Be able to run, inspect, and troubleshoot Podman containers on RHEL, especially rootless containers with bind mounts. The single most important thing: get SELinux labeling and host directory ownership right so the container can actually read and write mounted storage.
Start practicing
Manage containers — choose a session length
Free · No account required
Domain overview
The Manage containers domain of EX200 covers running and inspecting OCI containers with Podman on RHEL, including rootless operation, bind mounts, SELinux labeling, and persistent storage. Questions are task-oriented: you read command output or a scenario, then choose the podman command, flag, or conclusion that satisfies the stated requirement.
Exam objectives
Running rootless containers with podman run --user and mapping host UID/GID ownership
Bind-mounting host directories with -v and applying :Z or :z SELinux relabeling
Inspecting container network and storage config via podman inspect output fields
Managing persistent container data with named volumes and podman volume commands
Assuming a bind-mounted directory is writable without matching host ownership or SELinux labels, so the container fails despite correct --user settings.
Confusing :Z (private relabel) with :z (shared relabel), which breaks access when multiple containers use the same host path.
Treating podman inspect fields as runtime guarantees; misreading network or mount output and drawing wrong conclusions about the container.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator needs to ensure that a container always runs with a specific SELinux context for security reasons. The container uses a volume mount from the host. Which command should be used to start the container?
2A system administrator wants to run a container that uses the rootless mode available in Podman. Which requirement must be met for rootless containers to work correctly?
3A container running a database service needs to persist data across restarts. The administrator decides to use a named volume. Which command creates a named volume and mounts it correctly?
4Which TWO statements are true regarding container images and containers in Podman?
5Which THREE actions are required to enable a non-root user to run containers using Podman on Red Hat Enterprise Linux 8?
6A system administrator needs to run a container that remains running in the background and executes a web server. Which podman command will correctly run the container detached and map host port 8080 to container port 80?
7A container named 'web1' was created and ran briefly before exiting with status 0. The administrator needs to restart it and attach to the running container's console. Which command should be used?
8Put the steps to configure NFS server to export /nfsshare to a specific client in order.
9Match each log file to its typical content.
10A user wants to run a container that will restart automatically unless explicitly stopped by the administrator. Which podman run option should be used?
11A container fails to start because the port it needs is already in use. Which command can the administrator use to identify the process using the port?
12A team wants to run a container as a non-root user inside the container for security. Which instruction should be included in the Containerfile?
13A containerized web server needs to persist logs outside the container. Which podman run option allows the administrator to specify a bind mount with mount propagation options?
14A database container crashes repeatedly. The administrator wants to see the last 10 lines of the container's logs before it exited. Which command should be used?
15An administrator is building a container image with a Containerfile. They want to ensure that a specific RUN command always executes without using the build cache. Which build option should they use?
16A container needs to share the host's network namespace for performance monitoring. Which podman run option achieves this?
17Which TWO options to podman run can be used to persist data outside the container? (Select exactly two.)
18Which THREE options to podman run can be used to publish container ports to the host? (Select exactly three.)
19A container is running but cannot be accessed from the network. Which TWO commands could help diagnose the issue? (Select exactly two.)
20Based on the exhibit, which command should be used to start the container named 'mycontainer'?
21Based on the exhibit, which statement about the container 'webserver' is true?
22An administrator needs to run a container with a bind mount of the host directory /data to /var/lib/data inside the container. The container image is web:latest. Which command correctly achieves this?
23A system administrator wants to run a container as a systemd service that restarts automatically after a system reboot. Which approach follows Red Hat best practices?
24An administrator needs to pull a container image from a private registry at registry.example.com:5000. The registry requires authentication. Which command should be used first?
25A containerized application writes logs to stdout. The administrator wants to view only the last 50 lines of logs from a container named 'app1'. Which command accomplishes this?
26Which file should be present in a directory to build a container image using 'podman build'?
27An administrator wants to run a container with --user 1001:1001 to avoid running as root. After starting, the container cannot write to a bind-mounted directory owned by root. What is the best practice to allow write access?
28A container exits immediately with status 1. The administrator runs 'podman logs container' but sees no output. What is the most likely reason for the missing logs?
29Which TWO options correctly describe the use of 'podman exec'? (Choose TWO.)
30Which THREE statements about container storage in podman are correct? (Choose THREE.)
31A company runs a critical web application in a container on a Red Hat Enterprise Linux 9 server. The container is started via a systemd service called 'webapp.service'. The service unit file was generated using 'podman generate systemd --new --name webapp'. Recently, after a kernel update and reboot, the service fails to start the container. The administrator runs 'systemctl status webapp.service' and sees 'Active: failed (Result: exit-code)' and 'Process: 1234 ExecStart=/usr/bin/podman run ... (code=exited, status=125)'. The administrator also checks 'journalctl -u webapp.service' and sees: 'Error: unable to start container: container create failed: OCI runtime error: container_linux.go:380: starting container process caused: exec: "/usr/bin/app.sh": stat /usr/bin/app.sh: no such file or directory'. The container image was built locally using a Containerfile that includes 'COPY app.sh /usr/bin/app.sh'. The administrator verifies the image is present locally. What should the administrator do to resolve this issue?
32A system administrator is troubleshooting a container that fails to start with the error: 'Error: cannot start container: listen tcp4 :80: bind: address already in use'. The container is intended to serve HTTP traffic on port 80. What is the most appropriate first step to resolve this issue?
33A developer is running Podman as a non-root user on a Red Hat Enterprise Linux 8 system. The developer successfully runs a container, but notices that after logging out of the SSH session, the container stops. The developer wants the container to continue running even after disconnecting from the SSH session. The container is a simple web server that listens on port 8080. The developer has already enabled lingering for the user account using 'loginctl enable-linger'. However, the container still stops upon logout. What additional step should the developer take to ensure the container persists after logout?
34A system administrator needs to ensure that data written to a container's `/var/lib/mysql` directory persists after the container is removed. Which TWO methods accomplish this requirement?
35Refer to the exhibit. A container named 'db' is running on the host. An administrator runs `podman inspect db` and sees the above output snippet. What can be concluded about the container's network configuration?
Be able to run, inspect, and troubleshoot Podman containers on RHEL, especially rootless containers with bind mounts. The single most important thing: get SELinux labeling and host directory ownership right so the container can actually read and write mounted storage.
The Courseiva EX200 question bank contains 35 questions in the Manage containers domain, covering the 11% of the exam attributed to this domain in the official Red Hat blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Manage containers domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included