EX200 Manage containers Practice Question
A container fails to start because the port it needs is already in use. Which command can the administrator use to identify the process using the port?
⚠ Common exam trap
Many candidates think `podman port -l` or `podman logs` can diagnose host-level port conflicts, but these commands only show container-specific information and cannot identify processes outside the container namespace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ss -tlnp
The `ss -tlnp` command displays listening TCP sockets (`-t`), numeric addresses (`-n`), and the associated process information (`-p`). This allows the administrator to identify which process (PID and program name) is bound to a specific port, directly addressing the container startup failure caused by a port conflict.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
podman logs <container>
Why it's wrong here
podman logs <container> retrieves only the container's stdout/stderr history, which is generated by the application running inside the container. Although the application might print an error like 'address already in use', that message is not a definitive indicator of the host's port state. It also does not query the host kernel's socket table, so it cannot reveal which process is actually listening on the conflicting port.
- ✓
ss -tlnp
Why this is correct
ss -tlnp is correct because it directly interrogates the kernel's socket table for listening TCP endpoints. The -t option limits output to TCP, -l shows only listening sockets, -n displays numeric addresses and ports without DNS lookups, and -p appends the process ID and name that holds each socket. This lets you see exactly which host process has bound the port that the container needs, confirming the conflict at the OS level.
- ✗
podman port -l
Why it's wrong here
podman port -l shows the port forwarding mappings defined for the most recently created container, such as 8080->80, but it does not inspect the host's current network state. It only reports what ports the container is configured to map, not whether any other process is already listening on the host side. Therefore it cannot reveal that the target port is occupied by an unrelated process.
- ✗
firewall-cmd --list-ports
Why it's wrong here
firewall-cmd --list-ports lists the TCP and UDP ports explicitly allowed through the firewalld zone, which is a packet filtering policy, not a list of active listeners. A port can be open in the firewall yet completely unused, or it can be in use even when blocked by the firewall. To find a port conflict, you need to inspect running sockets, not firewall rules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.