EX362 Sample Questions & Answers
Spans configuring IdM users and their access policies, the single biggest weight, plus Kerberized service configuration, single sign-on clients, managing secret vaults and the certificate authority, installing IdM servers and replicas, and maintenance.
Launch the full EX362 simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Implement Single Sign-On (SSO) · Verify SSO client operation
A developer needs to configure a Linux web server to authenticate users using Kerberos Single Sign-On (SSO). You have installed
mod_auth_gssapiand created the service principalHTTP/webserver.example.com.After generating the keytab, users report receiving a '401 Unauthorized' error when accessing the site, and the Apache error logs show 'gss_acquire_cred() failed'.
What is the most likely cause of this issue?
Show answer & explanation
Correct answer: A
The error
gss_acquire_cred() failedtypically indicates that the application (Apache) cannot read the credentials required to authenticate itself to the KDC. This is most often caused by the keytab file having strict permissions (e.g., 600 root:root) that prevent theapacheservice user from reading it. - Question 2Intermediate
Create and Configure IdM Users and User Policies · Use Ansible to configure and manage IdM users
You are tasked with automating the onboarding of 500 new developers. They require a specific set of HBAC rules and sudo privileges. You decide to use Ansible to manage this configuration.
Which Ansible module from the
ansible-freeipacollection should you use to ensure that the developer group exists and includes all 500 users, while maintaining idempotency?Show answer & explanation
Correct answer: A
The
ipagroupmodule is designed to manage IdM user groups. It supports adding members (users) to a group in an idempotent way using theuserparameter andstate: present. - Question 3Advanced
Manage the IdM Integrated Certificate Authority · Create secret vaults
A security audit requires that a specific department's sensitive secrets be stored in a way that allows the application to encrypt data using the vault's public key, but only the central IdM service can decrypt it using the private key for retrieval.
Which type of IdM vault should you create to meet this requirement?
Show answer & explanation
Correct answer: C
An asymmetric vault generates a key pair. The public key can be distributed to clients to encrypt data (archive) locally, but the private key remains securely in the KRA (Key Recovery Authority) and is used only for decryption (retrieval).
- Question 4Intermediate
Install and Configure an IdM Client · Install and configure IdM clients
You need to configure a new IdM client using
authselect. The security policy mandates that the system must strictly use SSSD for authentication and must create home directories automatically upon the first successful login.Which command correctly configures the system profile?
Show answer & explanation
Correct answer: B
The
authselectcommand selects the authentication profile. Thesssdprofile is standard for IdM clients. To enable thepam_oddjob_mkhomedir(or systemd equivalent) functionality, you must enable thewith-mkhomedirfeature. - Question 5Intermediate
Create and Configure IdM Users and User Policies · Configure policies and user access
Your organization uses Red Hat IdM to manage sudo rules. A junior administrator created a new rule named 'WebAdmins' intended to give the 'web_team' group access to run
/bin/systemctl restart httpdon the 'webservers' hostgroup. However, users in 'web_team' report they are prompted for a password but their password is not accepted, or they are denied immediately.Upon investigation, you find the rule is enabled. What is the most likely configuration error preventing the sudo rule from working?
Show answer & explanation
Correct answer: A
Sudo rules are cached by SSSD on the client systems. If the rule is correct on the server but not working on the client, the most common issue is cache latency. The users are likely being denied because the local SSSD hasn't updated its database. Running
sss_cache -Eor waiting for the refresh interval usually resolves this. - Question 6Beginner
Maintain IdM Services · Back up and restore IdM infrastructure
You are preparing to perform a maintenance operation that requires a full offline backup of your primary IdM server. You want to ensure that the backup includes all logs for audit purposes.
Which command should you execute?
Show answer & explanation
Correct answer: D
The
ipa-backupcommand performs a full offline backup by default (stopping services). The--logsflag instructs it to include the/var/logdirectories for the relevant services (Directory Server, CA, etc.) in the backup archive.
Ready for the real thing?
The full EX362 simulator has every exam-style question, timed mode, and instant scoring.