Courseiva
Manage containers →hardMultiple Choice

EX200 Manage containers Practice Question

A container needs to share the host's network namespace for performance monitoring. Which podman run option achieves this?

⚠ Common exam trap

It's easy for candidates to confuse `--network host` with `--network bridge` (the default), assuming bridge mode provides host-level visibility, but bridge mode actually creates an isolated network namespace with NAT, hiding the host's interfaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--network host

`--network host` makes the container use the host's network stack directly, bypassing any network namespace isolation. This allows performance monitoring tools inside the container to see the host's actual network interfaces, IP addresses, and traffic without NAT or port mapping overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    --network slirp4netns

    Why it's wrong here

    --network slirp4netns is a user-space networking backend, commonly used with rootless Docker or Podman, that provides a network namespace with a virtual network through a SLIRP-based user-mode stack. It does not place the container in the host's network namespace; rather, it emulates a private network and translates traffic through the userland, which is slower but avoids needing root privileges. This is distinctly different from --network host, which uses the host's actual interfaces without any translation.

  • ✗

    --network bridge

    Why it's wrong here

    --network bridge is the default Docker networking mode, where the container gets its own network namespace with a unique IP address on a virtual bridge network (usually docker0). Traffic from the container is forwarded to the host via Network Address Translation (NAT) and veth pairs, so the container does not share the host's network namespace. This mode provides isolation but adds a small layer of abstraction and requires explicit port publishing for external access.

  • ✗

    --network none

    Why it's wrong here

    --network none disables all external networking for the container. The container is created with only a loopback interface and no routes to the outside world, meaning it cannot access the host network, other containers, or the internet. This isolation is useful for batch jobs or security-sensitive processes that require no network connectivity, but it does not share the host's network namespace.

  • ✓

    --network host

    Why this is correct

    --network host connects the container directly to the host's network namespace, so the container sees the same IP address, routing table, and network interfaces as the host. Any service listening in the container binds directly to the host's ports without requiring -p or --publish mappings. This eliminates the NAT and veth-pair overhead of bridge networking, but it also means the container has no network isolation from the host, which can be a security risk if untrusted workloads are run.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.