Oracle Database Cloud Service

Question No: 11

You want to control network traffic among your DBaaS instances. Which two statements are true about network groups?

  1. By default, the DBaaS instances in a network group are accessible from hosts outside the network group.

  2. You can add a DBaaS instance to a network group, but this enables communication only within this network group.

  3. You can add a DBaaS instance to a network group, thus enabling communication with all other DBaaS instances both inside and outside thenetwork group.

  4. You can create a network group to enable unrestricted communication among your DBaaS instances.

  5. DBaaS prevents network groups from having unrestricted communication among DBaaS instances.

Answer: B,E Explanation:

Network groups provide a method for VMs to be grouped together forcommunications and firewall rules. You can define network groups to allow VMs within agroup to communicate with each other, while also preventing those VMs fromcommunicating outside the group.


Access rule. Access rules define the permitted paths of communication for VMs that are within a network group. You can define an access rule to enable a specific path of communication between two network groups, orbetween a network group and a specified list of IP addresses.

References:http://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/dbaas/OU/Intr oDBaaS/ConfiguringNetworkSettings/ConfiguringNetworkSettings.html#section2s2

Question No: 12

You want to apply a patch to your Oracle Database Cloud – Database as a Service. What command will you execute to patch your database instance?

  1. dbaascli dbpatchm -run -config

  2. dbaascli dbpatchm -run -setup

  3. dbaascli dbpatchm -run-apply

  4. dbaascli dbpatchm -run -patch

Answer: C Explanation:

Options of the command: dbaascli dbpatchm apply – applies the patch.

clonedb – applies a patch to a test deployment. list_patches – displays a list of available patches.

list_tools – checks whether anycloud tooling updates are available. prereq – checks the prerequisites of a patch.

rollback – rolls back the last deployment patch. switchback – restores database software to a prior state. toolsinst – downloads

References: References: Using Oracle Database Cloud Service (February 2018), page D-1 https://docs.oracle.com/en/cloud/paas/database-dbaas-cloud/csdbi/using-oracle-database- cloud-service.pdf

Question No: 13

You did not configure Backup and Recovery during instance creation. You therefore need to schedule your backup strategy with RMAN.

Which two tasks would you need to perform to customize the backup configuration?

  1. Use thebkup_apiutility logged in as theoracleuser to reconfigure the retention period and cycle period of the backups.

  2. Edit the/home/oracle/bkup/oscfg.specspecification file that is used by the DBaaS backup feature to maintain the list of system files and folders that are to be backed up.

  3. Edit the/home/oracle/bkup/dbcfg.specspecification file that is used by the DBaaSbackup feature to maintain the list of database configuration files that are to be backed up.

  4. Usedbms_schedulerto perform automatic backups.

Answer: A,C Explanation:

A:You can use the bkup_api utility to create an on-demand backup of a database deployment hostinga single-instance database or an Oracle Data Guard configuration.

By default, the backup is given a timestamp-based tag. To specify a custom backup tag, add the -tag option to the bkup_api command; for example, to create a longterm backup with the tag quot;monthlyquot;, enter the following command:

# /var/opt/oracle/bkup_api/bkup_api bkup_start -keep -tag=monthly

C.Customizing Which Database Configuration Files Are Backed Up To change which database configuration files are backed up:

References: Using Oracle Database Cloud Service (February 2018) , pages 6-4, 6-10 https://docs.oracle.com/en/cloud/paas/database-dbaas-cloud/csdbi/using-oracle-database- cloud-service.pdf

Question No: 14

You created your Database as a Service (DBaaS) database instance. Predefined network access rules are also created.

Which two predefined network access rules are created when you created the DBaaS database instance?

  1. Theora_p2_sshaccess rule for the public-internet network group is created to communicate with theora_dbpredefined network group over SSH.

  2. Theora_db_publicaccess rules to manage database access through the default port 1521 and theora_db_adminaccess rules for SSH connection via SQL*Net through port 5500 are created.

  3. Theora_access dbaccess rule for SSH connection via PuTTY is created to configure network rules andora_access_consolefor HTTPS access to Oracle Cloud Services Console.

  4. No access rules are created by default and users must manually configure all access rules.

  5. Theora_p2_dblisteneraccess rule for the public-internet network group (any host on the Internet) is created to communicate with theora_dbpredefined network group over SQL*Net.

Answer: A,E Explanation:

When a database deployment is created, the following Oracle Compute Cloud Servicesecurity rules are created, but set to a disabled status.

References: References: Using Oracle Database Cloud Service (February 2018), page A-5 https://docs.oracle.com/en/cloud/paas/database-dbaas-cloud/csdbi/using-oracle-database- cloud-service.pdf

Question No: 15

Users must be granted roles to manage Cloud services.

Which three statements are true about roles and role assignment in Database as a Service (DBaaS)?

  1. Service administrators can assign and remove roles only for users of theservices that they manage.

  2. The DBaaS Database Administrator role permits granting the DBaaS Database Administrator or DBaaS Database Operator role to existing users.

  3. Identity domain administrators can assign and remove roles for users in any identitydomains.

  4. The DBaaS Database Operator role permits the ability to scale, patch, and backup or restore service instances.

  5. DBaaS network administrators can grant access privileges to designated users.

Answer: A,D,E Explanation:

A: A Service administrator manages administrative functions related to Oracle Cloud services within an identity domain.

D: The privileges given to the DBaaS Database Administrator role include: Can scale, patch, and back up or restore database deployments

Question No: 16

Which are two of the tasks that must be performed to enable SQL*NET access for your DBaaS database instance over SSL?

  1. You must open a port on the virtual machine (VM) that is hosting the instance.

  2. You use Net Manager (NETMGR) to configure a database alias and set the connect string.

  3. You use Oracle Connection Manager to configure the required network settings.

  4. You must configure SSL support on the instance.

Answer: A,B Explanation:

SQL*Net is Oracle#39;s remote data access protocol that enables client-server and server- server communications across networks.

An Oracle client connects to the server using the port address of the listener, which is normally defined as TCP port 1521 during Oracle installation.

Oracle Net Manager is a utility used for configuring SQL*Net.

Question No: 17

You want to use traditional GUI tools on a Database as a Service (DBaaS) instance. You have configured PuTTY and SSH sessions.

What two things would you need to configure?

  1. X server program

  2. VPN connection

  3. X11 forwarding

  4. Remote Desktop Connection

Answer: C,D Explanation:

The key benefitsof using X11 over SSH is:

Server can have less packages installed.

None of the desktop packages and services need to be installed (such as CUPS, Bluetooth, amp; Network Manager). Freeing CPU amp; Memory on the server.

User accesses server over a secure connection. Graphics are tunneled over SSH.

Question No: 18

How do you enable a default connection between Database as a Service (DBaaS) instances?

  1. by creating network groups and adding the instances that you want to communicate to that group

  2. by creatingdedicated communication keys and setting them to be used only for your DBaaS instance-to-instance communication

  3. by creating nothing for communication between the DBaaS instances because all instances are interconnected by default

  4. by installing and configuring theNETMGRutility for your DBaaS environment, and then using it to set up the required communication channels

Answer: B Explanation:

Before your DBaaS database was created, you or a coworker generated a private and public SSH key pair, perhaps using PuTTY Key Generator.

The public key was specified when your database instance was created; a copy of that public key was stored in the VM hosting your database.

When you define in PuTTY an SSH connection to the VM hosting your database, you will specify a copy ofthe private key stored on your local PC. When you initiate a PuTTY connection, the VM compares the private key to the matching public key stored in the VM. The VM permits the connection when the private and public key match as a valid key pair.

References:http://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/dbaas/obe_d baas_connecting_to_an_instance/obe_dbaas_connecting_to_an_instance.html

Question No: 19

You created a Database as a Service (DBaaS) instance. This action also created a virtual machine and configured it for the DBaaS instance. It also created two user accounts. One of the users is oracle.

What three functions can the oracle user perform?

  1. Grant privileges and roles to database users.

  2. Create database users.

  3. Back up and recover databases.

  4. Create tablespaces.

  5. Reboot a VM.

  6. Use thesudocommand to perform root user access operations.

Answer: A,B,C Explanation:

oracle is the Oracle Database administrator account you use to access the system and perform non-root database administration tasks. A home directory, /home/oracle, is created forthis user. This user cannot use the sudo command to perform operations that require root-user access. Additionally, by default you cannot connect as this user to the compute node using SSH. You can add the public key to the user’s $HOME/.ssh/authorized_keys file to grant persistent SSH access, or you can connect as the opc user and then use the

sudo -s command to start a root-user command shell, followed by an su – oracle command to switch to the oracle user.

Question No: 20

How would you enable a port persistently to keep communication open through that port always?

  1. To enable a port persistently, you must contact your DBaaS support team to update the port specifications for use.

  2. You can use server certificates to map a server’s identity to enable persistent connection through a port to DBaaS instances.

  3. All ports that are available in DBaaS servers must use an SSH tunnel and cannot be enabled persistently.

  4. To enable a port persistently, you would require access to the Compute Cloud Service Console to open the ports to a set of IP addresses.

Answer: A

