Courseiva
NetworkingmediumMultiple ChoiceObjective-mapped

1Z0-1072-26 Networking Practice Question

An administrator configured a Network Security Group (NSG) and a Security List for a compute instance in a subnet. The Security List denies port 443 inbound, but the NSG associated with the instance's primary VNIC explicitly allows port 443 inbound from any source. What will happen when external traffic attempts to access the instance on port 443?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Traffic will be allowed because Security List and NSG rules are additive.

OCI security rules are evaluated additively. If either the Security List or the applicable NSG allows the traffic, the traffic is permitted. Therefore, port 443 traffic will be allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Traffic will be blocked due to the default stateless nature of NSGs.

    Why it's wrong here

    OCI Security Lists and NSGs are stateful by default.

  • Traffic will be dropped because both components must explicitly allow the traffic for it to pass.

    Why it's wrong here

    They do not both need to allow it; they operate on an 'allow if either permits' logic.

  • Traffic will be dropped because Security Lists take precedence over Network Security Groups.

    Why it's wrong here

    Security Lists and NSGs are evaluated together; if either allows the traffic, it is permitted.

  • Traffic will be allowed because Security List and NSG rules are additive.

    Why this is correct

    Traffic is allowed if permitted by either a Security List or an associated Network Security Group.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This 1Z0-1072-26 question is part of Courseiva's 521-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Oracle exam blueprint

This 1Z0-1072-26 practice question is part of Courseiva's free Oracle certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Z0-1072-26 exam.