Oracle 1Z0-1067-26 Certification Sample Questions and Answers

1Z0-1067-26 PDF, 1Z0-1067-26 Dumps PDF Free Download, 1Z0-1067-26 Latest Dumps Free PDF, Cloud Infrastructure Cloud Ops Professional PDF DumpsThe Oracle Cloud Infrastructure Cloud Ops Professional (1Z0-1067-26) Sample Question Set is designed to help you prepare for the Oracle Cloud Infrastructure Certified Cloud Ops Professional certification exam. To become familiar with the actual Oracle Certification exam environment, we suggest you try our Sample Oracle 1Z0-1067-26 Certification Practice Exam.

This Oracle Cloud Infrastructure Cloud Ops Professional certification sample practice test and sample question set are designed for evaluation purposes only. If you want to test your Oracle 1Z0-1067-26 knowledge to identify your areas of improvement and get familiar with the actual exam format, we suggest you prepare with the Premium Oracle Cloud Infrastructure Certified Cloud Ops Professional Certification Practice Exam. Our team of Oracle Cloud Infrastructure experts has designed Questions-Answers for this premium practice exam by collecting inputs from recently certified candidates. Our premium Oracle 1Z0-1067-26 certification practice exam will boost your confidence as well as your actual Oracle Cloud Infrastructure Cloud Ops Professional exam result.

Oracle 1Z0-1067-26 Sample Questions:

01. Block Volume backup charges for a production compartment have grown every month for a year. The volumes use a backup policy with long retention, although the business now requires restore points for only a short window. In addition, operators take an on-demand backup before each monthly patch cycle, and none of those backups has ever been removed.
Which two actions reduce backup storage cost while still meeting the restore requirement?
(Choose two.)
a) Delete the on-demand patch backups that are older than the required restore window
b) Copy the volume backups to a second region, and delete them from the original region
c) Enable detached volume auto-tune on the source volumes to lower their backup cost
d) Move the volume backups into Archive storage with an Object Storage lifecycle rule
e) Assign a backup policy whose retention matches the required restore window
 
02. To cut cost, an operations team stopped every VM instance in a development compartment three months ago. All instances use flexible standard shapes, and each has a boot volume plus one attached block volume. Cost Analysis for the compartment, grouped by service, shows compute charges fell to zero after the instances stopped, but Block Volume charges have stayed at the same level since.
What explains the remaining charges?
a) Boot volumes and attached block volumes are still billed, even while their instances are stopped
b) Stopping an instance raises its attached volumes to a higher performance level
c) Stopped instances automatically convert their boot volumes and data volumes into billed backups
d) Block Volume bills each month at the peak performance level that the volume reached
 
03. Compartment Projects contains the child compartments ProjA and ProjB. So that the ProjA leads can maintain their own team's access, a tenancy administrator attaches this statement at the root compartment:
Allow group ProjALeads to manage policies in compartment Projects:ProjA
A security reviewer asks what this delegation actually allows. Which statement is accurate?
a) ProjALeads can attach policies in ProjA that grant any group access anywhere in the tenancy, including ProjB
b) ProjALeads can grant any group, their own included, any access within ProjA and its child compartments
c) ProjALeads can edit just the policies they created, and cannot grant access to groups they are not members of
d) ProjALeads can also edit the root compartment policy that granted this delegation
 
04. An autoscaled instance pool launches Oracle Linux instances from an instance configuration whose launch details include cloud-config user data. The team has revised the cloud-config to install an additional monitoring package. Every instance the pool launches from now on must run the revised cloud-config, and running instances will be replaced gradually through scale-in and scale-out.
Which two actions meet this requirement?
(Choose two.)
a) Edit the user data in the launch details of the pool's current instance configuration
b) Update the metadata of each running pool instance so that it carries the revised user data
c) Run cloud-init clean on one pool instance and capture a custom image from it
d) Create a new instance configuration whose launch details carry the revised cloud-config user data
e) Update the instance pool so it references the new instance configuration
 
05. Functions deployed in the Etl compartment must write objects to a bucket by using resource principal authentication. Compute instances in Etl, and functions in every other compartment, must not receive the bucket policy, and no other resource type in the Etl compartment may receive it either.
Which matching rule should the dynamic group named in the bucket policy use?
a) ALL {resource.type = 'fnfunc', resource.compartment.id = '<Tenancy_OCID>'}
b) resource.compartment.id = '<Etl_OCID>'
c) ALL {instance.compartment.id = '<Etl_OCID>', tag.Etl.Role.value = 'loader', tag.Etl.Tier.value = 'batch'}
d) ALL {resource.type = 'fnfunc', resource.compartment.id = '<Etl_OCID>'}
 
06. A Resource Manager stack creates an Oracle Linux instance in a private subnet. A remote-exec provisioner then connects over SSH to the instance's private IP address to install an agent. The apply job creates the instance but fails when the provisioner's SSH connection times out. Company policy forbids public IP addresses on the instance.
What should be added to the stack?
a) A local-exec provisioner that runs the install commands from the Resource Manager job instead
b) A longer timeout in the provisioner's connection block, retrying the SSH connection until it succeeds
c) A Resource Manager private endpoint in the VCN, with the connection host set to its reachable IP
d) An internet gateway route in the private subnet so the job can reach the private IP
 
07. On an Oracle Linux instance, a cloud-config document's runcmd output looks as expected, but a file declared under write_files was never created. You want to see how cloud-init itself processed each module, including any warnings it logged about entries in the user data.
Which log should you read on the instance?
a) The console history captured for the instance from the Console
b) /var/log/cloud-init.log on the instance
c) The work request created for the instance launch
d) /var/log/cloud-init-output.log on the instance
 
08. Development, test and production each run the same application tier in an autoscaled instance pool. Installing its middleware takes a long time, and new instances must serve traffic soon after they boot. Each environment needs a different service endpoint and log level when the application starts. The operations team wants to build and patch only one image.
Which approach best meets these requirements?
a) Build one custom image per environment, each with the middleware and that environment's settings baked in
b) Bake the middleware and production settings into one image, and have Ansible correct each environment's settings after instances join the pool
c) Use a platform image and install the middleware with cloud-config packages and runcmd in every environment
d) Bake the middleware into one custom image, and pass each environment's settings through user data in its instance configuration
 
09. You are creating master encryption keys in OCI Vault for two workloads:
A payments database whose security policy requires that key material never leaves a hardware security module and that every cryptographic operation happens inside one.
A batch tool that must export its key from the server and perform cryptographic operations on the client.
Which protection mode choice meets both requirements?
a) Software protection mode for both keys, with each key kept in its own vault
b) HSM protection mode for both keys, with the batch tool calling the vault each time
c) HSM protection mode for the payments key, and software protection mode for the batch tool's key
d) HSM protection mode for the payments key, and an imported HSM key for the batch tool
 
10. New Oracle Linux instances must create a svcdeploy account that a deployment server reaches over SSH with its own public key. Administrators must continue to sign in as opc using the key supplied at launch in the ssh_authorized_keys instance metadata, and the deployment key must not grant access to opc.
Which cloud-config configuration meets these requirements?
a) A users list containing default and then svcdeploy, with its key under ssh_authorized_keys
b) No users list, with the deployment key added to the ssh_authorized_keys metadata
c) A users list containing only svcdeploy, with its key under ssh_authorized_keys
d) A write_files entry creating /home/svcdeploy/.ssh/authorized_keys

Answers:

Question: 01

Answer: a, e

Question: 02

Answer: a

Question: 03

Answer: b

Question: 04

Answer: d, e

Question: 05

Answer: d

Question: 06

Answer: c

Question: 07

Answer: b

Question: 08

Answer: d

Question: 09

Answer: c

Question: 10

Answer: a

 

Rating: 5 / 5 (82 votes)