305-300 Sample Questions & Answers
Full virtualization with Xen and QEMU ties with container virtualization using LXC and Docker for the top weight, well ahead of using Packer, cloud-init and cloud management tools to deploy and provision VMs.
Launch the full 305-300 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
352.1 Container Virtualization Concepts · Container Security with seccomp
A financial services company is containerizing a legacy application. For compliance reasons, they must strictly control the system calls the container can make to the host kernel. The security team has provided a JSON file (
profile.json) defining an allowed list of syscalls. Which Docker command correctly applies this seccomp profile to a container namedlegacy-app?Show answer & explanation
Correct answer: A
The correct way to apply a custom seccomp profile to a Docker container is by using the
--security-optflag. The syntax isseccomp=. This instructs the container runtime to load the specified profile and restrict the container's allowed system calls to only those defined in the file. The other options use incorrect flags (--seccomp-profile,--apparmor) or incorrect syntax for the security option. - Question 2Intermediate
351.2 Xen · Xen Domain State Management
A systems engineer is managing a Xen hypervisor and needs to perform maintenance on the host. Before shutting down, they want to save the exact memory state of a critical Para-Virtualized (PV) domain named
db-server-pvto disk so it can be resumed quickly later. Whichxlcommand should be used to accomplish this?Show answer & explanation
Correct answer: C
The
xl savecommand is used to stop a domain and save its current state, including its entire memory content, to a file on disk. The domain is terminated on the hypervisor after the save is complete. This state can then be restored later usingxl restore.xl snapshotis for disk snapshots,xl suspendpauses the domain but keeps its state in the host's memory, andxl migratemoves a running domain to another host. - Question 3Intermediate
351.4 Libvirt Virtual Machine Management · Libvirt Network Configuration
You are designing a libvirt network architecture to isolate a group of development VMs from the main production network while still allowing them to access the internet. The requirements are: the VMs should be on their own private subnet (192.168.100.0/24), they should obtain IPs via DHCP, and their outbound traffic should be NAT-ed through the host's primary network interface. Which type of libvirt virtual network should you create?
Show answer & explanation
Correct answer: C
A NAT-forwarded network is the standard libvirt configuration that meets these requirements. It creates a virtual bridge, runs a DHCP server to assign IPs to VMs on a private subnet, and uses iptables rules on the host to perform Network Address Translation (NAT) for outbound traffic. This isolates the VMs while providing them with internet access. A bridged network would place them on the same L2 network as the host, an isolated network would prevent internet access, and a routed network requires additional static routes on the external network.
- Question 4Advanced
353.2 Packer · Packer Provisioners and Variables
A team is using Packer to build golden images for both AWS (AMI) and local QEMU (QCOW2) environments from a single HCL template. They need to run a shell script (
setup.sh) to configure the base OS, but this script requires environment-specific variables. For AWS, it needs theAWS_REGION, and for QEMU, it needs aBUILD_TYPEvariable set tolocal. How can this be achieved within the Packer template?Show answer & explanation
Correct answer: A
The most effective way to handle builder-specific provisioning is to use a single
provisionerblock with differentenvironment_varsfor each builder, controlled byonlyorexceptclauses. However, since the variables are different, a cleaner approach is to use two distinctprovisionerblocks. One block would haveonly = ["amazon-ebs"]and setAWS_REGION, while the other would haveonly = ["qemu"]and setBUILD_TYPE. This provides clear separation and ensures the correct environment variables are passed to the script depending on which builder is active. - Question 5Advanced
352.4 Container Orchestration Platforms · Docker Compose Application Modeling
Case Study: A media company is migrating its video transcoding service to a containerized architecture. The service consists of a front-end web application that accepts uploads, a RabbitMQ message queue, and multiple back-end worker containers that perform the CPU-intensive transcoding tasks.
The lead architect has defined the following requirements:
- The entire multi-container application must be definable in a single, portable configuration file for easy deployment in development and staging.
- The worker containers must not expose any ports to the host or external network, but they must be able to connect to the RabbitMQ container.
- The front-end container needs to be accessible from the host machine on port 8080.
- A persistent volume is required for the RabbitMQ container to ensure message durability across restarts.
Which technology and configuration strategy best satisfies all of these requirements?
Show answer & explanation
Correct answer: C
Docker Compose is the ideal tool for this scenario, as it allows defining a multi-container application in a single YAML file (Req 1). By default, Compose creates a custom bridge network for the application, allowing all services to communicate via their service names (e.g.,
rabbitmq) without exposing ports (Req 2). Theportsmapping for the frontend service satisfies Req 3. Defining a named volume at the top level and mounting it into the RabbitMQ service provides persistent storage (Req 4). Kubernetes is a more complex solution than required, and the manual script approach lacks the declarative and portable nature of Compose. - Question 6Advanced
351.5 Virtual Machine Disk Image Management · Manipulating Images with libguestfs
A system administrator is using
libguestfstools to modify a qcow2 disk image offline. They need to upload a configuration file from their host (/tmp/app.conf) into the guest's filesystem at/etc/app/app.conf. Which command sequence usingguestfishcorrectly performs this action on the imageguest.qcow2?Show answer & explanation
Correct answer: D
The
guestfishcommand with the-ioption automatically inspects the disk image, finds the operating system, and mounts the filesystems in their correct locations (e.g.,/dev/sda1on/). The--rwflag is crucial to open the disk image in read-write mode. Theuploadcommand then copies the local file to the specified destination within the mounted guest filesystem. This is the most efficient and reliable method, as it avoids manual inspection and mounting of partitions. - Question 7IntermediateSelect 3
352.1 Container Virtualization Concepts · Linux Kernel Namespaces
When a Docker container is started, which of the following Linux kernel namespaces are typically used by default to provide isolation? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
By default, Docker utilizes several namespaces for isolation. PID provides an independent process tree where the container's main process is PID 1. NET provides an isolated network stack with its own interfaces and routing table. MNT provides an isolated view of the filesystem hierarchy. The USER namespace is not used by default; enabling it (for rootless containers) is a specific configuration choice. Cgroup is a mechanism for resource limiting, not a namespace for isolation in the same way.
- Question 8Advanced
351.4 Libvirt Virtual Machine Management · Libvirt Network Filtering
You are managing a KVM host using
libvirtand need to prevent a specific VM,rogue-vm, from spoofing MAC addresses on the network. Whichvirshcommand would you use to define a network filter that enforces this security policy on the VM's primary network interface?Show answer & explanation
Correct answer: C
Libvirt's network filtering capabilities are managed through the
nwfilter-*family of commands. To apply a MAC spoofing prevention rule, you would first define a filter using an XML file withvirsh nwfilter-define. The XML would contain rules, often using the built-inclean-trafficchain, to ensure that outgoing packets have the same MAC address as the VM's interface. After defining the filter, you would then edit the domain's configuration (virsh edit) to apply this filter to the specific interface. The other commands relate to DHCP reservations or interface attachment, not L2 security filtering. - Question 9Beginner
353.3 cloud-init · cloud-config Syntax
A developer is creating a
cloud-initconfiguration to bootstrap a web server. The server needs to havenginxandgitinstalled, and a specific userdeploymust be created with SSH access authorized by a public key. What is the correct YAML key to use within a#cloud-configfile for specifying the packages to be installed?Show answer & explanation
Correct answer: C
The standard key in a
cloud-init#cloud-configfile for defining a list of software packages to be installed ispackages:.cloud-initwill then use the appropriate package manager for the underlying distribution (e.g.,apton Debian/Ubuntu,yum/dnfon RHEL/CentOS) to install the listed packages. Theusers:key is used for user creation, andssh_authorized_keys:is used for adding public keys. - Question 10Intermediate
352.2 LXC · LXD Profile Inheritance
In LXD, profiles are used to apply a common set of configurations to multiple containers. If a container has multiple profiles applied, and a specific configuration key (e.g.,
limits.cpu) is defined in more than one of those profiles, how does LXD determine which value to use?Show answer & explanation
Correct answer: A
LXD applies profiles in the order they are listed for the container. If the same key exists in multiple profiles, the value from the right-most (last applied) profile in the list will override the values from earlier profiles. Any locally defined configuration on the container itself will override all profile values.
Ready for the real thing?
The full 305-300 simulator has every exam-style question, timed mode, and instant scoring.