305-300 Sample Questions

305-300 Sample Questions & Answers

Full virtualization with Xen and QEMU ties with container virtualization using LXC and Docker for the top weight, well ahead of using Packer, cloud-init and cloud management tools to deploy and provision VMs.

Launch the full 305-300 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    352.1 Container Virtualization Concepts · Container Security with seccomp

    A financial services company is containerizing a legacy application. For compliance reasons, they must strictly control the system calls the container can make to the host kernel. The security team has provided a JSON file (profile.json) defining an allowed list of syscalls. Which Docker command correctly applies this seccomp profile to a container named legacy-app?

    Show answer & explanation

    Correct answer: A

    The correct way to apply a custom seccomp profile to a Docker container is by using the --security-opt flag. The syntax is seccomp= . This instructs the container runtime to load the specified profile and restrict the container's allowed system calls to only those defined in the file. The other options use incorrect flags (--seccomp-profile, --apparmor) or incorrect syntax for the security option.

  2. Question 2Intermediate

    351.2 Xen · Xen Domain State Management

    A systems engineer is managing a Xen hypervisor and needs to perform maintenance on the host. Before shutting down, they want to save the exact memory state of a critical Para-Virtualized (PV) domain named db-server-pv to disk so it can be resumed quickly later. Which xl command should be used to accomplish this?

    Show answer & explanation

    Correct answer: C

    The xl save command is used to stop a domain and save its current state, including its entire memory content, to a file on disk. The domain is terminated on the hypervisor after the save is complete. This state can then be restored later using xl restore. xl snapshot is for disk snapshots, xl suspend pauses the domain but keeps its state in the host's memory, and xl migrate moves a running domain to another host.

  3. Question 3Intermediate

    351.4 Libvirt Virtual Machine Management · Libvirt Network Configuration

    You are designing a libvirt network architecture to isolate a group of development VMs from the main production network while still allowing them to access the internet. The requirements are: the VMs should be on their own private subnet (192.168.100.0/24), they should obtain IPs via DHCP, and their outbound traffic should be NAT-ed through the host's primary network interface. Which type of libvirt virtual network should you create?

    Show answer & explanation

    Correct answer: C

    A NAT-forwarded network is the standard libvirt configuration that meets these requirements. It creates a virtual bridge, runs a DHCP server to assign IPs to VMs on a private subnet, and uses iptables rules on the host to perform Network Address Translation (NAT) for outbound traffic. This isolates the VMs while providing them with internet access. A bridged network would place them on the same L2 network as the host, an isolated network would prevent internet access, and a routed network requires additional static routes on the external network.

  4. Question 4Advanced

    353.2 Packer · Packer Provisioners and Variables

    A team is using Packer to build golden images for both AWS (AMI) and local QEMU (QCOW2) environments from a single HCL template. They need to run a shell script (setup.sh) to configure the base OS, but this script requires environment-specific variables. For AWS, it needs the AWS_REGION, and for QEMU, it needs a BUILD_TYPE variable set to local. How can this be achieved within the Packer template?

    Show answer & explanation

    Correct answer: A

    The most effective way to handle builder-specific provisioning is to use a single provisioner block with different environment_vars for each builder, controlled by only or except clauses. However, since the variables are different, a cleaner approach is to use two distinct provisioner blocks. One block would have only = ["amazon-ebs"] and set AWS_REGION, while the other would have only = ["qemu"] and set BUILD_TYPE. This provides clear separation and ensures the correct environment variables are passed to the script depending on which builder is active.

  5. Question 5Advanced

    352.4 Container Orchestration Platforms · Docker Compose Application Modeling

    Case Study: A media company is migrating its video transcoding service to a containerized architecture. The service consists of a front-end web application that accepts uploads, a RabbitMQ message queue, and multiple back-end worker containers that perform the CPU-intensive transcoding tasks.

    The lead architect has defined the following requirements:

    1. The entire multi-container application must be definable in a single, portable configuration file for easy deployment in development and staging.
    2. The worker containers must not expose any ports to the host or external network, but they must be able to connect to the RabbitMQ container.
    3. The front-end container needs to be accessible from the host machine on port 8080.
    4. A persistent volume is required for the RabbitMQ container to ensure message durability across restarts.

    Which technology and configuration strategy best satisfies all of these requirements?

    Show answer & explanation

    Correct answer: C

    Docker Compose is the ideal tool for this scenario, as it allows defining a multi-container application in a single YAML file (Req 1). By default, Compose creates a custom bridge network for the application, allowing all services to communicate via their service names (e.g., rabbitmq) without exposing ports (Req 2). The ports mapping for the frontend service satisfies Req 3. Defining a named volume at the top level and mounting it into the RabbitMQ service provides persistent storage (Req 4). Kubernetes is a more complex solution than required, and the manual script approach lacks the declarative and portable nature of Compose.

  6. Question 6Advanced

    351.5 Virtual Machine Disk Image Management · Manipulating Images with libguestfs

    A system administrator is using libguestfs tools to modify a qcow2 disk image offline. They need to upload a configuration file from their host (/tmp/app.conf) into the guest's filesystem at /etc/app/app.conf. Which command sequence using guestfish correctly performs this action on the image guest.qcow2?

    Show answer & explanation

    Correct answer: D

    The guestfish command with the -i option automatically inspects the disk image, finds the operating system, and mounts the filesystems in their correct locations (e.g., /dev/sda1 on /). The --rw flag is crucial to open the disk image in read-write mode. The upload command then copies the local file to the specified destination within the mounted guest filesystem. This is the most efficient and reliable method, as it avoids manual inspection and mounting of partitions.

  7. Question 7IntermediateSelect 3

    352.1 Container Virtualization Concepts · Linux Kernel Namespaces

    When a Docker container is started, which of the following Linux kernel namespaces are typically used by default to provide isolation? (Select THREE)

    Show answer & explanation

    Correct answers: A, B, D

    By default, Docker utilizes several namespaces for isolation. PID provides an independent process tree where the container's main process is PID 1. NET provides an isolated network stack with its own interfaces and routing table. MNT provides an isolated view of the filesystem hierarchy. The USER namespace is not used by default; enabling it (for rootless containers) is a specific configuration choice. Cgroup is a mechanism for resource limiting, not a namespace for isolation in the same way.

  8. Question 8Advanced

    351.4 Libvirt Virtual Machine Management · Libvirt Network Filtering

    You are managing a KVM host using libvirt and need to prevent a specific VM, rogue-vm, from spoofing MAC addresses on the network. Which virsh command would you use to define a network filter that enforces this security policy on the VM's primary network interface?

    Show answer & explanation

    Correct answer: C

    Libvirt's network filtering capabilities are managed through the nwfilter-* family of commands. To apply a MAC spoofing prevention rule, you would first define a filter using an XML file with virsh nwfilter-define . The XML would contain rules, often using the built-in clean-traffic chain, to ensure that outgoing packets have the same MAC address as the VM's interface. After defining the filter, you would then edit the domain's configuration (virsh edit) to apply this filter to the specific interface. The other commands relate to DHCP reservations or interface attachment, not L2 security filtering.

  9. Question 9Beginner

    353.3 cloud-init · cloud-config Syntax

    A developer is creating a cloud-init configuration to bootstrap a web server. The server needs to have nginx and git installed, and a specific user deploy must be created with SSH access authorized by a public key. What is the correct YAML key to use within a #cloud-config file for specifying the packages to be installed?

    Show answer & explanation

    Correct answer: C

    The standard key in a cloud-init #cloud-config file for defining a list of software packages to be installed is packages:. cloud-init will then use the appropriate package manager for the underlying distribution (e.g., apt on Debian/Ubuntu, yum/dnf on RHEL/CentOS) to install the listed packages. The users: key is used for user creation, and ssh_authorized_keys: is used for adding public keys.

  10. Question 10Intermediate

    352.2 LXC · LXD Profile Inheritance

    In LXD, profiles are used to apply a common set of configurations to multiple containers. If a container has multiple profiles applied, and a specific configuration key (e.g., limits.cpu) is defined in more than one of those profiles, how does LXD determine which value to use?

    Show answer & explanation

    Correct answer: A

    LXD applies profiles in the order they are listed for the container. If the same key exists in multiple profiles, the value from the right-most (last applied) profile in the list will override the values from earlier profiles. Any locally defined configuration on the container itself will override all profile values.

Ready for the real thing?

The full 305-300 simulator has every exam-style question, timed mode, and instant scoring.