RHCSA EX200 Practice Questions and Answers: 23 Original Hands-On Tasks
Prepare for the RHCSA EX200 exam with real exam questions and answers. Access dumps, live interactive sessions, Red Hat official study material, mock tests, and a free retake exam voucher. Enroll now for expert-led training and boost your chances of certification success!
Quick answer: Real EX200 questions cannot be legitimately shared: Red Hat candidates agree not to disclose exam content, and EX200 is a live hands-on exam, so memorised answers fail. What works is practising the task types it tests: users and permissions, LVM storage, networking, firewalld, SELinux, services and containers. This page gives 23 original tasks with solutions for an RHEL 10 style lab.
Key takeaways
- EX200 is hands-on and based on RHEL 10; you are scored on the final working configuration.
- Practise tasks in a lab and verify every one with a command, including after a reboot.
- Never turn SELinux off to fix a problem; learn semanage, restorecon and booleans.
- Use the official Red Hat objective list as the source of truth and docs.redhat.com as your reference.
Why this page does not list "real" exam questions
When you sit an exam from Red Hat, you agree not to disclose its content. Real questions are not meant to be shared, and anyone selling them is selling something that breaks that agreement. Using leaked material can lead to your result being cancelled or a certification being revoked. It also does not work. EX200 is a hands-on exam in which you configure a live system, so memorised answers do not help if you cannot do the task. This page covers what actually helps: original practice tasks, with solutions, written for the skills the exam tests.
The current exam is based on RHEL 10. Check the official objective list on Red Hat Training and Certification before you start, because objectives change between versions. The tasks below use commands that are stable across recent RHEL releases, but test them on an RHEL 10 (or Rocky or AlmaLinux 10) lab VM.
How to use these tasks
- Build a lab: two RHEL-compatible VMs with an extra empty disk or two on the first. Take snapshots before you start.
- Read a task, close the page, and try it without looking. Use
manand--helpas you would in the exam. - Verify the result with a command, not by belief. Then compare with the solution.
- Reboot after storage, networking and SELinux tasks. Configuration that does not survive a reboot scores nothing in a real exam.
- Redo each task a week later from scratch.
Passwords and names below are placeholders for a lab. Replace them with your own.
Users, groups and permissions
Task 1: Create a group and users
Create group devs with GID 3000. Create users alice and bob as members of devs, and carol with no login shell. Set a password for alice and make it expire after 90 days with a 7-day warning.
groupadd -g 3000 devs
useradd -G devs alice
useradd -G devs bob
useradd -s /sbin/nologin carol
echo 'alice:ChangeMe123' | chpasswd
chage -M 90 -W 7 alice
id alice; chage -l alice
Task 2: A shared directory
Create /srv/shared, owned by group devs, so that new files inherit the group, members have full access and others have none.
mkdir /srv/shared
chgrp devs /srv/shared
chmod 2770 /srv/shared
ls -ld /srv/shared
The leading 2 is the set-GID bit, shown as an s in the group permissions.
Task 3: ACLs
Let carol read and enter /srv/shared, and make that apply to new files created inside it.
setfacl -m u:carol:rx /srv/shared
setfacl -d -m u:carol:rx /srv/shared
getfacl /srv/shared
Task 4: Limited sudo
Allow members of devs to restart httpd as root without a password, and nothing else.
visudo -f /etc/sudoers.d/devs
# add the line:
%devs ALL=(root) NOPASSWD: /usr/bin/systemctl restart httpd
visudo -c
Storage
Task 5: Partition, LVM and a persistent mount
On the spare disk (assumed /dev/vdb), create a 2 GiB partition, a volume group vgdata with 8 MiB extents, a 1 GiB logical volume lvapp formatted as XFS and mounted at /app on every boot.
parted -s /dev/vdb mklabel gpt mkpart primary 1MiB 2GiB set 1 lvm on
pvcreate /dev/vdb1
vgcreate -s 8M vgdata /dev/vdb1
lvcreate -n lvapp -L 1G vgdata
mkfs.xfs /dev/vgdata/lvapp
mkdir /app
blkid /dev/vgdata/lvapp # note the UUID
echo 'UUID=<uuid-here> /app xfs defaults 0 0' >> /etc/fstab
systemctl daemon-reload
mount -a
findmnt --verify; df -hT /app
Always run mount -a after editing fstab. A typo here can stop the machine booting.
Task 6: Extend a logical volume
Grow lvapp by 500 MiB while it stays mounted.
vgs vgdata # check free space first
lvextend -r -L +500M /dev/vgdata/lvapp
df -h /app
The -r flag grows the file system as well. XFS can be grown but never shrunk.
Task 7: Swap
Add 512 MiB of swap that persists.
lvcreate -n lvswap -L 512M vgdata
mkswap /dev/vgdata/lvswap
echo '/dev/vgdata/lvswap none swap defaults 0 0' >> /etc/fstab
systemctl daemon-reload
swapon -a
swapon --show
Networking and time
Task 8: Static IP and hostname
Set a static IPv4 address, gateway and DNS server on the connection, and set the hostname.
nmcli connection show # find the real connection name
nmcli connection modify ens3 ipv4.method manual \
ipv4.addresses 192.168.122.50/24 ipv4.gateway 192.168.122.1 \
ipv4.dns 192.168.122.1
nmcli connection up ens3
hostnamectl set-hostname server1.example.com
ip -br addr; hostnamectl
Use NetworkManager tools (nmcli or nmtui). Do not hand-edit old ifcfg files on current RHEL versions.
Task 9: Firewall
Permanently allow HTTP and TCP port 8080 in the default zone.
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-port=8080/tcp
firewall-cmd --reload
firewall-cmd --list-all
Task 10: Time synchronisation
Make the system sync time from ntp.example.com.
vi /etc/chrony.conf # add: server ntp.example.com iburst
systemctl enable --now chronyd
systemctl restart chronyd
chronyc sources -v
Services, boot and scheduling
Task 11: Services and the default target
Install and start Apache so that it starts at boot, and make the system boot to the text target.
dnf install -y httpd
systemctl enable --now httpd
systemctl is-enabled httpd; systemctl is-active httpd
systemctl set-default multi-user.target
systemctl get-default
Task 12: Recover a lost root password
At the GRUB menu press e, add rd.break to the end of the line starting with linux, and press Ctrl+x. Then:
mount -o remount, rw /sysroot
chroot /sysroot
passwd root
touch /.autorelabel
exit
exit
The .autorelabel file matters: without it SELinux contexts on the changed password file are wrong and you cannot log in. This procedure has been stable across recent RHEL releases, but confirm it on your RHEL 10 lab.
Task 13: Scheduled jobs
Run logger "backup check" every 10 minutes as alice, and once at 23:30 tonight as root.
crontab -u alice -e # */10 * * * * logger "backup check"
echo 'logger "backup check"' | at 23:30
atq; systemctl is-active crond
Task 14: Performance profile
tuned-adm recommend
tuned-adm profile virtual-guest
tuned-adm active
SELinux
Task 15: A web server on a non-standard port
Apache must listen on port 8888. It fails to start with SELinux enforcing. Fix it without disabling SELinux.
semanage port -l | grep http_port_t
semanage port -a -t http_port_t -p tcp 8888
# also edit Listen in /etc/httpd/conf/httpd.conf and open the firewall port
systemctl restart httpd
Task 16: A custom document root
Serve content from /web. Files there must get the correct context permanently.
mkdir /web; echo test > /web/index.html
semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?"
restorecon -Rv /web
ls -Z /web
Task 17: Booleans and mode
getsebool -a | grep httpd_enable_homedirs
setsebool -P httpd_enable_homedirs on
getenforce
grep ^SELINUX= /etc/selinux/config
Make sure the mode in /etc/selinux/config is enforcing. setenforce 0 is temporary and is not a fix.
Task 18: Diagnose a denial
ausearch -m avc -ts recent
sealert -a /var/log/audit/audit.log # if setroubleshoot is installed
journalctl -t setroubleshoot
Read what context the process and the file have, then decide whether to relabel the file, change a boolean, or add a port. Do not generate policy modules unless nothing else fits.
Software, files and archives
Task 19: Configure a repository and install a package
cat > /etc/yum.repos.d/lab.repo <<'EOF'
[lab-baseos]
name=Lab BaseOS
baseurl=http://repo.example.com/BaseOS
enabled=1
gpgcheck=0
EOF
dnf clean all; dnf repolist
dnf install -y tree
In a lab, gpgcheck=0 is acceptable. In real use, keep signature checking on and import the key.
Task 20: Find, copy, search
mkdir /root/found
find / -user alice -type f -exec cp -p {} /root/found/ \; 2>/dev/null
grep -E '^(root|alice):' /etc/passwd > /root/users.txt
find /var -size +10M 2>/dev/null
Task 21: Archive and compress
tar -czf /root/etc-backup.tar.gz /etc
tar -tzf /root/etc-backup.tar.gz | head
tar -xzf /root/etc-backup.tar.gz -C /tmp etc/hostname
Task 22: Links and file attributes
ln -s /app /home/alice/appdir
ln /root/users.txt /root/users-hard.txt
ls -li /root/users*.txt
The two names in the hard link share one inode number; the symbolic link is its own file.
Containers
Task 23: Run a rootless container that starts at boot
As a normal user, run a web container with a persistent host directory. Start it automatically after reboot.
loginctl enable-linger alice
# as alice:
podman run -d --name web -p 8080:80 -v /home/alice/site:/usr/share/nginx/html:Z docker.io/library/nginx
podman ps
For start at boot, create a Quadlet file such as ~/.config/containers/systemd/web.container and enable the generated user unit with systemctl --user. Follow the current Red Hat container documentation for the exact keys on your version. The :Z on the volume sets the SELinux label so the container can read the files.
Common mistakes that cost marks
- Not rebooting to check persistence.
- Putting device names like
/dev/vdb1in fstab where a UUID or LV path is safer. - Turning SELinux off or permissive to "make it work".
- Forgetting
--permanentand--reloadin firewalld, or-Pin setsebool. - Misreading the task: wrong size, wrong user, wrong path, wrong name.
- Spending too long on one task. Move on and come back.
What the exam looks like
EX200 is a performance-based exam with no multiple choice. You work on live systems and are scored on the final state of the configuration. For the RHEL 9 version, Red Hat listed a duration of 2.5 hours; check the current exam page for the RHEL 10 version's length and passing score. The skills grouped above (users and permissions, storage, networking, services, SELinux, software, containers) mirror the main objective areas, but the official list is the source to follow. Red Hat's product documentation on docs.redhat.com is what you should practise searching, because that is the kind of help you will have.
Next steps
Do all 23 tasks twice, then build your own variations: change sizes, names and ports. If you want instructor-led practice and lab access, see the RHCSA EX200 course; the course page lists what is currently included. Read how to pass RHCSA EX200 in your first attempt for a study plan. For voucher details, see the pages on the RHCSA exam voucher.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0