EX362 Sample Questions

EX362 Sample Questions & Answers

Spans configuring IdM users and their access policies, the single biggest weight, plus Kerberized service configuration, single sign-on clients, managing secret vaults and the certificate authority, installing IdM servers and replicas, and maintenance.

Launch the full EX362 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Implement Single Sign-On (SSO) · Verify SSO client operation

    A developer needs to configure a Linux web server to authenticate users using Kerberos Single Sign-On (SSO). You have installed mod_auth_gssapi and created the service principal HTTP/webserver.example.com.

    After generating the keytab, users report receiving a '401 Unauthorized' error when accessing the site, and the Apache error logs show 'gss_acquire_cred() failed'.

    What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: A

    The error gss_acquire_cred() failed typically indicates that the application (Apache) cannot read the credentials required to authenticate itself to the KDC. This is most often caused by the keytab file having strict permissions (e.g., 600 root:root) that prevent the apache service user from reading it.

  2. Question 2Intermediate

    Create and Configure IdM Users and User Policies · Use Ansible to configure and manage IdM users

    You are tasked with automating the onboarding of 500 new developers. They require a specific set of HBAC rules and sudo privileges. You decide to use Ansible to manage this configuration.

    Which Ansible module from the ansible-freeipa collection should you use to ensure that the developer group exists and includes all 500 users, while maintaining idempotency?

    Show answer & explanation

    Correct answer: A

    The ipagroup module is designed to manage IdM user groups. It supports adding members (users) to a group in an idempotent way using the user parameter and state: present.

  3. Question 3Advanced

    Manage the IdM Integrated Certificate Authority · Create secret vaults

    A security audit requires that a specific department's sensitive secrets be stored in a way that allows the application to encrypt data using the vault's public key, but only the central IdM service can decrypt it using the private key for retrieval.

    Which type of IdM vault should you create to meet this requirement?

    Show answer & explanation

    Correct answer: C

    An asymmetric vault generates a key pair. The public key can be distributed to clients to encrypt data (archive) locally, but the private key remains securely in the KRA (Key Recovery Authority) and is used only for decryption (retrieval).

  4. Question 4Intermediate

    Install and Configure an IdM Client · Install and configure IdM clients

    You need to configure a new IdM client using authselect. The security policy mandates that the system must strictly use SSSD for authentication and must create home directories automatically upon the first successful login.

    Which command correctly configures the system profile?

    Show answer & explanation

    Correct answer: B

    The authselect command selects the authentication profile. The sssd profile is standard for IdM clients. To enable the pam_oddjob_mkhomedir (or systemd equivalent) functionality, you must enable the with-mkhomedir feature.

  5. Question 5Intermediate

    Create and Configure IdM Users and User Policies · Configure policies and user access

    Your organization uses Red Hat IdM to manage sudo rules. A junior administrator created a new rule named 'WebAdmins' intended to give the 'web_team' group access to run /bin/systemctl restart httpd on the 'webservers' hostgroup. However, users in 'web_team' report they are prompted for a password but their password is not accepted, or they are denied immediately.

    Upon investigation, you find the rule is enabled. What is the most likely configuration error preventing the sudo rule from working?

    Show answer & explanation

    Correct answer: A

    Sudo rules are cached by SSSD on the client systems. If the rule is correct on the server but not working on the client, the most common issue is cache latency. The users are likely being denied because the local SSSD hasn't updated its database. Running sss_cache -E or waiting for the refresh interval usually resolves this.

  6. Question 6Beginner

    Maintain IdM Services · Back up and restore IdM infrastructure

    You are preparing to perform a maintenance operation that requires a full offline backup of your primary IdM server. You want to ensure that the backup includes all logs for audit purposes.

    Which command should you execute?

    Show answer & explanation

    Correct answer: D

    The ipa-backup command performs a full offline backup by default (stopping services). The --logs flag instructs it to include the /var/log directories for the relevant services (Directory Server, CA, etc.) in the backup archive.

Ready for the real thing?

The full EX362 simulator has every exam-style question, timed mode, and instant scoring.

Go to the EX362 simulator →