OpenShift EX280 Practice Tasks With Worked Solutions (Original, Not Real Exam Questions)

Prepare for the OpenShift DO280 course and EX280 exam with our comprehensive training program. Get access to Red Hat’s official study material, unlimited mock tests, ex280 dumps and a free exam retake. Our expert instructors guide you through real exam questions, hands-on labs, and personalized 1-1 doubt sessions to ensure you pass with confidence. Start your journey to becoming a Red Hat Certified Specialist in OpenShift Administration today!

Jan 23, 2025 - 16:14
Updated: 8 days ago
103.4k
OpenShift EX280 Practice Tasks With Worked Solutions (Original, Not Real Exam Questions)

Quick answer: Real EX280 questions are confidential and sharing them breaks Red Hat's candidate agreement, so this page offers original practice tasks instead. EX280 is a hands-on OpenShift administration exam: you complete tasks on a live cluster using oc. Practise identity providers, RBAC, quotas, secrets, routes, network policies, SCCs, scaling, storage and Operators until you can do each from memory.

Key takeaways

  • EX280 is performance-based. You are marked on the state of the cluster, so practising commands on a real cluster matters more than memorising answers.
  • Exam content is confidential. 'Real question' dumps are unreliable, may be outdated and can put your certification at risk.
  • These ten tasks are original and cover the skill areas Red Hat publishes for OpenShift administration. Check the official objectives for your exam version.
  • Use Deployment, not DeploymentConfig. DeploymentConfig is deprecated in current OpenShift 4 releases.
  • Learn oc explain, oc get -o yaml and --dry-run=client -o yaml. They are faster than searching documentation.

Why are real EX280 questions not published here?

Red Hat requires candidates to agree not to disclose exam content. That is the reason you will not find honest "real EX280 questions" anywhere. Pages that claim them are either guessing, outdated, or copying content that could lead Red Hat to revoke your certification. They also teach the wrong skill. EX280 does not ask you to pick an answer. It gives you a cluster and a task, and then checks the cluster.

The better approach is to practise tasks of the same kind. The ten below are original. They follow the public skill areas for OpenShift administration: access and authentication, RBAC, resource limits, secrets and configuration, networking, security contexts, scaling, storage and Operators. Always check Red Hat's published objectives for your exam version on the official certification pages.

What is EX280 and who is it for?

EX280 is the exam for the Red Hat Certified Specialist in OpenShift Administration credential. The matching course is DO280. It suits system administrators, platform engineers and DevOps engineers who run applications on OpenShift. It is a hands-on exam: you sit at a live cluster, run oc commands and edit YAML, and Red Hat checks the result.

How do you build a practice cluster?

  • OpenShift Local (formerly CodeReady Containers) runs a single-node cluster on a laptop and gives you admin access. It needs a good amount of RAM, so check its requirements.
  • The Red Hat Developer Sandbox is free and fine for application tasks, but you do not get cluster-admin rights, so you cannot practise OAuth or Operators there.
  • A trainer-provided lab mirrors the exam most closely.

Use a throwaway cluster. Some tasks below change authentication and cluster settings.

Task 1: Add users with an htpasswd identity provider

Task: Create users alice and bob that can log in to the cluster using an htpasswd identity provider named local-users.

htpasswd -c -B -b users.htpasswd alice 'Passw0rd!'
htpasswd -B -b users.htpasswd bob 'Passw0rd!'
oc create secret generic htpass-secret --from-file=htpasswd=users.htpasswd -n openshift-config
oc edit oauth cluster

In the editor, add the provider under spec:

spec:
 identityProviders:
 - name: local-users
 mappingMethod: claim
 type: HTPasswd
 htpasswd:
 fileData:
 name: htpass-secret

Wait for the authentication pods to roll out with oc get pods -n openshift-authentication -w, then test with oc login -u alice. Common mistake: replacing the whole OAuth object and deleting an existing provider. Run oc get oauth cluster -o yaml first and add to the list.

Task 2: Grant access with RBAC

Task: In project shop, give alice and bob edit rights through a group called dev-team, and give a user carol read-only access.

oc new-project shop
oc adm groups new dev-team alice bob
oc adm policy add-role-to-group edit dev-team -n shop
oc adm policy add-role-to-user view carol -n shop
oc auth can-i create deployments --as alice -n shop
oc auth can-i create deployments --as carol -n shop

The first check should say yes and the second no. Use roles over cluster-admin wherever you can, and bind to groups so access can be managed in one place.

Task 3: Set quotas and default limits

Task: Limit project shop to 10 pods and set total CPU and memory ceilings, then give containers default requests and limits.

oc create quota shop-quota --hard=pods=10, requests.cpu=2, requests.memory=4Gi, limits.cpu=4, limits.memory=8Gi -n shop
cat <<'EOF' | oc apply -n shop -f -
apiVersion: v1
kind: LimitRange
metadata:
 name: shop-limits
spec:
 limits:
 - type: Container
 default:
 cpu: 500m
 memory: 512Mi
 defaultRequest:
 cpu: 100m
 memory: 128Mi
EOF
oc describe quota shop-quota -n shop

A quota that covers CPU or memory means every pod must declare requests or limits, or the LimitRange must supply defaults. Without the LimitRange, new pods are rejected, which is a classic confusing failure.

Task 4: Deploy an app and inject configuration and a secret

Task: Deploy a web app, supply a database password from a Secret and a setting from a ConfigMap as environment variables.

oc create deployment web --image=registry.access.redhat.com/ubi9/httpd-24 -n shop
oc create secret generic db-creds --from-literal=DB_PASSWORD='S3cret!' -n shop
oc create configmap web-config --from-literal=APP_MODE=production -n shop
oc set env deployment/web --from=secret/db-creds -n shop
oc set env deployment/web --from=configmap/web-config -n shop
oc rollout status deployment/web -n shop
oc exec deployment/web -n shop -- env | grep -E 'DB_PASSWORD|APP_MODE'

Note this uses a Deployment. DeploymentConfig is deprecated in current OpenShift 4 releases, so expect Deployments in new work.

Task 5: Expose the app securely with an edge route

Task: Create a service for the app and publish it over HTTPS with TLS terminated at the router.

oc expose deployment web --port=8080 -n shop
openssl req -x509 -newkey rsa:2048 -nodes -days 30 -keyout tls.key -out tls.crt -subj "/CN=web.apps-crc.testing"
oc create route edge web --service=web --cert=tls.crt --key=tls.key --hostname=web.apps-crc.testing -n shop
curl -k https://web.apps-crc.testing

Use a hostname that matches your lab's apps domain. The self-signed certificate is for practice only.

Route typeWhere TLS endsUse when
EdgeAt the routerRouter holds the certificate, traffic to the pod is plain
PassthroughAt the podThe application must handle its own TLS
Re-encryptRouter, then re-encrypted to the podYou need encryption end to end and router-level certificates

Task 6: Restrict traffic with a NetworkPolicy

Task: In shop, deny all ingress by default, then allow traffic from inside the project and from the OpenShift router.

cat <<'EOF' | oc apply -n shop -f -
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
 name: deny-all
spec:
 podSelector: {}
 policyTypes: [Ingress]
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
 name: allow-same-namespace
spec:
 podSelector: {}
 ingress:
 - from:
 - podSelector: {}
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
 name: allow-from-openshift-ingress
spec:
 podSelector: {}
 ingress:
 - from:
 - namespaceSelector:
 matchLabels:
 policy-group.network.openshift.io/ingress: ""
EOF

Without the third policy, your route stops working because the router lives in another namespace. Check the label name against your cluster's documentation, since it is the part most likely to differ.

Task 7: Fix a pod blocked by a Security Context Constraint

Task: A pod fails because its image wants to run as root. Find why and apply the least risky fix.

oc get events -n shop --sort-by=.lastTimestamp | tail
oc describe pod <pod-name> -n shop
oc get pod <pod-name> -n shop -o yaml | grep 'openshift.io/scc'
oc create sa appsa -n shop
oc adm policy add-scc-to-user anyuid -z appsa -n shop
oc set serviceaccount deployment/web appsa -n shop

By default, OpenShift runs pods under the restricted SCC with a random user ID. Granting anyuid to a dedicated service account is narrower than granting it to everyone, but the better fix, when you control the image, is to make it run as a non-root user. After the rollout, the SCC annotation on the new pod shows which SCC was applied.

Task 8: Add probes and autoscaling

Task: Add a readiness probe, set CPU requests, and scale between 2 and 5 replicas at 70% CPU.

oc set probe deployment/web --readiness --get-url=http://:8080/ --initial-delay-seconds=5 -n shop
oc set resources deployment/web --requests=cpu=100m, memory=128Mi -n shop
oc autoscale deployment/web --min=2 --max=5 --cpu-percent=70 -n shop
oc get hpa -n shop
oc scale deployment/web --replicas=3 -n shop

The autoscaler needs CPU requests to calculate utilisation. Note that when an HPA is active, it will override a manual oc scale after a short time.

Task 9: Add persistent storage

Task: Give the app a 1 GiB persistent volume mounted at /var/data.

oc set volumes deployment/web --add --name=data -t pvc --claim-name=web-data --claim-size=1Gi --mount-path=/var/data -n shop
oc get pvc -n shop
oc rollout status deployment/web -n shop

If the claim stays in Pending, check oc get storageclass to confirm a default class exists, and read oc describe pvc web-data for the reason. Multiple replicas sharing a ReadWriteOnce volume is a typical trap.

Task 10: Install an Operator from the catalogue

Task: Install an Operator in a namespace and confirm that it is running.

oc get packagemanifests -n openshift-marketplace | grep -i <keyword>
oc get packagemanifest <package> -n openshift-marketplace -o jsonpath='{.status.defaultChannel}'
cat <<'EOF' | oc apply -f -
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
 name: <package>
 namespace: <target-namespace>
spec:
 channel: <channel>
 name: <package>
 source: redhat-operators
 sourceNamespace: openshift-marketplace
EOF
oc get csv -n <target-namespace>

Operators that install into a single namespace also need an OperatorGroup in that namespace. You can do the same from the web console's OperatorHub, which is fine in the exam if it is quicker for you. The success check is the same: the ClusterServiceVersion reaches Succeeded.

How do you troubleshoot a failing pod?

Start with oc get pods, read the status, then pick the right command.

StatusLook withLikely causes
Pendingoc describe podNot enough CPU or memory, quota reached, unbound PVC, node selector or taint mismatch
ImagePullBackOffoc describe podWrong image name or tag, missing pull secret, registry unreachable
CrashLoopBackOffoc logs --previousApplication error, missing environment variable or Secret, wrong command
Running but not Readyoc describe pod, oc logsFailing readiness probe, wrong port
Route returns 503oc get endpoints, oc describe routeService selector does not match pod labels, no ready pods

Use oc debug node/<node> or oc debug deployment/web when you need a shell in a troubleshooting copy of the workload.

How do you practise under exam conditions?

  1. Pick six to eight tasks at random from your own list and set a timer.
  2. Close all notes. Allow only oc --help and oc explain.
  3. Verify every result with a command, not by assumption. For example, run curl against the route and oc auth can-i for access checks.
  4. Reset the cluster, or at least the project, and repeat the ones you were slow on.

Two habits save the most time: oc explain deployment.spec.template.spec --recursive to find field names, and oc create... --dry-run=client -o yaml to generate a YAML skeleton you edit instead of writing from scratch. Our 10 tips for the DO280 and EX280 exam covers more exam-day habits.

Next steps

Run all ten tasks twice this week, the second time without looking at the solutions. For trainer-led labs and the official course material, see our OpenShift DO280 and EX280 course, and read the EX280 certification overview to see how the credential fits your career.

Related reading

Frequently Asked Questions

DO280 is Red Hat's official course on OpenShift administration. It teaches managing users and access, deploying and securing applications, networking, storage and cluster operations on OpenShift, and prepares you for the EX280 exam.

EX280 is the hands-on exam for the Red Hat Certified Specialist in OpenShift Administration credential. You perform administration tasks on a live OpenShift cluster and are marked on whether the cluster ends up configured as the task requires.

Not legitimately. Red Hat candidates agree not to share exam content, so any 'real questions' are unreliable and may be outdated. Practise with original tasks and the official course labs instead.

Run OpenShift Local on your laptop for a single-node cluster with admin access, or use a lab environment from your training provider. The free Developer Sandbox is useful for application tasks but does not give cluster-admin rights.

You do not get general internet or notes. Learn to use oc explain, oc --help and the cluster's own resources to look up fields. Check Red Hat's current exam page for what documentation is available in your exam.

oc login, oc new-project, oc create, oc apply, oc get with -o yaml, oc describe, oc logs, oc set, oc adm policy, oc adm groups, oc expose, oc create route, oc scale and oc debug. Know their common flags without looking.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Aayushi Sinha

With a passion for staying on the cutting edge of technology trends, I am dedicated to delivering content that not only informs but also inspires. Whether you need in-depth analysis pieces, informative guides, or thought-provoking opinion pieces, I craft content that resonates with tech enthusiasts and professionals alike.