300-910 Sample Questions & Answers
Three areas tie for the top weight: building and troubleshooting CI/CD pipelines, Ansible-driven infrastructure automation, and log and metric collection systems; smaller sections cover containerized microservices, Kubernetes deployment, and pipeline security.
Launch the full 300-910 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Cloud and Multicloud · Describe the concepts and objects of Kubernetes
A development team is deploying a new microservice to a Kubernetes cluster. They have created a Deployment object, but the application is not accessible from outside the cluster. They need to expose the application via a stable network endpoint within the cluster so other microservices can communicate with it. Which Kubernetes object should they create to achieve this internal-facing accessibility?
Show answer & explanation
Correct answer: B
A Kubernetes Service provides a stable network abstraction layer for a set of pods. It creates a single, stable IP address and DNS name (e.g., my-service.default.svc.cluster.local) that other applications within the cluster can use to access the pods managed by the Deployment. The Service automatically handles load balancing across the pods, even as they are created or destroyed. An Ingress is for external access, a Pod is the workload itself, and a ConfigMap is for configuration data.
- Question 2Intermediate
Logging, Monitoring, and Metrics · Describe the principles of chaos engineering
An SRE team is adopting chaos engineering principles to test the resilience of their distributed application. Their first experiment is to simulate a latency increase in the connection to a critical downstream database service. What is the primary goal of this type of chaos experiment?
Show answer & explanation
Correct answer: C
The primary goal of chaos engineering is to build confidence in the system's ability to withstand turbulent conditions in production. By injecting latency, the team is proactively testing whether the application's built-in resilience patterns (like timeouts, retries, and circuit breakers) behave as expected. This helps uncover hidden weaknesses before they cause a real-world outage.
- Question 3Beginner
Security · Identify methods to implement a secure software development life cycle
A DevOps engineer is implementing a secure software development life cycle (SDLC). The goal is to identify potential security vulnerabilities in the application code itself, before it is ever compiled or deployed. Which security testing method should be integrated into the CI pipeline to achieve this?
Show answer & explanation
Correct answer: B
Static Application Security Testing (SAST) analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the program. Because it works directly on the code, it can be integrated very early in the SDLC, such as upon a code commit or pull request, to find issues like SQL injection or buffer overflows before the application is even built. DAST requires a running application, IAST combines both, and penetration testing is typically a later-stage manual or automated process.
- Question 4Beginner
CI/CD Pipeline · Describe characteristics and concepts of build /deploy tools such as Jenkins, Drone, or Travis CI
An organization is migrating its CI/CD processes to a new platform and needs to choose a build/deploy tool. The primary requirements are that the tool must be highly extensible through a vast ecosystem of plugins, be self-hosted for security compliance, and have strong community support. Which of the following tools best fits these characteristics?
Show answer & explanation
Correct answer: A
Jenkins is renowned for its massive plugin ecosystem, which allows for extensive customization and integration with virtually any tool. It is an open-source, self-hosted solution, which satisfies the security compliance requirement. Its long history has resulted in a very large and active community, providing ample support and resources. While Drone is also self-hosted, its plugin ecosystem is smaller. Travis CI is primarily a cloud-based SaaS offering.
- Question 5Intermediate
CI/CD Pipeline · Diagnose code dependency management issues including API, tool chain, and libraries
A DevOps team is managing a Python application that has a
requirements.txtfile listing several dependencies, includingrequests==2.25.1andurllib3 =1.25.4. The CI/CD pipeline fails during thepip installstage with a dependency resolution error. This is a common and recurring problem. What is the most likely cause of this type of failure?Show answer & explanation
Correct answer: C
This is a classic transitive dependency conflict. The
requestslibrary itself depends onurllib3. If version 2.25.1 ofrequestsrequires a version ofurllib3that is outside the=1.25.4range,pipwill be unable to find a compatible set of packages, leading to a resolution error. This highlights the complexity of managing dependencies in modern applications. - Question 6Intermediate
Automating Infrastructure · Construct an Ansible playbook to automate an application deployment of infrastructure services
A team wants to automate the deployment of a new VLAN on a Cisco Nexus switch fabric using an Ansible playbook. The playbook needs to be idempotent, meaning running it multiple times should result in the same final state without causing errors or unintended changes after the initial successful run. Which Ansible state parameter value ensures this behavior when defining the VLAN?
Show answer & explanation
Correct answer: D
In Ansible, the
state: presentparameter is used to ensure that a resource (like a VLAN, user, or package) exists. If the VLAN is not configured, Ansible will create it. If the VLAN already exists as defined, Ansible will report 'ok' and make no changes. This is the core of idempotency. The opposite isstate: absent, which ensures the resource does not exist. - Question 7Advanced
Packaging and Delivery of Applications · Evaluate microservices and container architecture diagrams based on technical and business requirements
A consultant is evaluating the architecture for a new cloud-native application composed of over 30 microservices. The business requirements demand high performance, strong security for inter-service communication, and detailed observability into traffic flows. Which architectural component should be recommended to meet these specific requirements for a large number of microservices?
Show answer & explanation
Correct answer: B
A service mesh is a dedicated infrastructure layer for managing service-to-service communication. It provides features like mutual TLS (mTLS) for security, advanced traffic management (e.g., circuit breaking, retries) for performance and resilience, and detailed telemetry (metrics, logs, traces) for observability. While an API Gateway handles north-south (ingress) traffic, a service mesh is specifically designed to manage east-west traffic between microservices, making it the ideal choice for this scenario.
- Question 8Intermediate
Cloud and Multicloud · Compare cloud services strategies (build versus buy)
When comparing cloud service strategies for a new project with a small, inexperienced team and a tight deadline, the 'buy' strategy (using managed services like AWS RDS or Azure SQL Database) is often preferred over the 'build' strategy (deploying and managing your own database on a VM). What is a primary benefit of the 'buy' strategy in this context?
Show answer & explanation
Correct answer: C
The main advantage of using managed services ('buy') is the reduction of operational burden. The cloud provider handles complex and time-consuming tasks like OS patching, database software updates, automated backups, and configuring high availability/failover. This allows a small team to focus on developing the application's core features and accelerate time-to-market, which is critical given the tight deadline.
- Question 9Intermediate
CI/CD Pipeline · Identify tests to integrate into a CI/CD pipeline for a given scenario
A CI/CD pipeline for a web application includes a stage for automated user interface testing using Selenium. These tests are known to be slow and occasionally fail due to transient network issues, a condition known as 'flakiness'. Which of the following is the BEST practice for integrating these types of tests into the pipeline?
Show answer & explanation
Correct answer: C
Slow and flaky tests can severely hinder developer productivity by blocking the main CI/CD pipeline. The best practice is to move them to a separate, parallel pipeline (often called an acceptance or end-to-end test pipeline). This allows the primary pipeline (with fast, reliable unit and integration tests) to complete quickly, providing rapid feedback. The slower tests still provide value by running against a stable build, but they don't become a bottleneck for every commit.
- Question 10Beginner
Security · Identify methods to implement a secure software development life cycle
True or False: A threat model created during the design phase of the SDLC is a static document that should not be changed after the application is deployed to production.
Show answer & explanation
Correct answer: B
This statement is false. A threat model is a living document that should be reviewed and updated throughout the entire software development lifecycle. New features, changes in architecture, newly discovered vulnerabilities, or evolving threat landscapes all necessitate revisiting and updating the threat model to ensure it accurately reflects the current security posture of the application.
Ready for the real thing?
The full 300-910 simulator has every exam-style question, timed mode, and instant scoring.