EX280 Sample Questions

EX280 Sample Questions & Answers

Free Red Hat Certified OpenShift Administrator practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full EX280 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Declarative Resource Management · Work with Kustomize overlays

    Your organization requires a specific set of Kustomize overlays for deploying an application to Development, Stage, and Production environments. You have a 'base' directory containing the common deployment.yaml and service.yaml. You need to ensure the Production overlay scales the replicas to 5 and changes the image tag to 'stable'.

    Which file structure and content is correct for the production overlay?

    Show answer & explanation

    Correct answer: D

    The standard Kustomize overlay pattern involves a kustomization.yaml file in the overlay directory (e.g., /overlays/production). It must reference the base resources using the 'resources' field and apply environment-specific changes using 'patches' (or 'patchesStrategicMerge').

    graph TD Base[Base Directory] -->|Contains| Dep[deployment.yaml] Base -->|Contains| Svc[service.yaml] Overlay[Overlay: Production] -->|References| Base Overlay -->|Applies| Patch[Replica & Image Patch] Patch -.->|Modifies| Dep
  2. Question 2Beginner

    Manage authentication and authorization · Modify user and group permissions

    You need to grant a specific user, 'alice', the ability to view all resources in the 'marketing' project, but she should not be able to modify any resources. Which command achieves this using the default ClusterRoles?

    Show answer & explanation

    Correct answer: D

    The command 'oc adm policy add-role-to-user' creates a RoleBinding within the specified namespace ('-n marketing'). The 'view' ClusterRole provides read-only access to most resources, which meets the requirement. Using 'add-cluster-role-to-user' would grant her view access to the entire cluster, which violates the principle of least privilege.

  3. Question 3Intermediate

    Enable developer self-service · Configure cluster resource quotas

    A database pod in the 'db-prod' project keeps restarting with an 'OOMKilled' error. You determine that the application needs more memory than the current limit allows. The project has a ResourceQuota 'quota-prod' with 'limits.memory: 10Gi' and 'used: 9.5Gi'. The pod requests 1Gi. What must you do to successfully deploy the fix?

    Show answer & explanation

    Correct answer: C

    The project is currently using 9.5Gi out of a 10Gi limit. Increasing the pod's memory requirement (which is already 1Gi) would push the total usage beyond the 10Gi quota. Therefore, you must first expand the ResourceQuota to accommodate the new requirement before the pod can be successfully scheduled with higher limits.

  4. Question 4Intermediate

    Manage OpenShift operators · Install an operator

    You are tasked with installing the 'Web Terminal' Operator from the OperatorHub. You want to ensure that the Operator is installed in all namespaces and that it automatically updates whenever a new version is available in the 'stable' channel. Which resource should you configure to define the channel and approval strategy?

    Show answer & explanation

    Correct answer: B

    The Subscription resource is the control point for the Operator Lifecycle Manager (OLM). It links an Operator package to a CatalogSource and defines the update channel (e.g., 'stable') and the install plan approval strategy (Automatic vs Manual).

  5. Question 5Advanced

    Configure application security · Manage and apply permissions using security context constraints

    An application in the 'hr-app' project requires the ability to run as a specific user ID (UID 5000) defined in its Dockerfile. By default, OpenShift assigns an arbitrary UID. What is the most secure and appropriate way to allow this specific UID for the application's ServiceAccount?

    Show answer & explanation

    Correct answer: C

    Creating a custom SCC with 'MustRunAs' and the specific UID (5000) is the principle of least privilege. It allows exactly what is needed without granting the broad and dangerous permissions associated with the 'privileged' or 'anyuid' SCCs.

  6. Question 6Intermediate

    Configure network security · Configure application network policies

    You are defining a NetworkPolicy to isolate the 'backend' pods. The policy must block all incoming traffic to 'backend' pods except for traffic originating from pods with the label 'role=frontend' in the same namespace. Which ingress rule configuration achieves this?

    Show answer & explanation

    Correct answer: A

    This configuration specifies an ingress rule that allows traffic FROM pods matching the selector 'role: frontend'. By default, if a NetworkPolicy selects pods but provides an empty or specific ingress rule, all other traffic is denied. Since no 'namespaceSelector' is provided, it implies the same namespace.

Ready for the real thing?

The full EX280 simulator has every exam-style question, timed mode, and instant scoring.

Go to the EX280 simulator →