Skip to content

EX362 Red Hat Certified Specialist in Identity Management exam Practice Questions

Prepare for EX362 with more than an answer.

147 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$500 USD
Time limit
180 minutes
Passing score
210 out of 300 (70%) (scale 0-300)
Level
Specialist
Valid for
3 years
Domains covered on the exam 6
  1. Install and Configure Red Hat Identity Management (IdM)20%
  2. Implement Single Sign-On (SSO)10%
  3. Install and Configure an IdM Client15%
  4. Manage the IdM Integrated Certificate Authority15%
  5. Create and Configure IdM Users and User Policies25%
  6. Maintain IdM Services15%
  1. 1

    You are preparing to perform a maintenance operation that requires a full offline backup of your primary IdM server. You want to ensure that the backup includes all logs for audit purposes.

    Which command should you execute?

    Show answer details

    Correct answer: B

    The ipa-backup command performs a full offline backup by default (stopping services). The --logs flag instructs it to include the /var/log directories for the relevant services (Directory Server, CA, etc.) in the backup archive.

  2. 2

    You have a fleet of laptops that roam between the corporate office and home networks. You need to configure these IdM clients to mount user home directories from a central NFS server when on the corporate network, but you must ensure the mount configuration is managed centrally in IdM.

    Which sequence of steps correctly configures the server-side components for this requirement?

    Show answer details

    Correct answer: A

    The correct hierarchy for automount in IdM is: Location -> Maps -> Keys. First, define a location (e.g., 'default'). Then define the master map (auto.master). Add a key to auto.master that points the mount point (e.g., /home) to the indirect map (auto.home). Create the indirect map (auto.home). Finally, add keys to auto.home (e.g., *) that point to the NFS export.

  3. 3

    Which of the following commands would you use to verify that a client system has successfully obtained a Kerberos Ticket Granting Ticket (TGT) for the admin user?

    Show answer details

    Correct answer: B

    kinit requests the ticket, but klist is the command used to verify/list the tickets currently held in the credential cache.

  4. 4

    You are configuring a new IdM replica and need to ensure it can act as a Certificate Authority (CA). However, during the initial installation of the primary server, the --no-ca option was used.

    What must you do before you can install a replica with CA capabilities?

    Show answer details

    Correct answer: A

    If the primary server was installed without a CA (using external CA or no CA), the IdM topology lacks the CA service entirely. You cannot create a CA replica until the CA service exists in the topology. You must run ipa-ca-install on an existing server to promote it to a CA before installing replicas with --setup-ca.

  5. 5

    You are the lead architect designing a Red Hat Identity Management (IdM) topology for a multinational corporation with data centers in New York, London, and Tokyo. The network team has established high-latency, limited-bandwidth links between these regions. You need to configure the replication topology to ensure data consistency while minimizing cross-region traffic.

    Which topology configuration strategy provides the optimal balance of redundancy and network efficiency?

    Show answer details

    Correct answer: C

    In a multi-site environment with WAN constraints, a full mesh is inefficient due to excessive traffic. A linear chain introduces single points of failure. The optimal approach is to create highly connected clusters (hub-and-spoke or partial mesh) within each high-bandwidth region and then link these regions using specific replication agreements (segments) between designated bridge servers. This minimizes cross-WAN traffic while maintaining redundancy.

    graph TD subgraph NY [New York Region] NY1((NY-Hub)) NY2((NY-Rep1)) NY3((NY-Rep2)) NY1 --- NY2 NY1 --- NY3 NY2 --- NY3 end subgraph LON [London Region] L1((LON-Hub)) L2((LON-Rep1)) L1 --- L2 end subgraph TKY [Tokyo Region] T1((TKY-Hub)) T2((TKY-Rep1)) T1 --- T2 end NY1 == WAN Link ==> L1 L1 == WAN Link ==> T1 T1 == WAN Link ==> NY1
  6. 6

    A system administrator is attempting to install a new IdM server using ipa-server-install on a RHEL 9 system. The installation fails immediately during the prerequisite check phase with an error indicating that the hostname is not resolvable. The server is intended to be the primary DNS server for the new IdM domain.

    Which combination of arguments should the administrator use to successfully proceed with the installation given this context?

    Show answer details

    Correct answer: C

    When the server's hostname cannot be resolved (often because the DNS server that will resolve it is the one being installed), you must explicitly provide the hostname, domain name, and realm name. Additionally, --setup-dns is required to configure the integrated Bind instance. The installer will then configure a loopback address resolution temporarily until the DNS service is up.

Create an account to continue.