Skip to content

EX288 Red Hat Certified OpenShift Application Developer Practice Questions

Prepare for EX288 with more than an answer.

120 questions in the full set12 sample questionsUpdated Mar 12, 2026
  1. 1

    A developer has pushed a Docker image to the internal OpenShift image registry in the project myproject. The image stream is named myapp and the tag is v1. You want to verify the image metadata and signature.

    Which command should you use to inspect the image details stored in the internal registry?

    Show answer details

    Correct answer: A

    The oc describe istag (or ImageStreamTag) command retrieves detailed metadata about a specific tag in an image stream, including the image digest, creation time, and Docker metadata managed by the internal registry.

  2. 2

    You are troubleshooting a build failure in OpenShift. The build named frontend-1 failed. You suspect the issue is related to a script error during the assembly phase.

    Which command would most effectively help you identify the specific error line in the build output?

    Show answer details

    Correct answer: A

    oc logs build/ (or just oc logs -f bc/frontend to follow the latest) retrieves the standard output/error from the build container. This log contains the output of the S2I scripts, including any syntax errors or failure messages generated during the assembly phase.

  3. 3

    You have a Deployment named payment-service that mounts a ConfigMap named payment-config as a volume at /etc/config. You update the data in the payment-config ConfigMap to change a timeout value.

    What happens to the Pods controlled by the Deployment after this update?

    Show answer details

    Correct answer: B

    When a ConfigMap is mounted as a volume, Kubernetes updates the mounted files when the ConfigMap changes (with a slight delay due to cache sync). However, the Pod itself does NOT restart automatically. The application running inside must either watch the file for changes or be manually restarted (e.g., oc rollout restart) to read the new configuration.

  4. 4

    Case Study: TechCorp Inc.

    TechCorp is migrating a monolithic Node.js application to OpenShift. The application code resides in a private Git repository. The build process requires fetching dependencies from a private npm registry which requires authentication. The developers want to use the standard Node.js S2I builder image but need to provide a .npmrc file containing the authentication token during the build process.

    Requirement: The .npmrc file contains sensitive tokens and should NOT be committed to the source code repository. It must be injected securely during the build.

    Which solution meets these requirements?

    Show answer details

    Correct answer: B

    To inject sensitive files into an S2I build without committing them, you create a Kubernetes Secret. In the BuildConfig, you reference this secret under source.secrets. By specifying destinationDir: ., the .npmrc file from the secret is placed in the root of the source code directory before the assemble script runs, allowing npm install to use it.

  5. 5

    You are configuring a Red Hat OpenShift Pipeline (Tekton) to build and deploy a Java application. The pipeline consists of two tasks: build-app (which compiles the code using Maven) and build-image (which uses Buildah to create a container image). The build-app task produces a JAR file that the build-image task requires. However, the build-image task fails immediately, stating the JAR file cannot be found. You have verified the JAR is successfully created in the first task.

    Which configuration is required to persist and share files between these two tasks?

    Show answer details

    Correct answer: B

    In Tekton/OpenShift Pipelines, tasks run in separate pods. The filesystem is not shared by default. To share artifacts (like a compiled JAR) between tasks, you must define a Workspace in the Pipeline definition and bind it to a storage volume (like a PVC) at runtime via the PipelineRun. Both tasks then mount this workspace to read/write shared files.

  6. 6

    A developer is customizing a Source-to-Image (S2I) build for a Python application. The application requires a specific configuration file to be generated dynamically based on environment variables before the application starts, but after the dependencies are installed. The developer decides to provide a custom S2I script in the source repository.

    Which script must the developer create, and where should it be placed in the source code repository to override the default behavior?

    Show answer details

    Correct answer: B

    The assemble script is responsible for building the application artifacts (installing dependencies, compiling code, etc.). By placing an executable script named assemble in the .s2i/bin/ directory of the source code, the S2I process will use this script instead of the default one provided by the builder image. This allows the developer to inject custom build steps like generating configuration files.

Create an account to continue.