01. A healthcare provider has two ODB networks in the same AWS region, one in each of two Availability Zones, and each hosts an Exadata VM Cluster. A single shared services VPC carries the middle tier and has to reach the VM cluster in both zones. The platform owner has also asked for a second, independent connection into the zone that carries the production workload, so that a path remains if one is withdrawn during maintenance.
Which peering plan can actually be built?
a) One ODB peering connection from the shared services VPC to each of the two ODB networks, with no second peering into the production ODB network.
b) Two ODB peering connections from the shared services VPC into the production ODB network, plus one into the other ODB network.
c) One ODB peering connection into the production ODB network, and an Amazon VPC peering connection into the other ODB network.
d) A single ODB peering connection from the shared services VPC, shared by both ODB networks through the transit gateway.
02. Minutes after the first ODB network and VM cluster are created, the application team reports that nothing in its VPC can reach the database listener. The corporate network cannot reach it either, and neither can a test from the internet. An incident has been raised against the build.
What should the architect conclude?
a) Provisioning has not finished: the database listeners register only once the Exadata infrastructure reports itself available, and the incident should be held until that completes.
b) The multicloud link between the AWS account and the OCI tenancy has not completed, so the ODB network has no path to the OCI child site or the subnets and network components that back it.
c) Nothing is faulty: an ODB network is private and isolated, with no connectivity to AWS VPCs, on-premises networks or the internet until connectivity is added deliberately.
d) The application VPC's route tables are missing the ODB network's routes; these propagate automatically once the first VM cluster in the network reaches the available state, so the route tables, and the corporate router's tables, need refreshing and the test repeating before the incident is closed.
03. After a contract renegotiation, a bank's board has asked architecture to reduce the risk of depending on a single provider for the core banking system of record. The application tier already runs on AWS and will stay there.
The database team is four DBAs. They have stated that they cannot take on hardware, firmware or Exadata platform operations, and the system of record must keep the Oracle Database features the bank relies on today.
Which approach satisfies the board's requirement within the team's capacity?
a) Deliver the system of record through the multicloud service that places Oracle-operated Exadata infrastructure inside the AWS region, so the database platform is operated by Oracle while the application estate, and the commercial transaction for the database, stay with AWS.
b) Re-platform the core banking data onto an AWS-native database engine, removing the Oracle dependency altogether, and rebuild the features the downstream systems consume in application code.
c) Run Oracle Database on EC2 instances that the bank patches and administers itself, so that no provider operates the core banking platform, and the application tier, the system of record and the operations beneath them all stay inside AWS.
d) Move the application tier to Oracle Cloud Infrastructure so that the application and its database are operated by one provider.
04. A media company connects a fleet of containerized application instances to an Exadata Database Service database on Oracle AI Database@AWS. The platform team's standard forbids any file-based credential or keystore being present in a container image, in a mounted secret, or on a container's file system. The security policy separately requires that traffic between application and database be encrypted with AES-256 where the client supports it.
Connections are being configured now, and nothing has been changed from the defaults on the database side.
Which connection configuration satisfies both the platform standard and the security policy?
a) Connect over TCPS on port 2484, baking the downloaded connection wallet into each container image at build time.
b) Connect over TCP and rely on Oracle native network encryption, which negotiates AES-256, AES-192 or AES-128 and needs no wallet, so that nothing has to be distributed to the containers.
c) Connect over TCP and add an ingress rule for SQL*Net to the Oracle-managed EXA_1521_ADJUSTABLE_NSG, restricting the source to the container subnet, and accepting that the rule may be reverted when the ODB network is next modified.
d) Connect over TCPS on port 2484, and have each container fetch the connection wallet from an Amazon S3 bucket at start-up, leaving the image itself without a keystore.
05. An insurer's applications run in a peered Amazon VPC and must connect to the Exadata VM Cluster by host name rather than by address. Separately, a nightly job that runs on the database hosts has to resolve an internal name published in a private DNS zone attached to that same VPC. The architect is finalizing the client subnet plan before the ODB network is created, and needs name resolution to work in both directions from day one.
Which two items should the plan include?
(Choose two.)
a) One extra SCAN address in the client subnet for each VM cluster, so that database host names resolve from the AWS side without a DNS endpoint.
b) An OCI DNS listening endpoint, which accepts queries arriving from the AWS side and consumes one client subnet address.
c) A second ODB peering connection between the VPC and the ODB network, dedicated to DNS queries.
d) A DNS forwarding endpoint, which sends queries from the OCI side out to AWS and consumes one further client subnet address.
e) Static A records in the VPC's private DNS zone for every database VM address, which consumes no client subnet allowance on the OCI side, refreshed whenever a VM is replaced.
06. After a hardening review, a network team narrowed the DNS path between an application VPC and its ODB network so that only UDP on port 53 remains permitted; TCP on port 53 was withdrawn as unused. Short lookups still succeed, but resolution of the database service names now fails intermittently. The change was made in the team's own VPC-side policy rather than on the ODB network, and they have confirmed that the OCI DNS listening endpoint is healthy and the ODB peering connection is up.
What should the architect recommend?
a) Add a DNS forwarding endpoint, which consumes one more client subnet address, so that queries leaving the application VPC are answered from the OCI side and not by AWS.
b) Move DNS traffic to port 443, which the ODB network's service integration rules already permit.
c) Add a rule to the Oracle-managed DNS_NSG that re-admits TCP on port 53, accepting that the rule may be removed, modified or re-applied when the ODB network is next modified or updated.
d) Restore TCP on port 53, because the ODB network's DNS rules cover port 53 over both TCP and UDP.
07. A bank is preparing an Exadata VM cluster on Oracle AI Database@AWS to use AWS KMS for TDE master keys. The cloud team has already created a symmetric customer-managed key with encrypt and decrypt usage in the AWS account that owns the ODB network, and has confirmed the ODB network is in place.
The database administrators ask what else must exist before a database on this VM cluster can take its master key from that AWS KMS key.
(Choose two.)
a) An ingress entry for the AWS KMS endpoint added to the Oracle-managed EXA_STATIC_NSG so the database can reach the key service with no identity provider in the path.
b) An OCI identity domain, acting as the identity provider that authenticates the database for access to AWS KMS.
c) An OCI Vault key in the same compartment as the VM cluster, holding a copy of the master key for local unwrap operations.
d) A downloadable connection wallet distributed to the database clients so that key requests travel over TLS.
e) An IAM role associated to the VM cluster, which attaches the identity connector.
08. A pharmaceutical company is choosing a service for a new clinical-data application. The team has stated in writing that it will not patch an operating system or tune a database, and no DBA capacity is funded. A governance rule separately forbids the workload from sharing database infrastructure with any other tenant. The application is a conventional OLTP schema with no operating-system dependencies.
Which Oracle Database@AWS service meets both constraints?
a) Oracle Autonomous AI Database Serverless, which Oracle describes as fully managed and serverless, with automatic provisioning and elastic scaling, and which removes the administration the team has ruled out.
b) Oracle Autonomous AI Database on Dedicated Exadata Infrastructure, which removes the operating-system and database administration the team has ruled out while running on Exadata infrastructure dedicated to the company.
c) Oracle Exadata Database Service on Dedicated Infrastructure, which gives the company Exadata infrastructure of its own in the availability zone, and keeps the workload off infrastructure shared with any other tenant.
d) Oracle Exadata Database Service on Exascale Infrastructure, which is one of the four services offered on Oracle Database@AWS, alongside the Dedicated Infrastructure form and the two Autonomous AI Database services.
09. An insurer is consolidating its departmental Oracle databases onto Oracle AI Database@AWS. It has already selected Oracle Autonomous AI Database on Dedicated Exadata Infrastructure. Each department must keep its own database with an independent lifecycle, and the architect is now working out how the estate is laid out within the service.
Which structure should the architect plan?
a) An Autonomous VM cluster on the Exadata infrastructure, Autonomous Container Databases on that cluster, and each department's database inside a container.
b) An Autonomous Container Database for each department, created directly on the Exadata infrastructure, with an Autonomous VM cluster added afterwards for the databases that need one.
c) Separate Exadata infrastructure for each department, each carrying its own Autonomous VM cluster and its own Autonomous Container Databases, so that no two departments share any layer of the deployment at all.
d) A single Autonomous AI Database on the cluster, with each department's workload created as a schema inside it.
10. A migration lead circulates a plan for moving several Oracle databases onto Oracle AI Database@AWS with Zero Downtime Migration. The plan states that ZDM will be procured and driven from the AWS console alongside the company's other AWS migration tooling, and describes ZDM as a replication engine that captures and applies changes itself, so that the team no longer needs skills in Oracle's own migration technologies.
Which correction should the architect make to the plan?
a) ZDM reaches the company through AWS Marketplace as part of the Oracle Database@AWS private offer, and is operated from the AWS console once the AWS account has been linked to the OCI tenancy by multicloud linking, alongside the other migration tooling the company already runs there.
b) ZDM supports Autonomous targets on Oracle Database@AWS only; Exadata targets are migrated with RMAN, Data Guard or transportable tablespaces used directly instead.
c) ZDM is Oracle's own migration automation: it orchestrates RMAN and Data Guard on its physical workflows and Data Pump and GoldenGate on its logical ones, and it is driven from the Oracle side even though the target hardware sits in an AWS Availability Zone.
d) ZDM is a replication engine in its own right, which is why it is planned and licensed separately from RMAN, Data Guard, transportable tablespaces, Data Pump and GoldenGate, and why it captures and applies the changes itself rather than driving RMAN or GoldenGate.