Domain 1: Identity and Access Management
- The tenancy and compartment hierarchy for organizing and isolating resources.
- Writing least-privilege policies: the allow group to verb resource-type in compartment syntax, and the verb ladder inspect, read, use, manage.
- Dynamic groups and resource principals so instances and functions can call OCI APIs securely.
- Network Sources and tag-based access control for conditional access.
- Identity domains, federation with an external identity provider, and MFA.
- IAM policy optimization (new in 2025) to simplify and audit existing policies, plus Security Zones and Cloud Guard for governance.
Domain 2: Networking
- VCN design: public and private subnets, VNICs, and IP addressing.
- Choosing the right gateway: Internet Gateway, NAT Gateway, Service Gateway, and Dynamic Routing Gateway, with route table design.
- Security Lists (subnet level) versus Network Security Groups (VNIC level), and stateful versus stateless rules.
- Hybrid and multi-VCN connectivity: Site-to-Site VPN, FastConnect, and Local versus Remote Peering, including transit routing for hub-and-spoke topologies.
- DNS (public and private zones and views) and Traffic Management steering policies for failover and geolocation.
- Load Balancer (Layer 7) versus Network Load Balancer (Layer 4), plus network troubleshooting tools (Network Path Analyzer, Network Visualizer) and Bastion for private access.
Domain 3: Compute
- Selecting compute shapes: flexible VM shapes, dense I/O, GPU, HPC, and bare metal, and virtual machine versus bare metal tradeoffs.
- Custom versus platform images, and image import and export.
- Autoscaling (schedule-based and metric-based) using Instance Pools and Instance Configurations.
- Capacity Reservations and Dedicated Virtual Machine Hosts for isolation and compliance.
- Designing high availability with fault domains and availability domains.
- OS Management Hub (new in 2025) for centralized patching and compliance, plus awareness of OKE and Functions.
Domain 4: Storage
- Block Volume performance tiers, boot volumes, Volume Groups, backups, clones, and cross-region replication.
- Object Storage tiers (Standard, Infrequent Access, Archive), pre-authenticated requests, lifecycle policies, versioning, and replication.
- File Storage with mount targets, exports, snapshots, clones, and replication.
- Choosing the right storage type and tier for an access pattern, durability need, and cost target.
- Backup and disaster-recovery design that spans block, object, and file storage.
- Encryption of data at rest using Vault keys.
Oracle Cloud Infrastructure 2025 Architect Associate (1Z0-1072-25) exam tips
- Networking is the largest domain at 35 percent, so invest the most preparation there. Be able to design VCN topologies, pick the correct gateway, choose Security Lists versus NSGs, and connect environments with VPN, FastConnect, and local or remote peering.
- This is an architect exam: expect scenario questions that give requirements (high availability, disaster recovery, cost, security) and ask for the best design. Practice reasoning about fault domains, availability domains, and multi-region replication for RTO and RPO targets.
- Know the two 2025 additions: OS Management Hub in Compute (centralized patch and compliance management) and IAM Policy Optimization (simplifying and auditing existing policy sets).
- For IAM, be fluent in policy syntax and the verb ladder (inspect, read, use, manage), dynamic groups and resource principals, and conditional access with Network Sources and tags. Security shows up inside the IAM and Networking domains, not as a separate section.
- For Storage, master the managed distinctions: Block versus Object versus File, the Object Storage tiers, and when replication, backups, clones, or pre-authenticated requests are the right tool. Choosing the right tier for cost and access pattern is a common question.
Study guide FAQ
How many questions are on the exam and what is the passing score?
The exam has about 50 multiple-choice and multiple-response questions in 90 minutes, with a passing score of roughly 68 percent. It is delivered through Pearson VUE at a test center or online with a proctor, and the certification is valid for two years.
What are the exam domains and their weights?
Four domains: Identity and Access Management (20%), Networking (35%), Compute (20%), and Storage (25%). There is no separate Database or Security domain - security topics are covered within the IAM and Networking domains.
Do I need experience or the Foundations certification first?
There are no formal prerequisites, but Oracle recommends about six months of hands-on OCI design and implementation experience. Holding the OCI Foundations Associate first is helpful but not required.
What changed in the 2025 version?
The 2025 refresh (1Z0-1072-25) added OS Management Hub content in the Compute domain and IAM Policy Optimization in the IAM domain. The overall four-domain structure (IAM, Networking, Compute, Storage) is unchanged from prior years.
Is CertGrid practice official Oracle material?
No. CertGrid is an independent practice platform and is not affiliated with or endorsed by Oracle. These questions are original and written to mirror the current exam objectives so you can rehearse them. Always confirm the current exam topics on Oracle's certification site before your exam.