exam questions

Exam 1z0-997-20 All Questions

View all questions & answers for the 1z0-997-20 exam

Exam 1z0-997-20 topic 1 question 11 discussion

Actual exam question from Oracle's 1z0-997-20
Question #: 11
Topic #: 1
[All 1z0-997-20 Questions]

An Oracle Cloud Infrastructure (OCI) Public Load Balancer's SSL certificate is expiring soon. You noticed the Load Balancer is configured with SSL Termination only. When the certificate expires, data traffic can be interrupted and security compromised.
What steps do you need to take to prevent this situation? (Choose the best answer.)

  • A. Add the new SSL certificate to the Load Balancer and update backend servers to use the new certificate bundle.
  • B. Add the new SSL certificate to the Load Balancer and update listeners to use the new certificate bundle.
  • C. Add the new SSL certificate to the Load Balancer, update listeners and backend sets so they can use the new certificate bundle.
  • D. Add the new SSL certificate to the Load Balancer, update backend servers to work with a new certificate and edit listeners so they can use the new certificate bundle.
  • E. Add the new SSL certificate to the Load Balancer and implement end to end SSL so it can encrypt the traffic from clients all the way to the backend servers.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Reference:
https://docs.cloud.oracle.com/en-us/iaas/Content/Balance/Tasks/managingcertificates.htm

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nenoAZ
Highly Voted 3 years, 9 months ago
Answer is B. It says "SSL Termination Only". Then, only it's needed to update in the listener/s. Question not talk about encrypt internal communication or change the deployed service. Otherway, update the certificate at backends will interrupt the active connections.
upvoted 9 times
...
adouban
Most Recent 1 week ago
Selected Answer: B
"SSL Termination Only"
upvoted 1 times
...
fiamma0
2 years ago
d https://docs.oracle.com/en-us/iaas/Content/Balance/Tasks/update_certificate.htm
upvoted 1 times
...
AT12
2 years, 9 months ago
I think the correct answer is D based on this: To ensure consistent service, you must update (rotate) expiring certificates: Update your client or backend server to work with a new certificate bundle. Upload the new SSL certificate bundle to the load balancer: Edit listeners or backend sets (as needed) so they use the new certificate bundle (Optional) Remove the expiring SSL certificate bundle
upvoted 1 times
...
30th
2 years, 10 months ago
Selected Answer: B
B is the correct one. If LB does the SSL termination the backend servers know nothing about certificates.
upvoted 2 times
...
Stu_Dent
2 years, 11 months ago
So correct me if I'm wrong, but isn't the whole point of SSL Termination to take the pressure away from the backend servers? Meaning they are not involved in the process in the first place so they do not need to be updated to use the new certificate. Making the answer = B https://avinetworks.com/glossary/ssl-termination/
upvoted 1 times
...
EaglEyeZ
2 years, 11 months ago
B is the correct option as the load balancer has been configured with SSL Termination only
upvoted 1 times
...
Desong
3 years ago
B is correct. https://docs.oracle.com/en-us/iaas/Content/Balance/Tasks/managingcertificates.htm To ensure consistent service, you must update (rotate) expiring certificates: Update your client or backend server to work with a new certificate bundle. 1. Upload the new SSL certificate bundle to the load balancer: 2. Edit listeners or backend sets (as needed) so they use the new certificate bundle. Remember it is OR!!!! Important Updating the backend set temporarily interrupts traffic and can drop active connections. since it is OR, we can choose update either listener OR backend. update listener is a better choice since it does not cause any disruption.
upvoted 2 times
m_b_g
2 years, 11 months ago
Certificate update on load balancer and listener is enough. B is correct
upvoted 1 times
...
...
mifune
3 years, 1 month ago
Can someone explain to me why is not correct the option D when in the documentation says in regards to the certification expiring replacement: Editing a listener: Open the navigation menu, click Networking, and then click Load Balancers. Choose the Compartment that contains the load balancer you want to modify, and then click the load balancer's name. In the Resources menu, click Listeners. For the listener you want to edit, click the Actions menu, and then click Edit Listener. In the Certificate Name list, choose the new certificate bundle. Click Submit. So the option should be C
upvoted 2 times
AJ22
3 years ago
mifune C is correct if it just stopped updating the listener only. But it also says updating the backends. So B is correct.
upvoted 2 times
...
...
jkibbee
3 years, 5 months ago
I agree with nenoAZ. The answer is B. To terminate SSL at the load balancer, you must create a listener at a port such as 443, and then associate an uploaded certificate bundle with the listener. (https://docs.oracle.com/en-us/iaas/Content/Balance/Tasks/managingcertificates.htm)
upvoted 1 times
...
Rohit_B
3 years, 11 months ago
D is the correct Answer.
upvoted 3 times
...
CMMC
3 years, 11 months ago
B since SSL termination only needs to associate the listeners with new certificate bundle; and no need to update the backend set given there is no encryption between LB and backend servers. Note A and D are not right as they are referring to backend servers (not backend set).
upvoted 2 times
bilegt
3 years, 9 months ago
You have to edit Backend sets or Listener. so D should be good
upvoted 2 times
...
...
d3vnu77
4 years ago
Answer is A if the certificate is configured to use L7. It is D if the certificates is configured L3/L4. https://serverfault.com/questions/68753/does-each-server-behind-a-load-balancer-need-their-own-ssl-certificate
upvoted 2 times
...
ankit89
4 years ago
D seems a better choice!
upvoted 3 times
...
AshGup
4 years ago
D seems to be the correct answer here.
upvoted 2 times
...
adesmaster
4 years ago
D is the correct anwer - https://docs.cloud.oracle.com/en-us/iaas/Content/Balance/Tasks/managingcertificates.htm Update your client or backend server to work with a new certificate bundle. Editing a listener
upvoted 3 times
...
ankit89
4 years ago
B is the answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago