01. Compliance requires traffic to stay encrypted from clients through an OCI Load Balancer all the way to the backend servers, with TLS also used between the load balancer and the backends.
Where must certificate bundles be configured?
(Choose two.)
a) On the listener that accepts client connections
b) On the security list of the load balancer's subnet
c) On the backend set's health check
d) On the backend set that the listener forwards to
02. A VCN already controls traffic with security lists and network security groups (NSGs). The security team now enables Zero Trust Packet Routing (ZPR) and tags an application server and a database in different subnets of the VCN. The application server must reach the database on TCP 1521.
Which two statements describe what the connection now needs?
(Choose two.)
a) The ZPR policy alone decides, so security list and NSG rules are skipped
b) A ZPR policy must also allow the connection
c) Security list or NSG rules must still allow the connection on TCP 1521
d) ZPR is checked only after a security list or NSG rule denies it
03. To handle a high volume of HTTPS traffic, a team replaces the stateful rules on a public web subnet's security list with stateless ingress and egress rules for TCP 443. Afterwards, small requests still succeed, but some clients' connections hang when large responses are sent.
Which change fixes the problem?
a) Add back a stateful ingress rule for TCP 443 alongside the stateless rules
b) Add a stateless egress rule allowing ICMP type 8 to 0.0.0.0/0
c) Add a stateless ingress rule allowing ICMP type 3 code 4 from 0.0.0.0/0
d) Add a stateless egress rule allowing all TCP ports to 0.0.0.0/0
04. An operations team wants its OCI logging and monitoring to surface problems quickly across many services.
Which two practices make the logging and monitoring more effective?
(Choose two.)
a) Keeping each service's logs in its own compartment with no shared view
b) Aggregating logs from multiple sources for centralized analysis
c) Reviewing metric dashboards by hand once a week instead of alarming
d) Setting alarms that notify the team when critical metrics cross a threshold
05. Instances in two different VCNs that should communicate cannot reach each other.
Which two OCI features help troubleshoot this connectivity problem?
(Choose two.)
a) Traffic Management policies
b) Network Visualizer
c) VCN flow logs
d) Vault keys
06. A company is choosing between Site-to-Site VPN and FastConnect for migrating workloads from its data center to OCI.
Which two factors are most critical to this choice?
(Choose two.)
a) Number of availability domains in the target region
b) Regional or AD-specific subnet types in the VCN
c) Bandwidth and throughput the migration traffic requires
d) Cost of deployment
07. Before connecting several VCNs to a new hub, a network architect needs to check how full each subnet's CIDR is and whether any VCN CIDRs overlap, across the region's compartments.
Which two statements about IP Address Insights are true for this task?
(Choose two.)
a) It reports CIDR utilization for each VCN and subnet, per compartment
b) It sends test traffic between subnets to confirm reachability
c) It flags overlapping CIDRs between VCNs
d) It renumbers subnets whose CIDRs overlap automatically
08. A new IPSec connection between an on-premises CPE and OCI never comes up. The CPE logs show IKE phase 1 negotiation starting, but Oracle's proposal is never fully received. An on-premises firewall sits in front of the CPE.
Which two statements describe the likely cause and its fix?
(Choose two.)
a) Disabling PFS on the Oracle side lets the tunnel complete phase 1
b) The on-premises firewall must allow IKE fragments through to the CPE
c) Oracle's IKE proposal set is large, so its messages can be fragmented
d) Oracle's IKE messages always fit in one packet, so fragmentation is ruled out
09. Users report slow data replication between applications running in two OCI regions. The network team wants to see the round-trip times OCI measures between those regions.
Which OCI tool shows this?
a) The Inter-Region Latency dashboard in Network Command Center
b) VCN flow logs filtered to the replication subnets in both regions
c) Network Path Analyzer
d) Cloud Advisor recommendations
10. An engineer adds a firewall instance to a hub VCN and points the transit route rules at the firewall's private IP. The security rules allow the traffic and the firewall's operating system forwards packets, yet traffic routed through the firewall is dropped.
What must the engineer change?
a) Replace the private IP route target with the hub VCN's NAT gateway
b) Assign a reserved public IP to the firewall's VNIC
c) Attach a second internet gateway to the hub VCN for the firewall
d) Skip the source/destination check on the firewall's VNIC