OpenShift DO280 and EX280 Practice Questions and Answers: Original Hands-On Tasks
Prepare for the EX280 OpenShift Certification Exam with the latest DO280 training materials, real exam questions, and detailed answers. Get access to PDF formats, video tutorials, and practice dumps for guaranteed success in your OpenShift administration exam.
Quick answer: There is no legitimate source of real EX280 exam questions. Red Hat forbids sharing exam content, and dumps put your certification at risk. EX280 is the hands-on Red Hat Certified Specialist in OpenShift Administration exam, taught by DO280. This guide gives original practice tasks with oc solutions: identity providers, RBAC, quotas, routes, network policy, scaling and node maintenance.
Key takeaways
- EX280 tests whether you can administer a live OpenShift cluster. It is marked on the final state of the cluster, so memorised answers do not help.
- The title of this article once promised "real exam questions" and "guaranteed success". Neither can be honest. No one can guarantee a pass, and real questions are confidential.
- The tasks below are original, written to match the type of work in the published objectives. Check Red Hat's current objectives and the OpenShift version before you rely on any command.
- Practise each task until you can do it from a blank terminal, and learn where the documentation is for what you forget.
What is the DO280 and EX280?
DO280 is Red Hat's course "Red Hat OpenShift Administration II: Operating a Production Kubernetes Cluster". EX280 is the exam, which awards Red Hat Certified Specialist in OpenShift Administration. OpenShift is Red Hat's Kubernetes-based container platform. You will do the work on a live cluster using the oc command-line tool and the web console. Red Hat's pages for the course and exam are on its training and certification site, and the product documentation is at docs.redhat.com.
The objectives cover areas such as managing OpenShift cluster resources, configuring authentication and authorisation, controlling access to applications and networks, managing scheduling and applications, and working with Operators and storage. Read the current list on Red Hat's site, as versions change.
Why not use real exam questions?
- It breaks the rules. Red Hat's candidate agreement prohibits copying or sharing exam content. Misuse can cancel your result.
- It does not work. This is a performance-based exam. The cluster you see will differ, and you are marked on whether the cluster works.
- It teaches nothing. Employers hire you for the skill, and the exam only proves it. A memorised pass is a hollow one.
How should you prepare for EX280?
- Take the published objectives and turn each into a task.
- Get a cluster to practise on: a lab from your training provider, OpenShift Local on a laptop for single-node practice, or a cloud cluster. Some tasks, such as node maintenance, need a multi-node cluster.
- Practise with
oc explainandoc get -o yaml, which help when you cannot remember a field. - Time yourself. Many candidates lose marks to slowness, not to lack of knowledge.
Our page on EX280 training and certification, and the EX280 voucher post explain the rest of the path.
Practice tasks with worked solutions
Assume you are logged in as a cluster administrator on a practice cluster. Names such as alice, project1 and the image are examples. The commands are a guide. Check them against your cluster version.
Task 1: Configure an HTPasswd identity provider
Task: Create users alice and bob who can log in with a local password file.
htpasswd -c -B -b users.htpasswd alice 'ChangeMe1'
htpasswd -B -b users.htpasswd bob 'ChangeMe2'
oc create secret generic htpass-secret \
--from-file=htpasswd=users.htpasswd -n openshift-config
apiVersion: config.openshift.io/v1
kind: OAuth
metadata:
name: cluster
spec:
identityProviders:
- name: local-users
mappingMethod: claim
type: HTPasswd
htpasswd:
fileData:
name: htpass-secret
Apply it with oc apply -f oauth.yaml. Then wait for the authentication pods to roll out (oc get pods -n openshift-authentication) and test with oc login -u alice. If you already have identity providers, edit the existing OAuth resource instead of replacing it. Practise updating a password by regenerating the file and replacing the secret.
Task 2: Groups and role-based access control
Task: Create a group dev-team with alice and bob, give it edit rights in project1, and stop normal users creating projects.
oc adm groups new dev-team
oc adm groups add-users dev-team alice bob
oc new-project project1
oc policy add-role-to-group edit dev-team -n project1
oc adm policy remove-cluster-role-from-group self-provisioner system:authenticated:oauth
Check with oc auth can-i create deployments -n project1 --as alice. Know the difference between roles and cluster roles, and between role bindings and cluster role bindings. Be aware that removing self-provisioner affects every user, so use a lab cluster.
Task 3: Quotas and limit ranges
Task: In project1 limit total CPU to 2, memory to 4Gi and pods to 10, and set default container limits.
oc create quota compute-quota \
--hard=cpu=2, memory=4Gi, pods=10 -n project1
apiVersion: v1
kind: LimitRange
metadata:
name: default-limits
namespace: project1
spec:
limits:
- type: Container
default:
cpu: 500m
memory: 512Mi
defaultRequest:
cpu: 100m
memory: 128Mi
Verify with oc describe quota -n project1. Note that when a quota covers CPU and memory, pods without requests or limits are rejected unless a limit range supplies defaults. That is a common cause of "pod will not start" problems.
Task 3b: Create a project template (read the objectives)
If the objectives mention default project configuration, practise creating a template that adds a quota and a network policy to every new project, then setting it in the cluster's projects.config.openshift.io resource. Use oc adm create-bootstrap-project-template -o yaml as the starting point.
Task 4: Deploy an application, configuration and secrets
Task: Deploy a web app, give it an environment variable from a secret, and expose it with a TLS edge route.
oc new-app --name=web --image=registry.example.com/team/web:1.0 -n project1
oc create secret generic db-secret \
--from-literal=DB_PASSWORD='S3cret' -n project1
oc set env deployment/web --from=secret/db-secret -n project1
oc expose service web -n project1
oc create route edge web-secure --service=web --hostname=web.apps.example.com -n project1
For your own certificate use --cert, --key and --ca-cert. Learn the three route types: edge, passthrough and re-encrypt, and when each is used. Check with oc get route and curl -k https://web.apps.example.com.
Task 5: Scale an application and set autoscaling
Task: Run the app with three replicas, then add a horizontal pod autoscaler between two and five replicas at 70 percent CPU.
oc scale deployment/web --replicas=3 -n project1
oc autoscale deployment/web --min=2 --max=5 --cpu-percent=70 -n project1
oc get hpa -n project1
The autoscaler needs CPU requests on the pods to work. If it shows <unknown> for the target, check the requests and the metrics components.
Task 6: Network policy
Task: Only allow traffic to pods in project1 from pods in the same project.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-same-namespace
namespace: project1
spec:
podSelector: {}
ingress:
- from:
- podSelector: {}
Practise a second policy that allows traffic from the OpenShift router namespace, since otherwise your routes stop working. Test with oc exec and curl from a pod in another project.
Task 7: Persistent storage
Task: Give the application a 1Gi persistent volume mounted at /data.
oc set volumes deployment/web --add --name=data \
--type=pvc --claim-size=1Gi --claim-mode=ReadWriteOnce \
--mount-path=/data -n project1
oc get pvc -n project1
Know how to check the storage class with oc get storageclass and what to look at if the claim stays Pending.
Task 8: Node maintenance
Task: Take a worker node out of service for maintenance, then return it.
oc adm cordon worker-1
oc adm drain worker-1 --ignore-daemonsets --delete-emptydir-data
# do the maintenance
oc adm uncordon worker-1
Practise taints and tolerations, and node selectors in the same session, because they decide where pods run.
Task 9: Troubleshoot a failing pod
Task: A deployment's pod is in ImagePullBackOff or CrashLoopBackOff. Find the cause.
oc get pods -n project1
oc describe pod <pod-name> -n project1
oc logs <pod-name> -n project1
oc get events -n project1 --sort-by=.lastTimestamp
oc debug node/worker-1 -- chroot /host journalctl -u kubelet --no-pager | tail
Most failures come from a wrong image name, a missing pull secret, a missing quota default, a security context constraint or a bad probe. Read the events first.
Task 10: Operators
Task: Install an Operator from OperatorHub in a chosen namespace, using the web console, and check it is running.
Practise the console steps and the command-line equivalents: oc get csv -n <namespace>, oc get subscription -n <namespace> and oc get installplan. Know what the Operator Lifecycle Manager does.
What should you check before you finish any task?
- Did the change persist? A change made with
oc editthat a controller reverts does not count. - Are you in the right project? Use
oc projectoften. - Did you test from the user's side, such as logging in as the user you configured?
- Did you follow names, values and sizes exactly as the task states?
Common mistakes
- Reading only. The exam is typing.
- Forgetting to log in as the right user, or working in the wrong project.
- Replacing the OAuth resource and wiping existing providers.
- Skipping route and network policy practice, which interact.
- Not knowing where the documentation lives and burning minutes searching.
Next steps
For guided practice in a lab, see WebAsha's DO280 | EX280 Red Hat OpenShift Administration II course. If you are not yet comfortable with containers, start with DO180.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0