OCI ARCHITECT EXAM 2 FINAL PAPER 2026
SOLVED QUESTIONS AND FULL SOLUTION
UPDATED
◉ You have created a VCN with 3 private subnets. 2 of the subnets
contain application servers and the 3rd subnet contains a DB
System. The application requires a shared file system so you have
provisioned one using the file storage service (FSS). You also created
the corresponding mount target in one of the application subnets.
The VCN security lists are properly configured so that both app
servers and the DB System can access the file system. The security
team determines that the DB System should have read-only access to
the file system.
What change would you make to satisfy this requirement?
- Create an NFS export option that allows READ_ONLY access where
the source is the CIDR range of the DB System subnet
- Connect via SSH to one of the application servers where the file
system has been mounted. Use the Unix command chmod to change
permissions on the file system directory, allowing the database
userread-only acce
Answer: - Create an NFS export option that allows READ_ONLY
access where the source is the CIDR range of the DB System subnet
,Explanation
NFS export options enable you to create more granular access
control than is possible using just security list rules to limit VCN
access. You can use NFS export options to specify access levels for IP
addresses or CIDR blocks connecting to file systems through exports
in a mount target.
◉ Which 2 OCI database services allow you to dynamically scale CPU
and storage?
- bare metal DB system
- VM DB system
- ADW
- ATP
Answer: - ADW
- ATP
Explanation
- If a bare metal DB system requires more compute node processing
power, you can scale up (increase) the number of enabled CPU cores
in the system without impacting the availability of that system but
you can't increase the storage
,- If the original DB system VM shape uses a single node, running
databases on the DB system nodes are sequentially stopped and
then restarted on the new shape so not dynamic
◉ Your company has decided to move a few applications to OCI and
you have been asked to design a cloud-based DR solution. One of the
requirements is to deploy the DR resources at least 300 miles from
the home OCI region and minimize the network latency.
What will be the recommended deployment?
- Deploy production and DR applications in the same VCN. Create
production subnets in one AD, and DR subnets in another AD.
- Deploy production and DR applications in 2 separate VCNs in
different ADs within your home region, and then use a VCN remote
peering connection for connectivity
- Deploy production and DR applications in 2 separate VCNs, each in
different regions. Connect them using a VCN remote peering
connection
Deploy production and DR apps in 2 separate VCNs, each in different
regions, and then use VCN local peering gateways for connectivity
Answer: - Deploy production and DR applications in 2 separate
VCNs, each in different regions. Connect them using a VCN remote
peering connection
Explanation
, Remote VCN peering is the process of connecting two VCNs in
different regions The peering allows the VCNs' resources to
communicate using private IP addresses without routing the traffic
over the internet or through your on-prem network.
◉ Which 2 statements are true about encryption on OCI?
- By default, object storage and block storage are encrypted at rest.
- A customer is responsible for data encryption in all services of OCI
- By default, DB Systems offers an encrypted database.
- By default, NVMe drives are encrypted but the block volume
service is not
Answer: 1. By default, object storage and block storage are
encrypted at rest.
2. By default, DB Systems offers an encrypted database.
◉ Which 2 options are available when setting up DNS for your bare
metal and VM DB Systems?
• Internet and custom resolver
• Google DNS servers
• Custom resolver
• Internet and VCN resolver
Answer: • Custom resolver
SOLVED QUESTIONS AND FULL SOLUTION
UPDATED
◉ You have created a VCN with 3 private subnets. 2 of the subnets
contain application servers and the 3rd subnet contains a DB
System. The application requires a shared file system so you have
provisioned one using the file storage service (FSS). You also created
the corresponding mount target in one of the application subnets.
The VCN security lists are properly configured so that both app
servers and the DB System can access the file system. The security
team determines that the DB System should have read-only access to
the file system.
What change would you make to satisfy this requirement?
- Create an NFS export option that allows READ_ONLY access where
the source is the CIDR range of the DB System subnet
- Connect via SSH to one of the application servers where the file
system has been mounted. Use the Unix command chmod to change
permissions on the file system directory, allowing the database
userread-only acce
Answer: - Create an NFS export option that allows READ_ONLY
access where the source is the CIDR range of the DB System subnet
,Explanation
NFS export options enable you to create more granular access
control than is possible using just security list rules to limit VCN
access. You can use NFS export options to specify access levels for IP
addresses or CIDR blocks connecting to file systems through exports
in a mount target.
◉ Which 2 OCI database services allow you to dynamically scale CPU
and storage?
- bare metal DB system
- VM DB system
- ADW
- ATP
Answer: - ADW
- ATP
Explanation
- If a bare metal DB system requires more compute node processing
power, you can scale up (increase) the number of enabled CPU cores
in the system without impacting the availability of that system but
you can't increase the storage
,- If the original DB system VM shape uses a single node, running
databases on the DB system nodes are sequentially stopped and
then restarted on the new shape so not dynamic
◉ Your company has decided to move a few applications to OCI and
you have been asked to design a cloud-based DR solution. One of the
requirements is to deploy the DR resources at least 300 miles from
the home OCI region and minimize the network latency.
What will be the recommended deployment?
- Deploy production and DR applications in the same VCN. Create
production subnets in one AD, and DR subnets in another AD.
- Deploy production and DR applications in 2 separate VCNs in
different ADs within your home region, and then use a VCN remote
peering connection for connectivity
- Deploy production and DR applications in 2 separate VCNs, each in
different regions. Connect them using a VCN remote peering
connection
Deploy production and DR apps in 2 separate VCNs, each in different
regions, and then use VCN local peering gateways for connectivity
Answer: - Deploy production and DR applications in 2 separate
VCNs, each in different regions. Connect them using a VCN remote
peering connection
Explanation
, Remote VCN peering is the process of connecting two VCNs in
different regions The peering allows the VCNs' resources to
communicate using private IP addresses without routing the traffic
over the internet or through your on-prem network.
◉ Which 2 statements are true about encryption on OCI?
- By default, object storage and block storage are encrypted at rest.
- A customer is responsible for data encryption in all services of OCI
- By default, DB Systems offers an encrypted database.
- By default, NVMe drives are encrypted but the block volume
service is not
Answer: 1. By default, object storage and block storage are
encrypted at rest.
2. By default, DB Systems offers an encrypted database.
◉ Which 2 options are available when setting up DNS for your bare
metal and VM DB Systems?
• Internet and custom resolver
• Google DNS servers
• Custom resolver
• Internet and VCN resolver
Answer: • Custom resolver