You are working with a social media company as a solution architect. The media company wants to collect and analyze
large amounts of data being generated from their websites and social media feeds to gain insights and continuously
improve the user experience. In order to meet this requirement, you have developed a microservices application hosted
on Oracle Container Engine for Kubernetes. The application will process the data and store the result to an
Data Warehouse (ADW) instance.
Which Oracle Cloud Infrastructure (OCI) service can you use to collect and process a large volume of unstructured data
in real-time?
A. OCI Events
B. OCI Streaming
C. OCI Resource Manager
D. OCI Notifications
Correct Answer: B


You are working as a cloud engineer for an IoT startup company which is developing a health monitoring pet collar for
dogs and cats. The company collects biometric Information of the pet every second and then sends it to Oracle Cloud
Infrastructure (OCI) Your task is to come up with an architecture that will accept and process the monitoring data as
well as provide complete trends and health reports to the pet owners. The portal should be highly available, durable,
scalable with an additional feature for showing real-time biometric data analytics.
which architecture will help you meet this requirement?
A. Use OCI Streaming Service to collect the incoming biometric data. Use Oracle Functions to process the date and
show the results on a real-time dashboard and store the results lo OCI Object Storage Store the data In OCI
Autonomous Data warehouse (ADW) to handle analytics.
B. Launch an open-source Hadoop cluster to collect the Incoming biometrics data Use an Open source Fluentd cluster
to analyze the- data I result to OCI Autonomous Transaction Processing (ADW)to handle complex analytics
C. Create an OCI Object Storage bucket to collect the incoming biometric data from the smart pet collar Fetch the data
horn OC\ Object storage to OCI Autonomous Data Warehouse (ADW) every day and run analytics Jobs with it
D. Use OCI Streaming Service to collect the incoming biometric data. Use an open-source Hadoop cluster to analyze
the data horn streaming service. Store the results to OCI Autonomous Data warehouse (ADW) to handle complex
Correct Answer: A

You work for a German company as the Lead Oracle Cloud Infrastructure architect. You have designed a highly
scalable architecture for your company\\’s business-critical application which uses the Load Balancer service auto which
uses the
Load Balancer service, autoscaling configuration for the application servers, and a 2 Node VM Oracle RAC database.
During the peak utilization period of the- application yon notice that the application is running slow and customers are
complaining. This is resulting in support of tickets being created for API timeouts and negative sentiment from the
customer base.
What are two possible reasons for this application’s slowness?
A. Autoscaling configuration for the application servers didn\\’t happen due to 1 AM policy that\\’s blocking access to the
application server compartment
B. The Load Balancer configuration is not sending traffic to the listener of the application servers.
C. Autoscaling configuration for the application servers didn\\’t happen due to compartment quota breach of the VM
shapes used by the application servers.
D. Autoscaling configuration for the application servers didn\\’t happen due to service limit breach of the VM shapes
used by the application servers
E. The Load Balancer doesn\\’t have a Network Security Group to allow traffic to the application servers.
Correct Answer: CD
Autoscaling enables you to automatically adjust the number of Compute instances in an instance pool
based on performance metrics such as CPU utilization. This helps you provide consistent performance for your end-users during periods of high demand, and helps you reduce your costs during periods of low demand. Prerequisites

You have an instance pool. Optionally, you can attach a load balancer to the instance pool. For steps to create an
instance pool and attach a load balancer, see Creating an Instance Pool.

Monitoring is enabled on the instances in the instance pool. For steps to enable monitoring, see Enabling Monitoring for
Compute Instances.

The instance pool supports the maximum number of instances that you want to scale. This limit is determined by
your tenancy\\’s service limits. About Service Limits and Usage When you sign up for Oracle Cloud Infrastructure, a set
of service limits are configured for your tenancy. The service limit is the quota or allowance set on a resource. For
example, your tenancy is allowed a maximum number of compute instances per availability domain. These limits are
generally established with your Oracle sales representative when you purchase Oracle Cloud Infrastructure.
Compartment Quotas Compartment quotas are similar to service limits; the biggest difference is that service limits are
set by Oracle, and compartment quotas are set by administrators, using policies that allow them to

You are building a highly available and fault-tolerant web application deployment for your company. Similar applications
delayed by competitors experienced web site attacks including DDoS which resulted in web server failing. You have
decided to use Oracle Web Application Firewall (WAF) to implement an architecture that will provide protection
against such attacks and ensure additional configuration will you need to implement to make sure WAF is protecting my
web application 24?. Which additional configuration will you need to Implement to make sure WAF Is protecting my web
application 24??
A. Configure auto-scaling policy and it to WAF instance.
B. Configure Control Rules to send traffic to multiple web servers
C. Configure multiple origin servers
D. Configure new rules based on new vulnerabilities and mitigations
Correct Answer: C
Origin Management An origin is an endpoint (typically an IP address) of the application protected by the WAF. An origin
can be an Oracle Cloud Infrastructure load balancer public IP address. A load balancer IP address can be used for high
availability to an origin. Multiple origins can be defined, but only a single origin can be active for a WAF. You can set
HTTP headers for outbound traffic from the WAF to the origin server. These name-value pairs are then available to the
application. Oracle Cloud Infrastructure Web Application Firewall (WAF) is a cloud-based, Payment Card Industry (PCI)
compliant, global security service that protects applications from malicious and unwanted internet traffic. WAF can
protect any internet-facing endpoint, providing consistent rule enforcement across a customer\\’s applications. WAF
provides you with the ability to create and manage rules for internet threats including Cross-Site Scripting (XSS), SQL
Injection and other OWASP-defined vulnerabilities. Unwanted bots can be mitigated while tactically allowed desirable
bots to enter. Access rules can limit based on geography or the signature of the request. Distributed Denial of Service
(DDoS) A DDoS attack is an often intentional attack that consumes an entity\\’s resources, usually using a large number
of distributed sources. DDoS can be categorized into either Layer 7 or Layer 3/4 (L3/4) A layer 7 DDoS attack is a DDoS
attack that sends HTTP/S traffic to consume resources and hamper a website\\’s ability to deliver content or to harm
the owner of the site. The Web Application Firewall (WAF) service can protect layer 7 HTTP-based resources from layer
7 DDoS and other web application attack vectors.


An online Stock trading application is deployed to multiple Availability Domains in us phoenix-1 region. Considering
the high volume of transactions that the trading application handles, the company has hired you to ensure that the data
stored by the application available, and disaster resilient. In the event of failure, the Recovery lime Objective (UK)) must
be less than 2 hours to meet regulator requirements.
Which Disaster Recovery strategy should be used to achieve the RTO requirement In the event of system failure?
A. Configure hourly block volumes backups through the Storage Gateway service.
B. Configure hourly block volumes backups using the Oracle Cloud Infrastructure (OCI) Command Line Interface (CLI)
C. Store hourly block volumes backup to NVMe device under a compute instance and generate a custom Image every 5
D. Configure your application to use synchronous master-slave data replication between Availability Domains.
Correct Answer: B
You can use the CLI, REST APIs, or the SDKs to automate, script, and manage volume backups and their lifecycle.
Planning Your Backup The primary use of backups is to support business continuity, disaster recovery, and long-term
archiving requirements. When determining a backup schedule, your backup plan and goals should consider the
following: Frequency: How often you want to back up your data. Recovery time: How long you can wait for a backup to
be restored and accessible to the applications that use it. The time for a backup to complete varies on several factors,
but it will generally take a few minutes or longer, depending on the size of the data being backed up and the amount of
data that has changed since your last backup. The number of stored backups: How many backups you need to keep
available and the deletion schedule for those you no longer need. You can only create one backup at a time, so if a
backup is underway, it will need to complete before you can create another one. For details about the number of
backups you can store


Your customer recently ordered a 1-Gbps Fast Connect connection In the ap-Tokyo-1 region of Oracle Cloud
Infrastructure (OCI). They will use this to one Virtual Cloud Network (VCN) in their production (OC1) tenancy and VCN In
their development OC1 tenancy As a Solution Architect, how should you configure and architect the connectivity
between on-premises and VCNs In OCI?
A. Create two private virtual circuits on the FastConnect link. Create two Dynamic Routing Gateways, one for each
VCNs. Attach the virtual circuits to the dynamic routing gateways.
B. You cannot achieve connectivity using a single FastConnect link as the production and the development VCNs-are in
separate tenancies. Request one more FastConnect connection.
C. Create a single private virtual circuit over FastConnect and attach fast connect to either of the
D. Create a hub-VCN that uses Dynamic Routing Gateway (DRG) to communicate with the on-premises network over
FastConnect. Connect the hub-VCN to the production VCN spoke and with development VCN spoke, each peered via
their respective local Peering Gateway (LPG)
Correct Answer: D
Their \\’s an advanced routing scenario called transit routing that enables the communication between an on-premises
network and multiple VCNs over a single Oracle Cloud Infrastructure FastConnect or IPSec VPN. The VCNs must be in
the same region and locally peered in a hub-and-spoke layout. As part of the scenario, the VCN that is acting as the hub
has a routing table associated with each LPG (typically route tables are associated with a VCN\\’s subnets).lead4pass 1z0-997 exam questions q6


Multiple departments In your company use a shared Oracle Cloud Infrastructure (OCI) tenancy to Implement their
projects. You are in charge of managing the cost of OCI resources in the tenancy and need to obtain better Insights Into
department\\’s usage. Which three options can you implement together to accomplish this?
A. Create a budget that matches your commitment amount and an alert at 100 percent of the forecast
B. Set up a consolidated budget tracking lags to analyze costs in,1 granular manner
C. Set up different compartments for each department then track and analyze cost per compartment
D. Use the billing cost tracking report to analyze costs
E. Set up a tag default that automatically applies tags to all specified resources created In a compartment then use
these tags for cost analysis.
Correct Answer: ACE
budgets You can use budgets to track costs in your tenancy. After creating a budget for a compartment, you can set up
alerts that will notify you if a budget is forecast to be exceeded or if spending surpasses a certain amount. OCI Cost
Analysis Visualization tools Help understand spending patterns at a glance Filter costs by Date, Tags and
Compartments Frend lines show how spending patterns are changing To use Cost Analysis you must be a member of
the Administrators grouplead4pass 1z0-997 exam questions q7


A customer is in a process of shifting their web-based Sales application from their own data center located in the US West
to OCI India West (Mumbai) region. They want to do it in a controlled manner and initially, only 1% of the traffic will be
steered to the servers in OCI. After verification of everything is working as expected, the company is gradually planning
to increase the ratio until they are comfortable with fully migrating all traffic to OCI.
Which of the following solution can be used in this situation?
A. OCI DNS and Traffic Management with Geolocation Steering policy
B. OCI DNS and Traffic Management with Failover Steering policy
C. OCI DNS and Traffic Management with Load Balancer Steering policy
D. OCI DNS and OCI Load Balancer Service
Correct Answer: C
STEERING POLICIES is A framework to define the traffic management behavior for your zones. Steering policies
contain rules that help to intelligently serve DNS answers.
Failover policies allow you to prioritize the order in which you want answers served in a policy (for example, Primary and
Secondary). Oracle Cloud Infrastructure Health Checks are leveraged to determine the health of answers in the policy.
the Primary Answer is determined to be unhealthy, DNS traffic will automatically
be steered to the Secondary Answer.
Load Balancer policies allow the distribution of traffic across multiple endpoints. Endpoints can be assigned equal weights
to distribute traffic evenly across the endpoints or custom weights may be assigned for ratio load balancing. Oracle
Infrastructure Health Checks are leveraged to determine the health of the
endpoint. DNS traffic will be automatically distributed to the other endpoints if an endpoint is determined to be
Geolocation-based steering policies distribute DNS traffic to different endpoints based on the location of the end-user.
Customers can define geographic regions composed of originating continent, countries, or states/provinces (North
and define a separate endpoint or set of endpoints for each region.
ASN-based steering policies enable you to steer DNS traffic based on Autonomous System Numbers (ASN).
DNS queries originating from a specific ASN or set of ASNs can be steered to a specified endpoint.
IP Prefix-based steering policies enable customers to steer DNS traffic based on the IP Prefix of the originating query.


A retail company has several on-premises data centers that span multiple geographical locations. They plan to move
some of their applications from on-premises data centers to Oracle Cloud Infrastructure (OCI). For these applications
running in OCI, they still need to interact with applications running on their on-premises data centers to Oracle Cloud
Infrastructure (OCI). for these applications running in OCI. they still need to interact with applications running on their on-premises data centers. These applications require highly available, fault-tolerant network connections between on-premises data centers and OCI.
Which option should you recommend to provide the highest level of redundancy?
A. Oracle cloud Infrastructure provides network redundancy by default so that no other operations are required
B. If your data centers span multiple, geographical locations, use only the specific IP address as a static route for the
specific geographical location
C. Set up both IPSec VPN and FastConnect to connect your on-premises data centers to Oracle Cloud Infrastructure.
D. Use FastConnect private peering only to ensure secure access from your data center to Oracle Cloud Infrastructure
E. Set up a single IPSec VPN connection (from your data center to Oracle Cloud Infrastructure since It is cost-effective
Correct Answer: B
If your data centers span multiple geographical locations, we recommend using a broad CIDR ( as a static
route in addition to the CIDR of the specific geographical location. This broad CIDR provides high availability and
flexibility to your network design. For instance, the following diagram shows two networks in separate geographical
areas that each connect to Oracle Cloud Infrastructure. Each area has a single on-premises router, so two IPSec VPN
connections can be created. Note that each IPSec VPN connection has two static routes: one for the CIDR of the
particular geographical area, and a broad static route.lead4pass 1z0-997 exam questions q9


All three Data Guard Configuration is fully supported on Oracle Cloud Infrastructure (OCI). You want to deploy a
maximum availability architecture (MAA) for database workload. Which option should you consider while designing your
Data Guard configuration to ensure the best RTO and PRO without causing any data loss?
A. Configure “Maximum Protection” mode which provides zero data loss If the primary database fails.
B. Configure “Maximum Performance” mode In SYNC mode between two availability domains (same region) which
provides, the highest level of data protection that is possible without affecting the performance of the primary database.
C. Configure \\’\\’Maximum Scalability” mode which provides the highest level of scalability without compromising the
availability of the primary database.
D. Configure \\’\\’Maximum Availability” mode in SYNC mode between two availability domains (same
Correct Answer: D All
three Data Guard configurations are fully supported on Oracle Cloud Infrastructure. However, because of a high risk of
a production outage, we don\\’t recommend using the maximum protection mode for your Data Guard configuration. We
recommend using the maximum availability mode in SYNC mode between two availability domains (same region) and
using the maximum availability mode in ASYNC mode between two regions. This architecture provides you the best
RTO and RPO without causing any data loss. We recommend building this architecture in daisy-chain mode: the
primary database ships redo logs to the first standby database in another availability domain in SYNC mode, and then
the first standby database ships the redo logs to another region in ASYNC mode. This method ensures that your
primary database is not doing the double work of shipping redo logs, which can cause a performance impact on a production workload. lead4pass 1z0-997 exam questions q10

This configuration offers the following benefits:
No data loss within a region.
No overhead on the production database to maintain standbys in another region. Option to configure lagging on the DR
site if needed for business reasons. Option to configure multiple standbys in different regions without any additional
overhead on the
production database. A typical use case is a CDN application Bottom of Form


After performing maintenance on an Oracle Linux compute instance the system is returned to a running state You
attempt to connect using SSH but are unable to do so. You decide to create an instance console connection to
troubleshoot the issue. Which three tasks would enable you to connect to the console connection and begin
A. Use SSH to connect to the public: IP address of the compute Instance and provide the console connection OCID as
the username.
B. edit the Linux boot menu to enable access to the console.
C. Use SSH to connect to the service endpoint of the console connection service
D. Reboot the compute instance using the Oracle Cloud Infrastructure (OCI) Management Console
E. Upload an API signing key for console connection authentication.
F. Stop the compute Instance using the Oracle Cloud Infrastructure (OCI) Command Line Interface (CLI).
Correct Answer: BCD
The Oracle Cloud Infrastructure Compute service provides console connections that enable you to remotely
troubleshoot malfunctioning instances, such as:
An imported or customized image that does not complete a successful boot.
A previously working instance that stops responding.
the steps to connect to console and troubleshoot the OS Issue 1- Before you can connect to the serial console you need
to create the instance console connection. Open the navigation menu. Under Core Infrastructure, go to Compute and
click Instances.
Click the instance that you\\’re interested in.
Under Resources, click Console Connections.
Click Create Console Connection.
Upload the public key (.pub) portion for the SSH key. You can browse to a public key file on your computer or paste
your public key into the text box.
Click Create Console Connection.
When the console connection has been created and is available, the status changes to ACTIVE.
2- Connecting to the Serial Console
you can connect to the serial console by using a Secure Shell (SSH) connection to the service endpoint
of the console connection service
Open the navigation menu. Under Core Infrastructure, go to Compute and click Instances.
Click the instance that you\\’re interested in.
Under Resources, click Console Connections.
Click the Actions icon (three dots), and then click Copy Serial Console Connection for Linux/Mac. Paste the connection
string copied from the previous step to a terminal window on a Mac OS X or Linux system, and then press Enter to
connect to the console. If you are not using the default SSH key or ssh-agent, you can modify the serial console
Press Enter again to activate the console.
3- Troubleshooting Instances from Instance Console Connections To boot into maintenance mode
Reboot the instance from the Console.
When the reboot process starts, switch back to the terminal window, and you see Console messages start to appear in
the window. As soon as you see the GRUB boot menu appear, use the up/down arrow key to stop the automatic boot
process, enabling you to use the boot menu. In the boot menu, highlight the top item in the menu, and type e to edit the
boot entry. In edit mode, use the down arrow key to scroll down through the entries until you reach the line that starts
either linuxefi for instances running Oracle Autonomous Linux 7.x or Oracle Linux 7.x, or kernel for instances running
Oracle Linux 6.x.
At the end of that line, add the following:
Reboot the instance from the terminal window by entering the keyboard shortcut CTRL+X.


You have provisioned a new VM.DenseIO2.24 compute instance with local NVMe drives. The compute instance is
running the production application. This is a write-heavy application, with a significant impact on the business if the
application goes down. What should you do to help maintain write performance and protect against the NVMe device’s
A. NVMe drive has the built-in capability to recover themself so no other actions are required
B. Configure RAID 6 for NVMe devices.
C. Configure RAID 1 for NVMe devices.
D. Configure RAID 10 for NVMe devices.
Correct Answer: D
VM.DeselO2.24 compute instance include locally attached NVMe devices. These devices provide extremely low
latency, high-performance block storage that is ideal for big data, OLTP, and any other workload that can benefit from
high-performance block storage. A protected RAID array is the most recommended way to protect against an NVMe
device failure. There are three RAID levels that can be used for the majority of workloads: RAID 1: An exact copy (or
mirror) of a set of data on two or more disks; a classic RAID 1 mirrored pair


You are working as a cloud consultant for a major media company. In the US and your client requested to consolidate
all of their log streams, access logs, application logs, and security logs into a single system. The client wants to analyze
of their logs In real-time based on heuristics and the result should be validated as well. This validation process requires
going back to data samples extracted from the last 8 hours.
What approach should you take for this scenario?
A. Create an auto-scaling pool of Syslog-enabled servers using compute instances which will store the logs In Object
storage, then use map-reduce jobs to extract logs from Object storage and apply heuristics on the logs.
B. Create a bare-metal instance big enough to host a Syslog enabled server to process the logs and store logs on the
locally attached NVMe SSDs for rapid retrieval of logs when needed.
C. Set up an OCI Audit service and ingest all the API arils from the Audit service pragmatically to a client-side application to
apply heuristics and save the result in an OCI Object storage.
D. Stream all the logs and cloud events of Events service to Oracle Streaming Service. Build a client process that will
apply heuristics on the logs and store them in an Object Storage.
Correct Answer: D
The Oracle Cloud Infrastructure Streaming service provides a fully managed, scalable, and durable storage solution for
ingesting continuous, high-volume streams of data that you can consume and process in real-time. Streaming can be
used for messaging, ingesting high-volume data such as application logs, operational telemetry, web click-stream data,
or other use cases in which data is produced and processed continually and sequentially in a publish-subscribe
messaging model. Streaming Usage Scenarios Here are some of the many possible uses for Streaming: Metric and log
ingestion: Use the Streaming service as an alternative for traditional file-scraping approaches to help make critical
operational data more quickly available for indexing, analysis, and visualization. Messaging: Use Streaming to decouple
components of large systems. Streaming provides a pull/buffer based communication model with sufficient capacity to
flatten load spikes and the ability to feed multiple consumers with the same data independently. Key-scoped ordering
and guaranteed durability provide reliable primitives to implement various messaging patterns, while high
Infrastructure and apps event processing: Use Streaming as a unified entry point for cloud components to report their
life cycle events for audit, accounting, and related activities.

