
手に入れよう!は2026年最新の有効な実践問題であなたの1Z0-1072-25日本語試験を合格させる(本日更新された53問)
Oracle Cloud Solutions Infrastructure 1Z0-1072-25日本語試験実践テスト問題集解答豪華セットを使おう!
質問 # 25
Oracle Cloud Infrastructure (OCI) ブロックボリューム サービス内で有効なアクションではないものはどれですか。
- A. ボリューム バックアップからより大きなボリュームに復元しています。
- B. 既存のボリュームを新しい、より大きなボリュームに複製します。
- C. オフライン サイズ変更により既存のボリュームをその場で拡張します。
- D. 異なる可用性ドメイン内のインスタンスにブロックボリュームをアタッチします。
正解:D
解説:
In Oracle Cloud Infrastructure (OCI), block volumes are designed to be highly flexible and can be used in various ways:
A . Restoring from a volume backup to a larger volume: This is supported and allows for resizing during the restoration process.
B . Cloning an existing volume to a new, larger volume: You can clone a block volume and specify a larger size for the new volume.
C . Expanding an existing volume in place with offline resizing: OCI allows you to increase the size of an existing block volume without needing to take it offline.
Option D is NOT valid because block volumes can only be attached to compute instances within the same availability domain. Cross-availability domain attachment of block volumes is not supported directly.
Reference:
Oracle Cloud Infrastructure Documentation: Block Volume Overview
質問 # 26
Oracle Cloud Infrastructure (OCI) Object Storage サービスについて正しくない記述はどれですか。
- A. オブジェクト ストレージに保存されるデータの不変オプションは、保持ルールを通じて設定できます。
- B. オブジェクトライフサイクルルールを使用して、オブジェクトをアーカイブまたは削除できます。
- C. オブジェクト ストレージ リソースはテナンシー間で共有できます。
- D. オブジェクトのバージョン管理は名前空間レベルで有効になります。
正解:C
解説:
Oracle Cloud Infrastructure (OCI) Object Storage is a scalable, highly durable service that allows you to store any type of data in a secure and cost-effective manner. The correct and incorrect statements regarding OCI Object Storage are as follows:
A . Immutable Option: You can indeed set an immutable option for data in Object Storage using retention rules. This feature ensures that once data is written, it cannot be modified or deleted until the retention period expires, making it ideal for regulatory compliance.
C . Object Lifecycle Rules: Object lifecycle policies allow you to automate the archiving or deletion of objects based on their age or other criteria, helping manage storage costs and data retention efficiently.
D . Object Versioning: Versioning is enabled at the bucket level, not the namespace level. However, once enabled for a bucket, it helps retain, retrieve, and restore every version of every object stored in that bucket.
B . Object Storage Sharing Across Tenancies: This statement is not true. OCI Object Storage buckets and objects are specific to a tenancy and cannot be shared across different tenancies directly. Access to Object Storage resources is controlled within a single tenancy through IAM policies.
Relevant OCI Documentation:
OCI Object Storage Overview
Object Lifecycle Management
These references provide details on how Object Storage functions and the features available.
質問 # 27
フル機能の Identity-as-a-Service (IDaaS) ソリューション用に作成する必要がある IAM アイデンティティ ドメイン タイプはどれですか?
- A. 無料
- B. 外部ユーザー
- C. プレミアム
- D. Oracle Apps プレミアム
正解:C
解説:
In Oracle Cloud Infrastructure (OCI), when you need a full-featured Identity-as-a-Service (IDaaS) solution, the appropriate Identity Domain type to create is Premium.
Premium Identity Domain: This option provides a comprehensive set of identity and access management (IAM) capabilities, including advanced security features, identity governance, and support for enterprise-grade integrations. It supports managing user identities, multifactor authentication, and various other identity services required for a robust IDaaS solution.
Other Options:
External User: This is a limited domain type typically used for managing users who only need access to specific external services.
Free: This domain type offers limited features and is not intended for full-featured enterprise IAM requirements.
Oracle Apps Premium: This is tailored for integrating with Oracle applications but does not offer the broad capabilities of the Premium option.
Relevant OCI Documentation:
Oracle Identity Domains Overview
This documentation explains the various identity domain types and their use cases within OCI.
質問 # 28
ポート 22 がセキュリティ リストから削除された後も SSH がまだ可能だったのはなぜですか?
- A. そのコンピューティングインスタンスの VNIC はクラスタネットワークに接続されています。
- B. そのコンピューティング インスタンスが存在する VCN には、まだインターネット ゲートウェイが存在します。
- C. そのコンピューティング インスタンスが存在する VCN には、ルート ルールがまだ存在します。
- D. そのコンピューティング インスタンスの VNIC は、ネットワーク セキュリティ グループ (NSG) に接続されています。
正解:D
解説:
Even after removing port 22 from the Security Lists, SSH was still possible because the Virtual Network Interface Card (VNIC) of the compute instance is attached to a Network Security Group (NSG).
NSGs: NSGs provide a more flexible and granular way to manage security rules compared to Security Lists. They allow you to apply security rules directly to VNICs associated with resources such as compute instances. If an NSG allows traffic on port 22, SSH will still be possible, regardless of the Security List settings.
Reference:
Oracle Cloud Infrastructure Documentation: Security Lists and Network Security Groups
質問 # 29
OCI IAM アイデンティティ ドメイン内のアクセス制御に管理者ロールを利用する主な利点は何ですか?
- A. より幅広い権限の組み合わせを提供する
- B. ポリシー作成をなくすことでアクセス管理を簡素化
- C. 特定のコンパートメントへのユーザーアクセスを細かく制御します
- D. アイデンティティドメイン外のリソースへのアクセスを許可するために使用できます
正解:B
解説:
In Oracle Cloud Infrastructure (OCI) Identity and Access Management (IAM), administrator roles play a significant role in managing access:
Simplification of Access Management: Utilizing administrator roles allows you to simplify access management by eliminating the need to create complex IAM policies manually. These roles come with predefined permissions that cover common administrative tasks, reducing the effort needed to manage access controls.
Granular Control: While administrator roles provide a broad range of permissions, they may not offer the same level of granularity as custom policies.
Other Benefits:
Offer a wider range of permission combinations (A): While custom policies can offer more specific combinations, administrator roles are designed to cover a broad range of tasks.
Granting Access Outside Identity Domain (C): Administrator roles are generally scoped to their identity domain and do not provide cross-domain access.
Granular Control (D): Although administrator roles simplify management, custom policies are typically used when granular control over specific compartments or resources is needed.
Relevant OCI Documentation:
OCI IAM Roles Overview
This resource provides detailed information on how roles and policies are used in OCI to manage access.
質問 # 30
Oracle Cloud Infrastructure (OCI) ファイル システムのスナップショットに関して正しくない記述はどれですか。
- A. スナップショットは、ファイル システムの一貫性のある特定時点のビューです。
- B. ファイル システムを複製する前に、ファイル システムのスナップショットが少なくとも 1 つ存在している必要があります。
- C. スナップショットは、ファイル システムのルート ディレクトリの .snapshot/name からアクセスできます。
- D. 最後のスナップショットが取得されてからファイル システム内で何も変更されていない場合でも、新しいスナップショットはより多くのストレージを消費します。
正解:D
解説:
In OCI File Storage, snapshots are point-in-time, read-only copies of a file system that do not immediately consume additional storage beyond the space needed to track changes.
Incorrect Statement: The statement that a new snapshot consumes more storage even if nothing has changed is incorrect. Snapshots are space-efficient; they only consume additional storage as changes are made to the file system after the snapshot is taken. If no changes are made between snapshots, the storage consumption remains minimal.
Correct Statements:
B . Before cloning a file system, at least one snapshot must exist, as the clone operation relies on this snapshot to create a copy.
C . Snapshots are accessible under the .snapshot directory, allowing users to view and restore files from specific snapshots.
D . Snapshots provide a consistent, point-in-time view of the file system, ensuring data integrity.
Reference:
Oracle Cloud Infrastructure Documentation: Managing File System Snapshots
質問 # 31
1 GB のファイルのうち 0.5 GB を上書きした場合、1 時間ごとの更新サイクルが完了した後にファイル ストレージ サービスによって表示される合計 meteredBytes はいくらになりますか?
- A. 0.5 GB
- B. 1 GB
- C. 1.5 GB
- D. 2.5 GB
正解:C
解説:
In Oracle Cloud Infrastructure (OCI) File Storage, when you overwrite a portion of a file, the service does not immediately reclaim the space occupied by the previous version of the file. The total meteredBytes reflects both the original data and the new data written.
Scenario Explanation: You start with a 1 GB file. When you overwrite 0.5 GB of this file, the file system retains both the 0.5 GB of the original file and the new 0.5 GB you wrote.
Calculation: The original 1 GB file contributes 1 GB to meteredBytes. When 0.5 GB is overwritten, the total usage becomes 1.5 GB (1 GB original + 0.5 GB new).
Thus, after the hourly update cycle, the total meteredBytes shown by the File Storage service will be 1.5 GB.
Reference:
Oracle Cloud Infrastructure Documentation: File Storage Service Overview
質問 # 32
サードパーティ API が OCI リソースと通信できるようにするには、どの認証オプションを使用する必要がありますか?
- A. OCIユーザー名とパスワード
- B. 2048ビットアルゴリズムのSSHキーペア
- C. 認証トークン
- D. API署名キー
正解:D
解説:
When ensuring that third-party APIs communicate securely with OCI resources, the appropriate authentication option is API Signing Key.
API Signing Key: This method uses an RSA key pair to authenticate and sign API requests. The API signing key provides a secure and reliable way to ensure that the API requests to OCI are coming from an authorized source. It is commonly used for programmatic access to OCI services.
Other Options:
SSH Key Pair: Primarily used for secure shell access to compute instances, not for API authentication.
Auth Tokens: Typically used for authentication in environments where APIs don't support the API Signing Key, such as OCI CLI or SDKs.
OCI Username and Password: Generally used for the Console login, not for securing API communications.
Relevant OCI Documentation:
API Signing Key Authentication
This documentation provides details on using API Signing Keys for secure API communication in OCI.
質問 # 33
データベース インスタンスを別のコンパートメントに移動すると、ユーザー アクセスにどのような影響がありますか?
- A. すべてのユーザーのアクセスが取り消されます。
- B. コンパートメントはリソースの移動を防ぎます。
- C. コンパートメントは IAM ポリシーの対象外です。
- D. IAM ポリシーはコンパートメントに関連付けられていません。
正解:A
解説:
In Oracle Cloud Infrastructure (OCI), when you move a database instance to a different compartment, the following impact on user access occurs:
Impact of Moving Resources: When you move a resource, like a database instance, to a different compartment, the IAM policies that grant access to that resource in the original compartment no longer apply. This effectively revokes access for users or groups unless equivalent policies are in place in the new compartment.
Restoring Access: To restore access, you would need to create new IAM policies in the destination compartment that grant the necessary permissions to the users or groups who need access.
Relevant OCI Documentation:
Managing Compartments
Moving Resources
These resources provide detailed steps on how compartment changes impact resource access and management.
質問 # 34
Oracle Cloud Infrastructure (OCI) ブロック・ボリューム・サービスのブロック・ボリューム・バックアップからボリュームをリストアすることに関して正しい記述はどれですか。
- A. ボリュームは、元のブロック ボリュームが存在するのと同じ可用性ドメインにのみリストアできます。
- B. ブロック ボリューム バックアップをより大きなボリューム サイズに復元できます。
- C. ボリュームは完全なボリューム バックアップから復元できますが、増分バックアップからは復元できません。
- D. 手動ブロックボリュームバックアップからは 1 つのボリュームのみを復元できます。
正解:B
解説:
Restoring a block volume from a backup in OCI provides flexibility and options for scaling and recovery:
Restoring to a Larger Volume Size: When restoring a block volume from a backup, you have the option to restore it to a volume that is larger than the original. This is particularly useful if you anticipate needing more storage capacity after the restore.
Full and Incremental Backups: OCI supports both full and incremental backups. You can restore from any backup type, which makes it possible to restore data efficiently depending on the backup strategy used.
Multiple Restores: Multiple volumes can be restored from a single backup, providing flexibility in disaster recovery scenarios.
Availability Domain: The restored volume can be created in any availability domain within the same region, not necessarily the same one where the original volume was located.
Relevant OCI Documentation:
Block Volume Service Overview
Restoring a Block Volume
These references explain the process and options available for restoring block volumes from backups.
質問 # 35
即時アクセスと 31 日間の保持の要件を満たしながらコストを最小限に抑えてバックアップを保存するのに適した OCI オブジェクト ストレージ層はどれですか。
- A. 自動階層化層
- B. アーカイブ層
- C. 標準層
- D. 低頻度アクセス層
正解:D
解説:
The Infrequent Access tier in OCI Object Storage is suitable for storing backups that need to be immediately accessible and retained for a specific period, such as 31 days, while also minimizing costs. This tier offers a balance between cost and accessibility, charging lower storage costs compared to the Standard tier but still allowing quick access to the data.
Use Case: The Infrequent Access tier is designed for data that is not frequently accessed but must remain readily available when needed, making it ideal for backup storage.
Reference:
Oracle Cloud Infrastructure Documentation: Object Storage Tiers
質問 # 36
Oracle Cloud Infrastructure (OCI) ファイル ストレージ サービスに関する次の 2 つの記述のうち、正しいものはどれですか。
- A. お客様は、エクスポート オプションを使用してマウント ターゲットへの通信を暗号化できます。
- B. マウント ターゲット内のファイル システムとの通信は HTTPS 経由で暗号化されます。
- C. ファイル システムは、デフォルトで Oracle 管理キーを使用します。
- D. お客様は独自の Vault 暗号化キーを使用してファイル システム内のデータを暗号化できます。
正解:C、D
解説:
Oracle Cloud Infrastructure (OCI) File Storage Service offers robust encryption capabilities to ensure data security.
B . Customer-Managed Encryption: Customers can choose to encrypt their data using their own keys stored in the OCI Vault service. This gives customers control over their encryption keys and enhances data security.
D . Oracle-Managed Encryption: By default, all data stored in OCI File Storage is encrypted using Oracle-managed keys. This ensures that data is encrypted at rest without requiring any action from the customer.
Incorrect Statements:
A . Communication is not encrypted via HTTPS when accessing file systems; instead, encryption in transit is typically managed via NFS over TLS.
C . Encryption of communication to a mount target is handled via network configurations, not through export options.
Reference:
Oracle Cloud Infrastructure Documentation: File Storage Encryption
質問 # 37
可用性ドメイン全体にわたる高可用性と分散の要件を満たすために、いくつの容量予約を作成しますか?
- A. 0
- B. 1
- C. 2
- D. 3
正解:C
解説:
In Oracle Cloud Infrastructure (OCI), to ensure high availability and distribution across Availability Domains (ADs), the recommended approach is as follows:
Capacity Reservations for High Availability: To achieve high availability, especially across all three Availability Domains in a region, you should create three capacity reservations. Each reservation corresponds to one AD, ensuring that your instances or resources are evenly distributed and resilient to AD-level failures.
Why Three: This setup provides redundancy and load distribution across the ADs, meeting the high availability requirements.
Relevant OCI Documentation:
Capacity Reservations
This document outlines how to create and manage capacity reservations to meet high availability and fault tolerance requirements.
質問 # 38
VMインスタンスをルートキットやブートキットなどの低レベルの脅威から保護したい場合、どうすればよいでしょうか?
- A. バースト可能なインスタンスを作成します。
- B. 転送中の暗号化を使用します。
- C. 脆弱性スキャン サービスを使用します。
- D. シールドされたインスタンスを作成します。
正解:D
解説:
To protect your VM instance from low-level threats, such as rootkits and bootkits, you should create a shielded instance in Oracle Cloud Infrastructure (OCI). Shielded instances are designed to provide enhanced security features, including:
Secure Boot: Ensures that the instance boots only with trusted software.
Measured Boot: Records boot metrics, allowing verification that the instance has not been tampered with.
Trusted Platform Module (TPM): Provides additional security through cryptographic functions.
These features help protect against low-level threats that could compromise the integrity of the instance at boot time.
Reference:
Oracle Cloud Infrastructure Documentation: Shielded Instances
質問 # 39
ダイナミックルーティングゲートウェイ(DRG)にリソースをアタッチできます。これらのリソースから3つ選択してください。
- A. 仮想回線
- B. リモートピアリング接続
- C. ローカルピアリング接続
- D. サブネット
- E. IPSecトンネル
- F. VNIC
正解:A、B、E
解説:
A Dynamic Routing Gateway (DRG) in Oracle Cloud Infrastructure (OCI) is a virtual router that provides a path for private traffic between your on-premises network and your VCN, or between your VCN and other VCNs. The resources that can be attached to a DRG include:
A . Virtual Circuits: Used to establish a private connection between your on-premises data center and your VCN via Oracle's FastConnect service.
D . Remote Peering Connections: Enables peering between VCNs located in different regions (Remote VCN Peering).
E . IPSec Tunnel: Facilitates secure VPN connections between your on-premises network and your OCI VCN.
Reference:
Oracle Cloud Infrastructure Documentation: Dynamic Routing Gateway Overview
質問 # 40
これらの要件を満たすには、どのコンピューティング容量タイプを選択しますか?
- A. プリエンプティブ容量
- B. オンデマンド容量
- C. 容量予約
- D. 専用ホスト
正解:B
解説:
On-demand capacity is the compute capacity type in Oracle Cloud Infrastructure (OCI) that allows you to provision and use compute instances whenever needed, without any long-term commitment. This flexibility is ideal for various workloads, including development, testing, and production environments, where immediate availability and scalability are crucial.
Key Points:
On-Demand Capacity: On-demand compute instances provide users with the flexibility to spin up instances as required and only pay for the time the instances are running. This model is most suitable for workloads with unpredictable usage patterns or short-term requirements.
Flexibility and Scalability: With on-demand capacity, you can quickly scale your resources up or down based on your application's needs, ensuring that you only pay for the resources you actually use.
No Commitment: Unlike reserved capacity, on-demand capacity does not require any long-term commitment or upfront payment, making it an attractive option for organizations looking to avoid capital expenditures.
Reference:
Oracle Cloud Infrastructure Documentation: OCI Compute Pricing
Oracle Cloud Infrastructure Documentation: Compute Instance Lifecycle
Explanation of Incorrect Options:
A . Capacity reservation: This option allows you to reserve capacity in advance, ensuring that resources are available when needed. It's ideal for predictable workloads but may not be as cost-effective for fluctuating demands.
B . Preemptible capacity: Preemptible instances are a lower-cost option where instances can be terminated by OCI if resources are needed elsewhere. This is suitable for non-critical workloads that can tolerate interruptions.
D . Dedicated host: Dedicated hosts provide physical servers for your exclusive use, offering isolation and predictable performance. This option is more suitable for workloads requiring dedicated resources or compliance needs.
Thus, Option C: On-demand capacity is the correct choice for most general-purpose workloads needing flexibility and immediate availability without long-term commitment.
質問 # 41
OCI IAMポリシーはデフォルトで最小権限の原則に従います。この原則は、ポリシー作成においてどのような意味を持つのでしょうか?
- A. ポリシーは、テナンシー内のすべてのユーザーに対して同一である必要があります。
- B. ポリシーは、ユーザーがタスクを効果的に実行するために必要な最小限の権限セットのみを提供する必要があります。
- C. セキュリティを強化するには、ポリシーを複雑かつ技術的な方法で記述する必要があります。
- D. アクセス制御を簡素化するために、ポリシーでは可能なすべての権限を付与する必要があります。
正解:B
解説:
The principle of least privilege is a security best practice that dictates that users should only be granted the minimum set of permissions necessary to perform their tasks. This principle helps to minimize the risk of accidental or malicious actions that could compromise security.
IAM Policies in OCI: When creating IAM policies in OCI, you should carefully evaluate the required permissions and only grant those that are absolutely necessary for the users or groups to perform their specific roles. This helps to reduce the attack surface and prevent unauthorized access to sensitive resources.
Reference:
Oracle Cloud Infrastructure Documentation: Identity and Access Management (IAM) Best Practices
質問 # 42
共有テスト コンパートメントの既存の 3 つの管理者グループすべてに管理者アクセスを提供するには、どのポリシーを作成しますか?
- A. request.principal.group.tag.EmployeeGroup.Role='Admin' の場合、動的グループがコンパートメント内のすべてのリソースを管理できるようにします。
- B. すべてのグループがコンパートメント内のすべてのリソースを管理できるようにする。request.principal.group.tag.EmployeeGroup.Role='Admin' の場合にテストする。
- C. request.principal.group.tag.EmployeeGroup.Role='Admin' の場合、グループ any-group がコンパートメント テスト内のすべてのリソースを管理できるようにします。
- D. request.principal.group.tag.EmployeeGroup.Role='Admin' の場合、コンパートメント テストですべてのユーザーがすべてのリソースを管理できるようにします。
正解:B
解説:
In Oracle Cloud Infrastructure (OCI), policies are written to define permissions for user groups. The correct policy to provide admin access to all three existing admin groups in a shared compartment (in this case, the "Test" compartment) would be:
"Allow all-group to manage all-resources in compartment Test where request.principal.group.tag.EmployeeGroup.Role='Admin'".
"Allow all-group": Grants access to all groups.
"to manage all-resources": Specifies full access permissions (manage includes all CRUD operations).
"in compartment Test": Limits the scope of the policy to the "Test" compartment.
"where request.principal.group.tag.EmployeeGroup.Role='Admin'": Adds a condition to restrict this admin-level access to only groups tagged with the role 'Admin'.
This policy ensures that only users in the groups tagged as Admin will be allowed to manage resources in the Test compartment, making it the most suitable choice for providing admin access.
For reference:
OCI Policy Syntax Documentation
質問 # 43
どのトラフィック管理ステアリング ポリシーが、エンド ユーザーの地理的な場所に基づいて DNS トラフィックの分散を促進しますか。
- A. 近接ステアリング
- B. ASNステアリング
- C. 地理位置情報ステアリング
- D. IPプレフィックスステアリング
正解:C
解説:
Geolocation Steering in OCI's Traffic Management Steering Policy allows you to distribute DNS traffic based on the geographical location of the end users. This method helps direct users to the nearest regional endpoint, optimizing latency and improving user experience.
Use Cases: Geolocation Steering is commonly used to deliver region-specific content, comply with data residency laws, or optimize service performance by directing traffic to the closest available servers.
Reference:
Oracle Cloud Infrastructure Documentation: Traffic Management Steering Policies
質問 # 44
Oracle Cloud Infrastructure (OCI) のプライベート IP アドレスについて正しい記述はどれですか 2 つあります。
- A. デフォルトでは、サブネット内のインスタンスのプライマリ VNIC には 1 つのプライマリプライベート IP アドレスがあります。
- B. プライベート IP は、パブリック サブネット内に存在する場合、オプションでパブリック IP を割り当てることができます。
- C. 各 VNIC にはプライベート IP アドレスを 1 つだけ設定できます。
- D. デフォルトでは、サブネット内のインスタンスのプライマリ VNIC には、プライマリ プライベート IP アドレスが 1 つとセカンダリ プライベート IP アドレスが 1 つあります。
正解:A、B
解説:
In Oracle Cloud Infrastructure (OCI), understanding how private IP addresses work is crucial for configuring network interfaces and managing instances within your Virtual Cloud Network (VCN).
Primary VNIC and Private IP Address:
When an instance is launched in OCI, it is attached to a Virtual Network Interface Card (VNIC). The primary VNIC, which is automatically created during the instance launch, is associated with a primary private IP address by default. This private IP address is essential for the instance to communicate within the VCN. The primary private IP address is automatically assigned and cannot be removed from the primary VNIC while the instance is running. This supports the statement C.
Additional Private IPs:
Contrary to statement B, each VNIC can indeed have multiple private IP addresses, but by default, the primary VNIC comes with only one primary private IP. You can manually add secondary private IPs if needed. However, the additional IPs are not assigned by default; hence, A is incorrect.
Public IP Association:
For instances requiring internet access, a public IP address can be optionally assigned to the private IP address if the instance is in a public subnet. This is critical for scenarios where an instance needs to communicate with the internet or external networks. This aligns with statement D.
Relevant OCI Documentation:
Oracle Cloud Infrastructure Networking Overview
VNICs and Private IPs
These references provide additional context and detail on how private IP addresses work within OCI and clarify the correct statements.
質問 # 45
Oracle Cloud Infrastructure (OCI) 内の 2 つの仮想クラウド ネットワーク (VCN) 間のリモート ピアリングを確立するために必要なコンポーネントはどれですか。
- A. 異なるリージョンにある重複しない CIDRS を持つ 2 つの VCN、各 VCN に接続された動的ルーティング ゲートウェイ (DRG)、各 DRG 上のリモート ピアリング接続 (RPC)、および RPC 間に確立された接続。
- B. 各リージョンに重複しない CIDRS を持つ単一の VCN、各 VCN に接続された動的ルーティング ゲートウェイ (DRG)、および DRGS 間の直接接続。
- C. 同じリージョン内に重複しない CIDRS を持つ 2 つの VCN、各 VCN に接続された動的ルーティング ゲートウェイ (DRG)、および DRG 間の直接接続。
- D. 異なるリージョンにある重複する CIDRS を持つ 2 つの VCN、各 VCN に接続された仮想プライベート ネットワーク (VPN) ゲートウェイ、および VPN ゲートウェイ間の直接接続。
正解:A
解説:
Remote peering in Oracle Cloud Infrastructure allows two VCNs in different regions to communicate securely. To establish remote peering, the following components are required:
Two VCNs with Nonoverlapping CIDRs:
The CIDR blocks of the two VCNs must not overlap. This is crucial to avoid routing conflicts and ensure that traffic is correctly routed between the VCNs.
Dynamic Routing Gateway (DRG) Attached to Each VCN:
A DRG is a virtual router that provides a path for traffic between the VCN and networks outside the VCN, such as other VCNs via remote peering, on-premises networks, or other cloud services. Each VCN needs its own DRG.
Remote Peering Connection (RPC):
An RPC is a specialized connection on the DRG used specifically for remote peering. You need to create an RPC on each DRG associated with the VCNs you wish to peer.
Connection Between RPCs:
Finally, a connection must be established between the RPCs of the two DRGs. This connection facilitates the secure and private exchange of traffic between the VCNs over Oracle's backbone network.
Incorrect Options:
Option A involves a single VCN, which does not fulfill the requirement of remote peering between two VCNs.
Option B involves overlapping CIDRs and VPN gateways, which are incorrect for remote peering.
Option C suggests peering within the same region, which would be considered local peering rather than remote peering.
Relevant OCI Documentation:
OCI Remote VCN Peering
Dynamic Routing Gateway (DRG) Overview
These resources provide a detailed guide on configuring remote peering in OCI, ensuring secure and effective communication between VCNs across regions.
質問 # 46
......
完全版最新の問題集PDFで最新1Z0-1072-25日本語試験問題と解答:https://jp.fast2test.com/1Z0-1072-25-JPN-premium-file.html