Skip to content

EX280 Practice Questions

Prepare for EX280 with more than an answer.

180 questions in the full set12 sample questionsUpdated Mar 12, 2026
  1. 1

    You are defining a NetworkPolicy to isolate the 'backend' pods. The policy must block all incoming traffic to 'backend' pods except for traffic originating from pods with the label 'role=frontend' in the same namespace. Which ingress rule configuration achieves this?

    Show answer details

    Correct answer: A

    This configuration specifies an ingress rule that allows traffic FROM pods matching the selector 'role: frontend'. By default, if a NetworkPolicy selects pods but provides an empty or specific ingress rule, all other traffic is denied. Since no 'namespaceSelector' is provided, it implies the same namespace.

  2. 2

    You need to perform a one-time database migration task inside your OpenShift cluster. The task should run to completion and then stop. The pod should restart if the container fails, but not if it completes successfully. Which OpenShift resource is best suited for this requirement?

    Show answer details

    Correct answer: B

    A Job creates one or more Pods and ensures that a specified number of them successfully terminate. This is designed for 'run-to-completion' tasks like database migrations. Deployments are for long-running services.

  3. 3

    Your company policies require that every new project created by developers must automatically include a 'NetworkPolicy' that denies all ingress traffic by default. How can you automate this for all future self-service project requests?

    Show answer details

    Correct answer: B

    OpenShift allows administrators to customize the template used when a new project is created. By modifying the default project template to include a 'deny-all' NetworkPolicy object and configuring the cluster project controller to use this template, the policy will be automatically instantiated in every new project.

  4. 4

    You are reviewing the status of a pod that is failing to start. The 'oc get pods' command shows the status as 'ImagePullBackOff'. Which command would provide the most detailed information about why the image cannot be pulled?

    Show answer details

    Correct answer: B

    'ImagePullBackOff' means the container hasn't started yet, so 'oc logs' will likely be empty or fail. 'oc describe pod' shows the Events section, which will list the exact error from the kubelet (e.g., 'repository not found', 'authentication required', 'manifest unknown').

  5. 5

    You are the OpenShift Administrator for a financial institution. A development team needs to expose a secure internal banking API to external partners. The application handles sensitive data that must be encrypted from the client all the way to the pod. The TLS termination must not occur at the router level; the router should simply forward the encrypted traffic to the destination pod which holds the private key. Which Route configuration strategy should you implement?

    Show answer details

    Correct answer: C

    Passthrough termination sends encrypted traffic directly to the destination pod without the router decrypting it. This is required when the pod owns the private key and end-to-end encryption is mandatory without an intermediate decryption point.

    graph LR Client((Client)) -->|Encrypted HTTPS| Router[OpenShift Router] Router -->|Encrypted HTTPS| Pod[Application Pod] style Router fill:#f9f,stroke:#333,stroke-width:2px style Pod fill:#bfb,stroke:#333,stroke-width:2px
  6. 6

    A developer reports that their application deployment in the 'frontend' project is failing to create new pods. Upon investigation, you see the message 'Forbidden: exceeded quota: compute-resources, requested: requests.cpu=200m, used: requests.cpu=1800m, limited: requests.cpu=2'. What is the most immediate cause of this issue?

    Show answer details

    Correct answer: C

    The error message explicitly states 'exceeded quota', indicating that a ResourceQuota object exists in the namespace ('frontend') and the cumulative CPU requests (1800m used + 200m requested = 2000m or 2 cores) has hit the hard limit defined in that quota.

Create an account to continue.