Implementing DevOps Solutions and Practices Using Cisco Platforms (DEVOPS) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 250 questions. Use the simulator for timed and flashcard mode.

Try Simulator

300-910 Sample Questions

  1. Question 1

    Q1

    A financial services company is containerizing a legacy Java application using Docker. The security team mandates that the final container image must not include the JDK, build tools like Maven, or any intermediate build artifacts. Furthermore, the image size must be minimized. Which Dockerfile feature is most effective for meeting these requirements?

    Show answer & explanation

    Correct answer: B

    A multi-stage build is the ideal solution. It allows you to use one stage with a full JDK and Maven to compile the application and build the JAR file, and a second, final stage that starts from a minimal JRE base image and copies only the compiled application artifact. This ensures no build tools or intermediate files are present in the final image, directly addressing both security and size requirements.

  2. Question 2

    Q2

    A DevOps team is responsible for a multi-cloud deployment of a critical application running on Kubernetes clusters in both AWS (EKS) and Azure (AKS). They need a secure method to store database credentials that can be accessed by pods in either cluster without hardcoding them into container images or deployment manifests. Which approach provides the most secure, cloud-agnostic, and centrally manageable solution?

    Show answer & explanation

    Correct answer: C

    HashiCorp Vault is a dedicated secrets management tool designed to be cloud-agnostic. By deploying a central Vault cluster, you create a single source of truth for secrets. The Vault Agent Injector can be deployed to both Kubernetes clusters, allowing pods to authenticate using their Kubernetes Service Account and receive secrets dynamically via a sidecar container. This approach is highly secure, centralized, and avoids vendor lock-in, making it the best choice for a multi-cloud scenario.

  3. Question 3

    Q3Multiple answers

    During a security review of a CI/CD pipeline, it was discovered that developers are building container images on their local machines and pushing them directly to the production container registry. This practice introduces significant security risks. Which TWO of the following methods should be implemented in the CI/CD pipeline to mitigate these risks and enforce a secure software supply chain? (Select TWO).

    Show answer & explanation

    Correct answers: A, B

  4. Question 4

    Q4

    A platform engineering team wants to provide application developers with a standardized, repeatable way to deploy their applications to Kubernetes. They decide to use 'golden images' for their base containers. True or False: In this context, a 'golden image' refers to a pre-configured virtual machine template stored in vSphere.

    Show answer & explanation

    Correct answer: B

    This statement is false. While 'golden image' can refer to a VM template in a traditional infrastructure context, in the context of containerized application deployment for Kubernetes, it refers to a standardized, pre-configured base container image. This base image would be stored in a container registry (like Docker Hub or ECR) and would include common dependencies, security configurations, and monitoring agents required by the organization.

  5. Question 5

    Q5

    A NetDevOps team is building a CI/CD pipeline to manage Cisco IOS XE router configurations using Terraform. A crucial requirement is to verify the intended operational state before applying any changes. The pipeline needs a step that generates an execution plan, showing what actions Terraform will take to modify the infrastructure, without actually performing them. Which Terraform command should be used for this pre-check validation step?

    Show answer & explanation

    Correct answer: C

    The terraform plan command is used specifically to create an execution plan. It compares the desired state defined in the Terraform configuration files with the actual state of the remote infrastructure and outputs the set of changes that will be made. This 'dry run' capability is essential for pre-check validation in a CI/CD pipeline, allowing for review and approval before any changes are applied with terraform apply.

  6. Question 6

    Q6

    A development team is deploying a new microservice to a Kubernetes cluster. They have created a Deployment object, but the application is not accessible from outside the cluster. They need to expose the application via a stable network endpoint within the cluster so other microservices can communicate with it. Which Kubernetes object should they create to achieve this internal-facing accessibility?

    Show answer & explanation

    Correct answer: B

    A Kubernetes Service provides a stable network abstraction layer for a set of pods. It creates a single, stable IP address and DNS name (e.g., my-service.default.svc.cluster.local) that other applications within the cluster can use to access the pods managed by the Deployment. The Service automatically handles load balancing across the pods, even as they are created or destroyed. An Ingress is for external access, a Pod is the workload itself, and a ConfigMap is for configuration data.

  7. Question 7

    Q7

    An SRE team is adopting chaos engineering principles to test the resilience of their distributed application. Their first experiment is to simulate a latency increase in the connection to a critical downstream database service. What is the primary goal of this type of chaos experiment?

    Show answer & explanation

    Correct answer: C

    The primary goal of chaos engineering is to build confidence in the system's ability to withstand turbulent conditions in production. By injecting latency, the team is proactively testing whether the application's built-in resilience patterns (like timeouts, retries, and circuit breakers) behave as expected. This helps uncover hidden weaknesses before they cause a real-world outage.

  8. Question 8

    Q8

    A DevOps engineer is implementing a secure software development life cycle (SDLC). The goal is to identify potential security vulnerabilities in the application code itself, before it is ever compiled or deployed. Which security testing method should be integrated into the CI pipeline to achieve this?

    Show answer & explanation

    Correct answer: B

    Static Application Security Testing (SAST) analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the program. Because it works directly on the code, it can be integrated very early in the SDLC, such as upon a code commit or pull request, to find issues like SQL injection or buffer overflows before the application is even built. DAST requires a running application, IAST combines both, and penetration testing is typically a later-stage manual or automated process.

  9. Question 9

    Q9

    An organization is migrating its CI/CD processes to a new platform and needs to choose a build/deploy tool. The primary requirements are that the tool must be highly extensible through a vast ecosystem of plugins, be self-hosted for security compliance, and have strong community support. Which of the following tools best fits these characteristics?

    Show answer & explanation

    Correct answer: A

    Jenkins is renowned for its massive plugin ecosystem, which allows for extensive customization and integration with virtually any tool. It is an open-source, self-hosted solution, which satisfies the security compliance requirement. Its long history has resulted in a very large and active community, providing ample support and resources. While Drone is also self-hosted, its plugin ecosystem is smaller. Travis CI is primarily a cloud-based SaaS offering.

  10. Question 10

    Q10

    A DevOps team is managing a Python application that has a requirements.txt file listing several dependencies, including requests==2.25.1 and urllib3 =1.25.4. The CI/CD pipeline fails during the pip install stage with a dependency resolution error. This is a common and recurring problem. What is the most likely cause of this type of failure?

    Show answer & explanation

    Correct answer: C

    This is a classic transitive dependency conflict. The requests library itself depends on urllib3. If version 2.25.1 of requests requires a version of urllib3 that is outside the =1.25.4 range, pip will be unable to find a compatible set of packages, leading to a resolution error. This highlights the complexity of managing dependencies in modern applications.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 300-910 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 250 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon