exam questions

Exam 1z0-932 All Questions

View all questions & answers for the 1z0-932 exam

Exam 1z0-932 topic 1 question 85 discussion

Actual exam question from Oracle's 1z0-932
Question #: 85
Topic #: 1
[All 1z0-932 Questions]

You have an application server that needs to copy data on Oracle Cloud Infrastructure (OCI) object storage in the same region. You have created a service gateway for OCI object storage in your virtual cloud network (VCN) and modified security lists associated with the subnet to allow traffic to the service gateway.
You are able to connect to the OCI object storage, however, you notice that the connectivity is over the internet instead of the service gateway.
What is the reason for this behavior?

  • A. The route table associated with the subnet has no route rule where the destination is object storage service
  • B. The service gateway created in the VCN resides in a different availability domain
  • C. The security list associated with the subnet has an egress rule that allows all traffic to be forwarded to a destination CIDR 0.0.0.0/0
  • D. Identity and Access Management (IAM) policies restrict the access to the object storage bucket
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://cloud.oracle.com/en_US/bare-metal-network/vcn/faq

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
umarkhan
Highly Voted 5 years ago
A must b the correct answer
upvoted 9 times
...
MarianoD
Highly Voted 4 years, 12 months ago
I think it's A. https://docs.cloud.oracle.com/en-us/iaas/Content/Network/Tasks/servicegateway.htm Each Oracle service has a regional public endpoint that uses public IP addresses for access. When you set up a service gateway with access to an Oracle service, you also set up Networking service route rules and optionally security rules that control traffic with the service. That means you need to know the service's public IP addresses to set up those rules. To make it easier for you, the Networking service uses service CIDR labels to represent all the public CIDRs for a given Oracle service or a group of Oracle services.
upvoted 6 times
...
alfonso_223
Most Recent 4 years, 4 months ago
The SG uses a service CIDR label. You use that service CIDR label when you configure the service gateway and related route rules to control traffic to the service. The key is "related route rules", you need to set route rules for fw trafic to the SG. My option is A
upvoted 1 times
...
Anirban_ITArchitect
4 years, 9 months ago
A is the right answer
upvoted 2 times
...
Scunningham99
4 years, 9 months ago
A is right you need a route to dest service gateway
upvoted 2 times
...
technicalguru
4 years, 9 months ago
Agreed with A
upvoted 1 times
...
Zek
4 years, 9 months ago
I agree with A, reading through the link provided by MarianoD "The service gateway is regional and enables access only to supported Oracle services in the same region as the VCN." This would eliminate option B . A looks the correct answer to me
upvoted 3 times
...
DanielNieto
4 years, 12 months ago
Agree A
upvoted 4 times
...
SIDNEY1
5 years ago
The question says the bucket is accessible. Rules out A and D. On careful reading, C looks to to be right answer, with that rule in there all traffic would hit the default gateway (not the service gateway), go out via the internet to the bucket. Maybe C's the answer? I don't think inter-AD traffic goes out the internet. Inter-region does. Anyone have further ideas?
upvoted 2 times
papayahead
4 years, 9 months ago
The question says the bucket is accessible but via Internet Gateway. It means routing rule routes to Internet Gateway, not Service Gateway. The egress rule in C needs to be there either way.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago