Project_A, compartment Project_B and compartment Team_X
Answer: B,C
NEW QUESTION 32
You have been monitoring your company's applications running in Oracle Cloud Infrastructure (OCI) and notice that the application is using OCI Traffic Management service. This service uses a traffic steering policy to distribute the DNS traffic based on subnet addresses in a rule set.
Which steering policy is in use in this particular case? (Choose the best answer.)
- A. ASN steering policy
- B. IP Prefix steering
- C. Geolocation steering
- D. Load Balancing policy
Answer: A
NEW QUESTION 33
An insurance company has contracted you to help automate their application business continuity plan. They have the application running in eu-frankfurt-1 as the primary site and uk-london-1 as a disaster recovery site. Normally they have a DNS A record associated with the IP address of the primary endpoint in eu-frankfurt-1. In the event of a disaster, they use OCI DNS Zone Management to update the A record and replace it with the IP address of the endpoint in uk-londond-1.
How can you automate the failover process? (Choose the best answer.)
- A. Provision a Load Balancer in Frankfurt and associate it with the A record in DNS. Create a backend set with backend servers from both eu-frankfurt-1 and uk-london-1 regions.
- B. Create a Health Check that evaluates both regional endpoints. Create a Traffic Management Steering policy with Failover type and associate it with the Health Check.
- C. Create a Traffic Management Steering policy with Load Balancer type and add both eu-frankfurt-1 and uk- london-1 endpoints. Attach the Traffic Management Steering policy to the A record.
- D. Create a Traffic Management Steering policy and attach it to a backend servers from both eu-frankfurt-1 and uk-london-1 regions.
Answer: C
NEW QUESTION 34
You set up a bastion host in your VCN to only allow your IP address (140.19.2.140) to establish SSH connections to your Compute Instances that are deployed in a private subnet. The Compute Instances have an attached Network Security Group with a Source Type: Network Security Group (NSG), Source NSG: NSG-050504. To secure the bastion host, you added the following ingress rules to its Network Security Group:
However, after checking the bastion host logs, you discovered that there are IP addresses other than your own that can access your bastion host.
What is the root cause of this issue? (Choose the best answer.)
- A. A netmask of /32 allows all IP address in the 140.19.2.0 network, other than your IP 140.19.2.140
- B. All compute instances associated with NSG-050504 are also able to connect to the bastion host.
- C. The Security List allows access to all IP address which overrides the Network Security Group ingress rules.
- D. The port 22 provides unrestricted access to 140.19.2.140 and to other IP address.
Answer: B
NEW QUESTION 35
You created an Oracle Linux compute instance through the Oracle Cloud Infrastructure (OCI) management console then immediately realize you forgot to add an SSH key file. You notice that OCI compute service provides instance console connections that supports adding SSH keys for a running instance. Hence, you created the console connection for your Linux server and activated it using the connection string provided.
However, now you get prompted for a username and password to login.
What option should you recommend to add the SSH key to your running instance, while minimizing the administrative overhead? (Choose the best answer.)
- A. You need to modify the serial console connection string to include the identity file flag, -i to specify the SSH key to use.
- B. You need to configure the boot loader to use ttyS0 as a console terminal on the VM.
- C. You need to terminate the running instance and recreate it by providing the SSH key file.
- D. You need to reboot the instance from the console, boot into the bash shell in maintenance mode, and add SSH keys for the opc user.
Answer: A
Explanation:
Explanation/Reference: https://docs.oracle.com/en-us/iaas/Content/Compute/References/serialconsole.htm
NEW QUESTION 36
You are working as a Cloud Operations Administrator for your company. They have different Oracle Cloud Infrastructure (OCI) tenancies for development and production workloads. Each tenancy has resources in two regions - uk-london-1 and eu-frankfurt-1. You are asked to manage all resources and to automate all the tasks using OCI Command Line Interface (CLI).
Which is the most efficient method to manage multiple environments using OCI CLI? (Choose the best answer.)
- A. Use different bash terminals for each environment.
- B. Use OCI CLI profiles to create multiple sets of credentials in your config file, and reference the appropriate profile at runtime.
- C. Run oci setup config to create new credentials for each environment every time you want to access the environment.
- D. Create environment variables for the sets of credentials that align to each combination of tenancy, region, and environment.
Answer: D
NEW QUESTION 37
Which two statements are TRUE about Object Storage data security and encryption in Oracle Cloud Infrastructure (OCI)? (Choose two.)
- A. A VPN connection to OCI is required to ensure secure data transfer to an object storage bucket.
- B. Data needs to be decrypted on the client side before retrieving it.
- C. All traffic to and from Object Storage service is encrypted using TLS.
- D. Client-side encryption is managed by the customer.
- E. OCI Vault Management is used by default to provide data security.
Answer: C,D
NEW QUESTION 38
You are using the Oracle Cloud Infrastructure Command Line Interface to launch a Linux virtual machine. You enter the following command (with correct values for all parameters):
The command fails.
Which is NOT a valid parameter in this command? (Choose the best answer.)
- A. - -image-id <image_id>
- B. - -shape "<shape_name>"
- C. -t <tenancy_id>
- D. - -subnet-id <subnet_id>
- E. -c <compartment_id>
Answer: C
NEW QUESTION 39
You have been asked to investigate a potential security risk on your company's Oracle Cloud Infrastructure (OCI) tenancy. You decide to start by looking through the audit logs for suspicious activity.
How can you retrieve the audit logs using the OCI Command Line Interface (CLI)? (Choose the best answer.)
- A. oci audit event list --start-time $start-time --end-time $end-time --tenancy-id
- B. oci audit event list --start-time $start-time --compartment-id $compartment-id
- C. oci audit event list --start-time $start-time --end-time $end-time -- compartment-id $compartment-id
- D. oci audit event list --end-time $end-time --compartment-id $compartment-id
Answer: C
Explanation:
$tenancy-id
NEW QUESTION 40
You are asked to deploy a new application that has been designed to scale horizontally. The business stakeholders have asked that the application be deployed in us-phoenix-1.
Normal usage requires 2 OCPUs. You expect to have few spikes during the week, that will require up to 4 OCPUs, and a major usage uptick at the end of each month that will require 8 OCPUs.
What is the most cost-effective approach to implement a highly available and scalable solution? (Choose the best answer.)
- A. Create an instance with 1 OCPU shape. Use a CLI script to clone it when more resources are needed.
- B. Create an instance pool with a VM.Standard2.2 shape instance configuration. Setup the autoscaling configuration to use 2 availability domains and have a minimum of 2 instances, to handle the weekly spikes, and a maximum of 4 instances.
- C. Create an instance with 1 OCPU shape. Use the Resize Instance action to scale up to a larger shape when more resources are needed.
- D. Create an instance pool with a VM.Standard2.1 shape instance configuration. Setup the autoscaling configuration to use 2 availability domains and have a minimum of 2 instances and a maximum of 8 instances.
Answer: B
NEW QUESTION 41
You have been asked to ensure that in-transit communication between an Oracle Cloud Infrastructure (OCI) compute instance and an on-premises server (192.168.10.10/32) is encrypted. The instances communicate using HTTP. The OCI Virtual Cloud Network (VCN) is connected to the on-premises network by two separate connections: a Dynamic IPsec VPN tunnel and a FastConnect virtual circuit. No static configuration has been added.
What solution should you recommend? (Choose the best answer.)
- A. The instances will communicate by default over the FastConnect private virtual circuit, which ensures data is encrypted in-transit.
- B. The instances will communicate by default over IPsec VPN, which ensures data is encrypted in-transit.
- C. Advertise a 192.168.10.10/32 router over the FastConnect.
- D. Advertise a 192.168.10.10/32 route over the VPN.
Answer: A
NEW QUESTION 42
You have recently been asked to take over management of your company's infrastructure provisioning efforts, utilizing Terraform v0.12 to provision and manage infrastructure resources in Oracle Cloud Infrastructure (OCI).
For the past few days the development environments have been failing to provision. Terraform returns the following error:
You locate the related code block in the Terraform config and find the following:
Which correction should you make to solve this issue? (Choose the best answer.)
- A. Modify line 15 to be the following:
tcp_options {
min = "22"
max = "22"
} - B. Replace the curly braces '{ }' in lines 11 and 16 with square braces '[ ]'
- C. Modify line 15 to be the following:
tcp_options = {min = "22", max = "22") - D. Place a command at the end of line 16
Answer: C
NEW QUESTION 43
You run a large global application with 90% of customers based in the US and Canad a. You want to be able to test a new feature and allow a small percentage of users to access the new version of your application.
What Oracle Cloud Infrastructure Traffic Management steering policy should you utilize? (Choose the best answer.)
- A. Geolocation steering
- B. Load Balancer
- C. ASN steering
- D. IP Prefix steering
Answer: A
NEW QUESTION 44
Multiple teams are sharing a tenancy in Oracle Cloud Infrastructure (OCI). You are asked to figure out an appropriate method to manage OCI costs.
Which is NOT a valid technique to accurately attribute costs to resources used by each team? (Choose the best answer.)
- A. Create separate compartment for each team. Use the OCI cost analysis tools to filter costs by compartment.
- B. Create an Identity and Access Management (IAM) group for each team. Create an OCI budget for each group to track spending.
- C. Define and use tags for resources used by each team. Analyze usage data from the OCI Usage Report which has detailed information about resources and tags.
- D. Create a Cost-Tracking tag. Apply this tag to all resources with team information. Use the OCI cost analysis tools to filter costs by tags.
Answer: B
NEW QUESTION 45
You have a Linux compute instance located in a public subnet in a VCN which hosts a web application. The security list attached to subnet containing the compute instance has the following stateful ingress rule.
The Route table attached to the Public subnet is shown below. You can establish an SSH connection into the compute instance from the internet. However, you are not able to connect to the web server using your web browser.
Which step will resolve the issue? (Choose the best answer.)
- A. In the route table, add a rule for your default traffic to be routed to service gateway.
- B. In the security list, remove the ssh rule.
- C. In the route table, add a rule for your default traffic to be routed to NAT gateway.
- D. In the security list, add an ingress rule for port 80 (http).
Answer: A
NEW QUESTION 46
You have created a geolocation steering policy in the Oracle Cloud Infrastructure (OCI) Traffic Management service, with this configuration:
What happens to requests that originate in Africa? (Choose the best answer.)
- A. The traffic will be dropped.
- B. The traffic will be forwarded at the same time to both Pool 1 and Pool 2.
- C. The traffic will be forwarded randomly to any of the pools mentioned in the rules.
- D. The traffic will be forwarded to Pool 1. If Pool 1 is not available, then it will be forwarded to Pool 2.
Answer: D
NEW QUESTION 47
You have received an email from your manager to provision new resources on Oracle Cloud Infrastructure (OCI). When researching OCI, you determined that you should use OCI Resource Manager. Since this is a task that will be done multiple times for development, test, and production. You will need to create a command that can be re-used.
Which CLI command can be used in this situation? (Choose the best answer.)
- A. oci resource-manager stack update --compartment-id <compartment_OCID> \
--config-source prod.zip --variables file://variables.json \
--display-name "Production stack build" \
--description Creating new Production environment - B. oci resource-manager stack update --tenancy-id <tenancy_OCID> \
--config-source prod.zip --variables file://variables.json \
--display-name "Production stack build" \
--description Creating new Production environment - C. oci resource-manager stack create --compartment-id <compartment_OCID> \
--config-source prod.zip --variables file://variables.json \
--display-name Production stack build \
--description Creating new Production environment - D. oci resource-manager stack create --tenancy-id <tenancy_OCID> \
--config-source prod.zip --variables file://variables.json \
--display-name Production stack build \
--description Creating new Production environment
Answer: C
NEW QUESTION 48
Which statement about Oracle Cloud Infrastructure paravirtualized block volume attachments is TRUE? (Choose the best answer.)
- A. Paravirtualized volumes may reduce the maximum IOPS performance for larger block volumes.
- B. Paravirtualized is required to manage iSCSI configuration for virtual machine instances.
- C. Paravirtualized volumes become immediately available on bare metal compute instances.
- D. Paravirtualization utilizes the internal storage stack of compute instance OS and network hardware virtualization to access block volumes.
Answer: A
NEW QUESTION 49
You have been contracted by a local e-commerce company to assist with enhancing their online shopping application. The application is currently deployed in a single Oracle Cloud Infrastructure (OCI) region. The application utilizes a public load balancer, application servers in a private subnet, and a database in a separate, private subnet.
The company would like to deploy another set of similar infrastructure in a different OCI region that will act as standby site. In the event of a failure at the primary site, all customers should be routed to the failover site automatically.
After deploying the additional infrastructure within the second region, how should you configure automated failover requirements? (Choose the best answer.)
- A. Create a failover policy in the Traffic Management service. Set the IP address of the public load balancer for the primary site in answer pool 1. Set the IP address of the public load balancer for the secondary site in answer pool 2. Define a health check to monitor both sites.
- B. Deploy a new load balancer in the primary region. Create one backend set for the primary application servers and a second backend set for the standby application servers. Create a listener for the primary backend set with a timeout of 3 minutes. Create a listener for the secondary backend set with a timeout of 10 minutes.
- C. Create a load balancer policy in the Traffic Management service. Configure one answer for each site. Set the answer for the primary site with a weight of 10 and the answer for the secondary site with a weight of 100.
- D. Create a new A record in DNS that points to the public load balancer at the secondary site. Create a CNAME for the sub-domain failover that will resolve to the new A record. Inform customers to prepend the website URL with failover if the primary site is unavailable.
Answer: B
NEW QUESTION 50
The boot volume on your Oracle Linux instance has run out of space. Your application has crashed due to a lack of swap space, forcing you to increase the size of the boot volume.
Which step should NOT be included in the process used to solve the issue? (Choose the best answer.)
- A. Reattach the boot volume and restart the instance.
- B. Create a RAID 0 configuration to extend the boot volume file system onto another block volume.
- C. Stop the instance and detach the boot volume.
- D. Attach the resized boot volume to a second instance as a data volume; extend the partition and grow the file system in the resized boot volume.
- E. Resize the boot volume by specifying a larger value than the boot volume's current size.
Answer: D
NEW QUESTION 51
A developer has created a file system in Oracle Cloud Infrastructure (OCI) File Storage service. She launches an Oracle Linux compute instance and successfully mounts the file system from the instance.
She then tries writing to the file system from the compute instance using the following command:
touch /mnt/yourmountpoint/helloworld
But gets an error message:
touch: cannot touch '/mnt/yourmountpoint/helloworrld': Permission denied Which is a reason for this error? (Choose the best answer.)
- A. 'touch' command is not available in Oracle Linux by default.
- B. Service limits or quota for file system writes have been breached.
- C. User is not part of any OCI Identity and Access Management group with write permissions to File Storage service.
- D. User is connecting as the default Oracle Linux user 'opc' instead of 'root' user.
Answer: C
NEW QUESTION 52
......
Oracle 1Z0-1067-21 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
Authentic Best resources for 1Z0-1067-21 Online Practice Exam: https://www.exam-killer.com/1Z0-1067-21-valid-questions.html

