Red Hat Certified Specialist in OpenShift Networking exam Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode.

Try Simulator

EX282 Sample Questions

  1. Question 1

    Q1

    A network engineer needs to configure a secondary network attachment for high-throughput container workloads on OpenShift Container Platform 4.20. The pods require direct Layer 2 connectivity to an external physical subnet connected to worker node interface eth2. Communication between pods scheduled on the same worker node over this secondary network must be switched internally within the node kernel without requiring frames to traverse an external physical switch, while each pod retains an independent MAC address. Which CNI plugin type and operating mode must be specified in the NetworkAttachmentDefinition?

    Show answer & explanation

    Correct answer: A

    The macvlan CNI plugin in bridge mode creates sub-interfaces on the parent physical device (eth2), each with a unique MAC address. In bridge mode, traffic between endpoints on the same host interface is switched directly within the Linux kernel, preventing packets from looping out to an external physical switch. In contrast, private mode drops inter-endpoint traffic on the same host, vepa requires an external switch supporting IEEE 802.1Qbg Hairpin mode, and passthru dedicates the physical interface entirely to a single container.

  2. Question 2

    Q2

    A quantitative trading firm runs latency-critical algorithmic applications on OpenShift Container Platform 4.20 bare-metal worker nodes. The network infrastructure team requires secondary interfaces on pods to connect directly to an external low-latency market data network attached to ens2f1.

    The upstream switch fabric enforces strict Port Security policies: each switchport is restricted to the single MAC address of the physical server NIC. Any incoming packet presenting an untrusted or newly generated MAC address causes an immediate port shutdown. Furthermore, the application team requires Layer 3 routing handled entirely in the host kernel stack, with pod IP addresses assigned from non-overlapping subnets without bridging overhead.

    Which secondary network configuration satisfies the upstream switch port security constraint while routing traffic via the host network stack?

    graph LR subgraph WorkerNode["Worker Node (Bare Metal)"] subgraph PodNS["Pod Network Namespace"] net1["Interface: net1 IP: 192.168.50.15/24"] end HostStack["Linux Host IP Routing Stack"] PhysicalNIC["Parent NIC: ens2f1 HWaddr: 52:54:00:ab:cd:ef"] net1 -->|Shares Parent MAC| HostStack HostStack --> PhysicalNIC end PhysicalNIC --> SwitchPort["ToR Switch Port (Port Security: 1 MAC)"]
    Show answer & explanation

    Correct answer: A

    The ipvlan plugin creates virtual network interfaces that share the exact physical MAC address of the master interface (ens2f1), satisfying upstream port security rules that permit only one MAC address. In mode: "l3", all Layer 2 broadcast and ARP processing is eliminated; the host networking stack routes packets directly at Layer 3 between the pod namespace and the physical interface. In contrast, macvlan creates distinct virtual MAC addresses for each pod, triggering port shutdown on the switch. ipvlan in l2 mode still acts as an L2 bridge (sharing the MAC), but does not route via the host kernel routing table. A Linux bridge with macspoofchk: true still exposes multiple MACs or drops frames.

  3. Question 3

    Q3

    A systems administrator is configuring a secondary network attachment definition for pods to receive IP addresses dynamically from an existing external corporate DHCP server. What must be deployed or configured on the OpenShift Container Platform cluster for the secondary network attachment's DHCP IPAM plugin to acquire and renew leases?

    Show answer & explanation

    Correct answer: D

    OpenShift Container Platform does not provide an integrated DHCP server. To utilize external DHCP servers for secondary networks, the DHCP CNI plugin relies on a local node-level daemon. Administrators must enable the DHCP IPAM CNI daemon by modifying the Cluster Network Operator (CNO) configuration (network.operator.openshift.io/cluster), which deploys the required DaemonSet on cluster nodes to request, maintain, and renew DHCP leases for pod attachments.

  4. Question 4

    Q4Multiple answers

    A cloud architect is designing secondary network attachments across worker nodes using the whereabouts IPAM plugin. The cluster does not have access to an external DHCP server. Which TWO statements accurately describe the configuration options and operational constraints of the whereabouts CNI plugin in OpenShift Container Platform 4.20? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    The whereabouts CNI IPAM plugin supports defining network_name within its IPAM configuration, enabling multiple NetworkAttachmentDefinition resources to share the same dynamic IP address allocation pool. Furthermore, because whereabouts calculates IP offsets using 64-bit integers (uint64), IPv6 subnets with prefix lengths of /64 or shorter would exceed the 64-bit integer limit; therefore, narrower subnets (e.g., /119 or /120) must be used. whereabouts allocates IPs cluster-wide rather than strictly node-local, and its reconciler runs automatically as a DaemonSet managed by the CNO.

    The whereabouts IPAM plugin uses 64-bit unsigned integers (uint64) internally to track address offsets. A standard /64 IPv6 subnet contains 2^64 addresses, which causes integer overflow in offset math. Therefore, Red Hat documentation explicitly mandates that IPv6 subnets for whereabouts must use prefix lengths longer than /64 (such as /119 to /128).

  5. Question 5

    Q5

    A developer needs to isolate a namespace named payment-processor using a primary UserDefinedNetwork (UDN) with Layer 2 topology. What is the mandatory requirement regarding namespace labeling when configuring a primary user-defined network in OpenShift Container Platform 4.20?

    Show answer & explanation

    Correct answer: B

    In OpenShift Container Platform 4.20, configuring a primary UserDefinedNetwork requires that the namespace be labeled with k8s.ovn.org/primary-user-defined-network: "" strictly when the namespace is created. OVN-Kubernetes does not support converting an existing default namespace to a primary user-defined network by appending the label after namespace creation.

  6. Question 6

    Q6

    When authoring a namespace-scoped UserDefinedNetwork (UDN) resource with spec.topology: Layer3, which subnet fields are mandatory under spec.layer3.subnets?

    Show answer & explanation

    Correct answer: B

    Under spec.topology: Layer3, the subnets stanza is mandatory and requires defining both cidr (the total CIDR block assigned to the user-defined network across the cluster) and hostSubnet (the subnet mask length allocated to each individual node for pods on that node, e.g., 24 for IPv4 or 64 for IPv6). In contrast, Layer 2 UDN subnets only accept a list of CIDR strings without hostSubnet because Layer 2 forms a single broadcast domain across nodes.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the EX282 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 150 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon