EX282 Sample Questions & Answers
From enabling network observability with eBPF-based flow collection, the single biggest weight, to configuring node networking for providers, you'll also handle DNS forwarding, egress firewall rules, BGP peering, and isolating traffic with user-defined networks.
Launch the full EX282 simulator →Showing 6 of 12 free samples.
- Question 1IntermediateSelect 2
Manage core networking in Red Hat OpenShift Container Platform · Configure IP address management (static, host-local, DHCP) for secondary networks
A cloud architect is designing secondary network attachments across worker nodes using the
whereaboutsIPAM plugin. The cluster does not have access to an external DHCP server. Which TWO statements accurately describe the configuration options and operational constraints of thewhereaboutsCNI plugin in OpenShift Container Platform 4.20? (Select TWO)Show answer & explanation
Correct answers: A, D
The
whereaboutsCNI IPAM plugin supports definingnetwork_namewithin its IPAM configuration, enabling multipleNetworkAttachmentDefinitionresources to share the same dynamic IP address allocation pool. Furthermore, becausewhereaboutscalculates IP offsets using 64-bit integers (uint64), IPv6 subnets with prefix lengths of/64or shorter would exceed the 64-bit integer limit; therefore, narrower subnets (e.g.,/119or/120) must be used.whereaboutsallocates IPs cluster-wide rather than strictly node-local, and its reconciler runs automatically as a DaemonSet managed by the CNO.The
whereaboutsIPAM plugin uses 64-bit unsigned integers (uint64) internally to track address offsets. A standard/64IPv6 subnet contains 2^64 addresses, which causes integer overflow in offset math. Therefore, Red Hat documentation explicitly mandates that IPv6 subnets for whereabouts must use prefix lengths longer than/64(such as/119to/128). - Question 2Beginner
Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create UserDefinedNetwork resources for namespace-scoped network isolation
A developer needs to isolate a namespace named
payment-processorusing a primaryUserDefinedNetwork(UDN) with Layer 2 topology. What is the mandatory requirement regarding namespace labeling when configuring a primary user-defined network in OpenShift Container Platform 4.20?Show answer & explanation
Correct answer: B
In OpenShift Container Platform 4.20, configuring a primary UserDefinedNetwork requires that the namespace be labeled with
k8s.ovn.org/primary-user-defined-network: ""strictly when the namespace is created. OVN-Kubernetes does not support converting an existing default namespace to a primary user-defined network by appending the label after namespace creation. - Question 3Intermediate
Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create UserDefinedNetwork resources for namespace-scoped network isolation
When authoring a namespace-scoped
UserDefinedNetwork(UDN) resource withspec.topology: Layer3, which subnet fields are mandatory underspec.layer3.subnets?Show answer & explanation
Correct answer: B
Under
spec.topology: Layer3, thesubnetsstanza is mandatory and requires defining bothcidr(the total CIDR block assigned to the user-defined network across the cluster) andhostSubnet(the subnet mask length allocated to each individual node for pods on that node, e.g.,24for IPv4 or64for IPv6). In contrast, Layer 2 UDN subnets only accept a list of CIDR strings withouthostSubnetbecause Layer 2 forms a single broadcast domain across nodes. - Question 4Intermediate
Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create ClusterUserDefinedNetwork resources that span multiple namespaces
True or False: In OpenShift Container Platform 4.20, a
ClusterUserDefinedNetwork(CUDN) resource supports configuring eitherPrimaryorSecondarynetwork roles across multiple target namespaces.Show answer & explanation
Correct answer: A
This statement is false. In OpenShift Container Platform 4.20,
Primaryis the ONLY supported role for aClusterUserDefinedNetwork(CUDN). Secondary roles are supported on namespace-scopedUserDefinedNetwork(UDN) resources, but not on cluster-scopedClusterUserDefinedNetworkresources. - Question 5Advanced
Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create ClusterUserDefinedNetwork resources that span multiple namespaces
A lead platform architect is designing a multi-tenant isolation model for a microservices suite spanning two namespaces:
tenant-ordersandtenant-inventory. Both namespaces must share a single isolated Layer 2 broadcast domain with persistent IP address retention across pod restarts.Corporate compliance requires that no default cluster traffic from other application namespaces or system infrastructure namespaces can reach these pods unless explicitly permitted. The architect decides to implement a
ClusterUserDefinedNetwork(CUDN).Which configuration must the architect apply to establish this multi-namespace isolated network?
graph TD CUDN["ClusterUserDefinedNetwork: tenant-l2-net"] -->|Matches Labels| NS1["Namespace: tenant-orders"] CUDN -->|Matches Labels| NS2["Namespace: tenant-inventory"] subgraph L2Switch["Isolated OVN Logical Switch (Layer 2)"] PodA["Pod: order-service"] PodB["Pod: inv-service"] end NS1 -.-> PodA NS2 -.-> PodB PodA |Direct L2 Broadcast Domain| PodBShow answer & explanation
Correct answer: A
A
ClusterUserDefinedNetwork(CUDN) is a cluster-scoped resource (k8s.ovn.org/v1) that defines a network spanning multiple namespaces chosen byspec.namespaceSelector. In OpenShift 4.20,role: Primaryis the supported role for CUDN. Settingtopology: Layer2creates a shared logical switch across nodes for those namespaces, whileipam.lifecycle: Persistentretains allocated pod IP addresses across restarts. The CNO automatically creates the necessaryNetworkAttachmentDefinitionin every matched namespace. The default network and unselected namespaces remain isolated from this logical switch. - Question 6Intermediate
Manage DNS in Red Hat OpenShift Container Platform · Configure DNS forwarding for custom domains using the DNS operator
A cluster administrator needs to configure DNS query forwarding for an internal corporate domain
corp.internal.example.comusing the OpenShift DNS Operator. Queries must be forwarded sequentially across two corporate nameservers (10.100.0.10and10.100.0.11). If the primary nameserver does not answer, the secondary nameserver must be queried. Which configuration snippet underspec.serversin thedns.operator/defaultresource achieves this requirement?Show answer & explanation
Correct answer: D
Under
spec.serversindns.operator/default, custom forwarding zones are configured viaforwardPlugin. Thepolicyfield determines upstream server selection order;Sequentialqueries the upstream nameservers in the exact order listed, falling back to subsequent entries upon failure or timeout.Random(the default) randomly distributes queries, andRoundRobincycles sequentially without prioritizing the primary nameserver. Specifyingpolicy: Failoveror placingupstreamsoutsideforwardPluginviolates the OpenShift DNS API schema.
Ready for the real thing?
The full EX282 simulator has every exam-style question, timed mode, and instant scoring.