EX282 Sample Questions

EX282 Sample Questions & Answers

From enabling network observability with eBPF-based flow collection, the single biggest weight, to configuring node networking for providers, you'll also handle DNS forwarding, egress firewall rules, BGP peering, and isolating traffic with user-defined networks.

Launch the full EX282 simulator →

Showing 6 of 12 free samples.

  1. Question 1IntermediateSelect 2

    Manage core networking in Red Hat OpenShift Container Platform · Configure IP address management (static, host-local, DHCP) for secondary networks

    A cloud architect is designing secondary network attachments across worker nodes using the whereabouts IPAM plugin. The cluster does not have access to an external DHCP server. Which TWO statements accurately describe the configuration options and operational constraints of the whereabouts CNI plugin in OpenShift Container Platform 4.20? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    The whereabouts CNI IPAM plugin supports defining network_name within its IPAM configuration, enabling multiple NetworkAttachmentDefinition resources to share the same dynamic IP address allocation pool. Furthermore, because whereabouts calculates IP offsets using 64-bit integers (uint64), IPv6 subnets with prefix lengths of /64 or shorter would exceed the 64-bit integer limit; therefore, narrower subnets (e.g., /119 or /120) must be used. whereabouts allocates IPs cluster-wide rather than strictly node-local, and its reconciler runs automatically as a DaemonSet managed by the CNO.

    The whereabouts IPAM plugin uses 64-bit unsigned integers (uint64) internally to track address offsets. A standard /64 IPv6 subnet contains 2^64 addresses, which causes integer overflow in offset math. Therefore, Red Hat documentation explicitly mandates that IPv6 subnets for whereabouts must use prefix lengths longer than /64 (such as /119 to /128).

  2. Question 2Beginner

    Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create UserDefinedNetwork resources for namespace-scoped network isolation

    A developer needs to isolate a namespace named payment-processor using a primary UserDefinedNetwork (UDN) with Layer 2 topology. What is the mandatory requirement regarding namespace labeling when configuring a primary user-defined network in OpenShift Container Platform 4.20?

    Show answer & explanation

    Correct answer: B

    In OpenShift Container Platform 4.20, configuring a primary UserDefinedNetwork requires that the namespace be labeled with k8s.ovn.org/primary-user-defined-network: "" strictly when the namespace is created. OVN-Kubernetes does not support converting an existing default namespace to a primary user-defined network by appending the label after namespace creation.

  3. Question 3Intermediate

    Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create UserDefinedNetwork resources for namespace-scoped network isolation

    When authoring a namespace-scoped UserDefinedNetwork (UDN) resource with spec.topology: Layer3, which subnet fields are mandatory under spec.layer3.subnets?

    Show answer & explanation

    Correct answer: B

    Under spec.topology: Layer3, the subnets stanza is mandatory and requires defining both cidr (the total CIDR block assigned to the user-defined network across the cluster) and hostSubnet (the subnet mask length allocated to each individual node for pods on that node, e.g., 24 for IPv4 or 64 for IPv6). In contrast, Layer 2 UDN subnets only accept a list of CIDR strings without hostSubnet because Layer 2 forms a single broadcast domain across nodes.

  4. Question 4Intermediate

    Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create ClusterUserDefinedNetwork resources that span multiple namespaces

    True or False: In OpenShift Container Platform 4.20, a ClusterUserDefinedNetwork (CUDN) resource supports configuring either Primary or Secondary network roles across multiple target namespaces.

    Show answer & explanation

    Correct answer: A

    This statement is false. In OpenShift Container Platform 4.20, Primary is the ONLY supported role for a ClusterUserDefinedNetwork (CUDN). Secondary roles are supported on namespace-scoped UserDefinedNetwork (UDN) resources, but not on cluster-scoped ClusterUserDefinedNetwork resources.

  5. Question 5Advanced

    Implement and manage user-defined networks in Red Hat OpenShift Container Platform · Create ClusterUserDefinedNetwork resources that span multiple namespaces

    A lead platform architect is designing a multi-tenant isolation model for a microservices suite spanning two namespaces: tenant-orders and tenant-inventory. Both namespaces must share a single isolated Layer 2 broadcast domain with persistent IP address retention across pod restarts.

    Corporate compliance requires that no default cluster traffic from other application namespaces or system infrastructure namespaces can reach these pods unless explicitly permitted. The architect decides to implement a ClusterUserDefinedNetwork (CUDN).

    Which configuration must the architect apply to establish this multi-namespace isolated network?

    graph TD CUDN["ClusterUserDefinedNetwork: tenant-l2-net"] -->|Matches Labels| NS1["Namespace: tenant-orders"] CUDN -->|Matches Labels| NS2["Namespace: tenant-inventory"] subgraph L2Switch["Isolated OVN Logical Switch (Layer 2)"] PodA["Pod: order-service"] PodB["Pod: inv-service"] end NS1 -.-> PodA NS2 -.-> PodB PodA |Direct L2 Broadcast Domain| PodB
    Show answer & explanation

    Correct answer: A

    A ClusterUserDefinedNetwork (CUDN) is a cluster-scoped resource (k8s.ovn.org/v1) that defines a network spanning multiple namespaces chosen by spec.namespaceSelector. In OpenShift 4.20, role: Primary is the supported role for CUDN. Setting topology: Layer2 creates a shared logical switch across nodes for those namespaces, while ipam.lifecycle: Persistent retains allocated pod IP addresses across restarts. The CNO automatically creates the necessary NetworkAttachmentDefinition in every matched namespace. The default network and unselected namespaces remain isolated from this logical switch.

  6. Question 6Intermediate

    Manage DNS in Red Hat OpenShift Container Platform · Configure DNS forwarding for custom domains using the DNS operator

    A cluster administrator needs to configure DNS query forwarding for an internal corporate domain corp.internal.example.com using the OpenShift DNS Operator. Queries must be forwarded sequentially across two corporate nameservers (10.100.0.10 and 10.100.0.11). If the primary nameserver does not answer, the secondary nameserver must be queried. Which configuration snippet under spec.servers in the dns.operator/default resource achieves this requirement?

    Show answer & explanation

    Correct answer: D

    Under spec.servers in dns.operator/default, custom forwarding zones are configured via forwardPlugin. The policy field determines upstream server selection order; Sequential queries the upstream nameservers in the exact order listed, falling back to subsequent entries upon failure or timeout. Random (the default) randomly distributes queries, and RoundRobin cycles sequentially without prioritizing the primary nameserver. Specifying policy: Failover or placing upstreams outside forwardPlugin violates the OpenShift DNS API schema.

Ready for the real thing?

The full EX282 simulator has every exam-style question, timed mode, and instant scoring.

Go to the EX282 simulator →