Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 1z0-997-20 topic 1 question 10 discussion

Actual exam question from Oracle's 1z0-997-20
Question #: 10
Topic #: 1
[All 1z0-997-20 Questions]

You designed and deployed your Autonomous Data Warehouse (ADW) so that it is accessible from your on-premise data center and servers running on both private and public networks in Oracle Cloud Infrastructure (OCI).

As you are testing the connectivity to your ADW database from the different access paths, you notice that the server running on the private network is unable to connect to ADW.
Which two steps do you need to take to enable connectivity from the server on the private network to ADW? (Choose two.)

  • A. Add an entry in the Security List of the ADW allowing ingress traffic for CIDR block 10.2.2.0/24
  • B. Add an entry in the route table (associated with the private subnet) with destination of 0.0.0.0/0; target type of NAT Gateway, add a stateful egress rule to the security list (associated with the private subnet) with destination of 0.0.0.0/0 and for all IP protocols.
  • C. Add an entry in the access control list of ADW for IP address 129.146.160.11
  • D. Add an entry in the route table (associated with the private subnet) with destination of 0.0.0.0/0; target type of Internet Gateway, add a stateful egress rule to the security list (associated with the private subnet) with destination of 0.0.0.0/0 and for all IP protocols.
  • E. Add an entry in the access control list of ADW for CIDR block 10.2.2.0/24.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ankit89
Highly Voted 3 years, 4 months ago
B and C are correct, there seems to be an IP typo though.
upvoted 8 times
...
Osong
Highly Voted 3 years, 5 months ago
Not true. the ADW has no idea what the private IP address means to it. It needs the public IP of the NAT gateway. It should be B and C
upvoted 7 times
...
Ludo
Most Recent 1 year, 3 months ago
Selected Answer: BC
A is wrong because the ADW has no Security List. B is correct as the private subnet needs a route entry to exit on internet through the NAT gateway C is "correct" because the ADW's ACL needs an entry for 129.145.160.11 (either the diagram or the C answer has got a typo, the second octect should match). D is wrong, a private subnet has no use for an Internet Gateway E is wrong, as the 10.2.2.0/24 CIDR block is hidden by the NAT Gateway and not visible by the ADW
upvoted 1 times
...
Attaxhan
2 years, 1 month ago
in the exam today
upvoted 1 times
...
30th
2 years, 2 months ago
Selected Answer: BC
B,C... ignoring the typo in the answer C
upvoted 1 times
...
Scipio88
2 years, 3 months ago
Correct Answers are B and C, here are the documentation links for the explanation I gave: https://docs.public.oneportal.content.oci.oraclecloud.com/en-us/iaas/Content/Database/Tasks/adbcreating_topic-Adding_an_access_control_list_ACL_to_your_database.htm https://docs.public.oneportal.content.oci.oraclecloud.com/en-us/iaas/adbnetworkaccess/network-access-control-list-configure.html https://docs.oracle.com/en/cloud/paas/autonomous-database/adbsa/network-access-control-list-configure.html#GUID-B6389402-3F4D-45A2-A4DE-EAF1B31D8E50
upvoted 1 times
...
Scipio88
2 years, 3 months ago
Correct Answers are B and C Can someone update the answers? For Option A: Security List, since sec lists are at subnet level ADW doesn’t have a security list. If it did have a list it and would need source, dest, and type of traffic. Not enough info for option A and doesn’t apply to ADW. For Option D: Resources that need to connect to the Internet must be in a PUBLIC subnet and have a PUBLIC IP address. A private subnet would need to go through a NAT. Therefore, Option D is not valid. For Option E: is ruled out due to the given CIDR block being private when a public one is needed. That’s why it goes through the NAT. ADW Access Control List (ACL): IP address in the ACL is the PUBLIC facing address on the public internet that you want to grant access. CIDR Block, is the public CIDR block of the clients that are visible on the public internet that you want to grant access.
upvoted 1 times
...
m_b_g
2 years, 4 months ago
Selected Answer: BC
B&C are correct answers.
upvoted 1 times
...
EaglEyeZ
2 years, 4 months ago
B & C are the correct options. please see; https://docs.oracle.com/en-us/iaas/adbnetworkaccess/network-access-control-list-notes.html
upvoted 1 times
...
plafaurie
2 years, 7 months ago
C is wrong, because the IP address, in the graph is 129.145.160.11 and in the answer it is 129.146.160.11, it has the second different octet
upvoted 2 times
plafaurie
2 years, 7 months ago
I did the exam and I passed, they asked me this question, the IPs are the same between the diagram and the answer, therefore the answer C is correct.
upvoted 7 times
AJ22
2 years, 4 months ago
We need two answers here.
upvoted 1 times
...
...
...
bjmC
3 years, 4 months ago
Its B and E. So - we largely agree that B is correct. So its down to whether the access Contrl List needs the CLIENT or the PRIVATE SUBNET adding. - C is wrong as the question isnt about accessing from the CLIENT computer, its about accessing from the PRIVATE SUBNET.
upvoted 1 times
bjmC
3 years, 4 months ago
Scratch that - helps if I can read the IP addresses correctly. its B and C!
upvoted 1 times
...
...
rc_1030
3 years, 5 months ago
Answer C and the NAT Gateway Public IP address doesn't match. Suppose it's a typo, otherwise C cannot be the answer
upvoted 2 times
...
fhoyos
3 years, 5 months ago
A&B.. Correct
upvoted 2 times
fhoyos
3 years, 5 months ago
Correct is B&C . the NAT gateway ip address is required to be in the ACL. Ensure that the Access Control List for the Autonomous Database (ADB) has the necessary entries for CIDR Block ranges and IP addresses. When connecting to ADB from a server running on a private subnet (on the same OCI tenancy as the ADB), ensure that you have a service gateway or NAT gateway attached to the VCN. The route table for the subnet needs to have the appropriate routing rules for the service gateway or NAT gateway. The security lists for the subnet will need to have the right egress rules.
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...