exam questions

Exam 1z0-1072-20 All Questions

View all questions & answers for the 1z0-1072-20 exam

Exam 1z0-1072-20 topic 1 question 13 discussion

Actual exam question from Oracle's 1z0-1072-20
Question #: 13
Topic #: 1
[All 1z0-1072-20 Questions]

You created a public subnet and an internet gateway in your virtual cloud network (VCN) of Oracle Cloud Infrastructure. The public subnet has an associated route table and security list. However, after creating several compute instances in the public subnet, none can reach the Internet.
Which two are possible reasons for the connectivity issue? (Choose two.)

  • A. The route table has no default route for routing traffic to the internet gateway.
  • B. There is no stateful egress rule in the security list associated with the public subnet.
  • C. There is no dynamic routing gateway (DRG) associated with the VCN.
  • D. There is no stateful ingress rule in the security list associated with the public subnet.
  • E. A NAT gateway is needed to enable the communication flow to internet.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AATP_AWS
Highly Voted 4 years, 4 months ago
AB correct
upvoted 14 times
...
KAYSERSOZE
Highly Voted 4 years ago
A B are correct. REF: https://docs.oracle.com/en-us/iaas/Content/Network/Concepts/securitylists.htm#Default "Stateful egress: Allow all traffic. This allows instances to initiate traffic of any kind to any destination. Notice that this means the instances with public IP addresses can talk to any internet IP address if the VCN has a configured internet gateway. And because stateful security rules use connection tracking, the response traffic is automatically allowed regardless of any ingress rules. For more information, see Stateful Versus Stateless Rules." If the instance cannot reach internet, it means that its default SL doesn't have a stateful egress rule (Even though default security lists arrive with default stateful egress rule enabling All traffic for all ports rule).
upvoted 10 times
...
ductrinh
Most Recent 3 years, 4 months ago
A,B is true. no route table= nothing no ingress= internet cant see internal IP no egress= cant see internet DRG and Nat is not necessary
upvoted 2 times
...
sam_11
3 years, 4 months ago
Selected Answer: AB
You need to reach the internet, and its a public subnet. If it was a private subnet you would configure a NAT gateway.
upvoted 1 times
...
11exam_mania11
3 years, 4 months ago
correct .. AB
upvoted 1 times
...
Gupshup
3 years, 4 months ago
Answer is AB
upvoted 1 times
...
Tobbyceaser
3 years, 5 months ago
A & B Since Statefulness means if Egress is configured, Ingres would be automatically configured as well, Egress goes our to the internet, hence A,B is correct.
upvoted 2 times
...
Rowe81
3 years, 11 months ago
AD. Ingress to define in which port connections from the outside are allowed.
upvoted 2 times
MarianoD
3 years, 4 months ago
I've tried in LAB. If you create an instance within a Public Subnet and Internet Gateway, only when you delete the default stateful Egress rules, the internet navigation stop. If you rty to delete all the default stateful Ingress rules the web surfing is done in any case. So the answer is AB, dude!
upvoted 3 times
...
...
osca1069
4 years ago
A and B correct Stateful egress: Allow all traffic. This allows instances to initiate traffic of any kind to any destination. Notice that this means the instances with public IP addresses can talk to any internet IP address if the VCN has a configured internet gateway. And because stateful security rules use connection tracking, the response traffic is automatically allowed regardless of any ingress rules. For more information, see Stateful Versus Stateless Rules.
upvoted 5 times
...
ercec
4 years ago
A+B will allow instances to go put to the internet, but we need D to get to them from internet. I vote A+D
upvoted 1 times
MarianoD
3 years, 4 months ago
I've tried in LAB. If you create an instance within a Public Subnet and Internet Gateway, only when you delete the default stateful Egress rules, the internet navigation stop. If you rty to delete all the default stateful Ingress rules the web surfing is done in any case. So the answer is AB, dude!
upvoted 2 times
...
...
PietroC
4 years, 1 month ago
It's definively A, D. There is no nedd of egress rules, as they are already defined in the default SL for any IP and port: "If you've configured the public subnet to use the default security list, remember that the list includes several helpful default rules that enable basic required access (examples: ingress SSH, egress access to all destinations)."
upvoted 3 times
MarianoD
3 years, 4 months ago
I've tried in LAB. If you create an instance within a Public Subnet and Internet Gateway, only when you delete the default stateful Egress rules, the internet navigation stop. If you rty to delete all the default stateful Ingress rules the web surfing is done in any case. So the answer is AB, dude!
upvoted 1 times
...
...
Mohamed79
4 years, 1 month ago
I belive it's A and B
upvoted 2 times
...
satyalanka
4 years, 1 month ago
answer is A nd B , because instances unable to reach internet that means egress need to be enabled
upvoted 2 times
...
treborbg
4 years, 1 month ago
Ingress is when someone make a request for your CLOUD VM's, and this is not the case, as the VM's want's to access the internet, so A and B.
upvoted 1 times
...
omid25
4 years, 3 months ago
Stateful Rules Marking a security rule as stateful indicates that you want to use connection tracking for any traffic that matches that rule. This means that when an instance receives traffic matching the stateful ingress rule, the response is tracked and automatically allowed back to the originating host, regardless of any egress rules applicable to the instance. So it's A D No egress rule is needed when you define ingress rule
upvoted 3 times
...
Davar39
4 years, 4 months ago
A,B are the correct answers. -DRG is used when you want to create a path between your network and destinations other than the internet, for example your on-prem network. -Stateful ingress rules are automatically created. -Nat gateway would be used if the created network was private.
upvoted 4 times
ces26015
3 years, 6 months ago
+ Nat gateway would be used if the traffic was originated from the internet
upvoted 1 times
...
...
alfonso_223
4 years, 4 months ago
AB The servers need a stateful egress rule for reaching the internet.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago