EX280 Sample Questions & Answers
Free Red Hat Certified OpenShift Administrator practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full EX280 simulator →Showing 6 of 12 free samples.
- Question 1Advanced
Declarative Resource Management · Work with Kustomize overlays
Your organization requires a specific set of Kustomize overlays for deploying an application to Development, Stage, and Production environments. You have a 'base' directory containing the common deployment.yaml and service.yaml. You need to ensure the Production overlay scales the replicas to 5 and changes the image tag to 'stable'.
Which file structure and content is correct for the production overlay?
Show answer & explanation
Correct answer: D
The standard Kustomize overlay pattern involves a kustomization.yaml file in the overlay directory (e.g., /overlays/production). It must reference the base resources using the 'resources' field and apply environment-specific changes using 'patches' (or 'patchesStrategicMerge').
graph TD Base[Base Directory] -->|Contains| Dep[deployment.yaml] Base -->|Contains| Svc[service.yaml] Overlay[Overlay: Production] -->|References| Base Overlay -->|Applies| Patch[Replica & Image Patch] Patch -.->|Modifies| Dep - Question 2Beginner
Manage authentication and authorization · Modify user and group permissions
You need to grant a specific user, 'alice', the ability to view all resources in the 'marketing' project, but she should not be able to modify any resources. Which command achieves this using the default ClusterRoles?
Show answer & explanation
Correct answer: D
The command 'oc adm policy add-role-to-user' creates a RoleBinding within the specified namespace ('-n marketing'). The 'view' ClusterRole provides read-only access to most resources, which meets the requirement. Using 'add-cluster-role-to-user' would grant her view access to the entire cluster, which violates the principle of least privilege.
- Question 3Intermediate
Enable developer self-service · Configure cluster resource quotas
A database pod in the 'db-prod' project keeps restarting with an 'OOMKilled' error. You determine that the application needs more memory than the current limit allows. The project has a ResourceQuota 'quota-prod' with 'limits.memory: 10Gi' and 'used: 9.5Gi'. The pod requests 1Gi. What must you do to successfully deploy the fix?
Show answer & explanation
Correct answer: C
The project is currently using 9.5Gi out of a 10Gi limit. Increasing the pod's memory requirement (which is already 1Gi) would push the total usage beyond the 10Gi quota. Therefore, you must first expand the ResourceQuota to accommodate the new requirement before the pod can be successfully scheduled with higher limits.
- Question 4Intermediate
Manage OpenShift operators · Install an operator
You are tasked with installing the 'Web Terminal' Operator from the OperatorHub. You want to ensure that the Operator is installed in all namespaces and that it automatically updates whenever a new version is available in the 'stable' channel. Which resource should you configure to define the channel and approval strategy?
Show answer & explanation
Correct answer: B
The Subscription resource is the control point for the Operator Lifecycle Manager (OLM). It links an Operator package to a CatalogSource and defines the update channel (e.g., 'stable') and the install plan approval strategy (Automatic vs Manual).
- Question 5Advanced
Configure application security · Manage and apply permissions using security context constraints
An application in the 'hr-app' project requires the ability to run as a specific user ID (UID 5000) defined in its Dockerfile. By default, OpenShift assigns an arbitrary UID. What is the most secure and appropriate way to allow this specific UID for the application's ServiceAccount?
Show answer & explanation
Correct answer: C
Creating a custom SCC with 'MustRunAs' and the specific UID (5000) is the principle of least privilege. It allows exactly what is needed without granting the broad and dangerous permissions associated with the 'privileged' or 'anyuid' SCCs.
- Question 6Intermediate
Configure network security · Configure application network policies
You are defining a NetworkPolicy to isolate the 'backend' pods. The policy must block all incoming traffic to 'backend' pods except for traffic originating from pods with the label 'role=frontend' in the same namespace. Which ingress rule configuration achieves this?
Show answer & explanation
Correct answer: A
This configuration specifies an ingress rule that allows traffic FROM pods matching the selector 'role: frontend'. By default, if a NetworkPolicy selects pods but provides an empty or specific ingress rule, all other traffic is denied. Since no 'namespaceSelector' is provided, it implies the same namespace.
Ready for the real thing?
The full EX280 simulator has every exam-style question, timed mode, and instant scoring.