Courseiva
Manage containers →easyMultiple Choice

EX200 Manage containers Practice Question

An administrator needs to pull a container image from a private registry at registry.example.com:5000. The registry requires authentication. Which command should be used first?

⚠ Common exam trap

Red Hat often tests the prerequisite step of authentication before interacting with a private registry, and the trap here is that candidates may jump directly to `podman pull` (option D) thinking it will prompt for credentials, but Podman does not prompt interactively in non-TTY environments and requires explicit prior login.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

podman login registry.example.com:5000

`podman login` authenticates the user to the specified private registry (registry.example.com:5000) before any pull or push operation. Without prior authentication, Podman cannot access the registry's content, and the pull command will fail with an authentication error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    podman login registry.example.com:5000

    Why this is correct

    Running 'podman login registry.example.com:5000' first authenticates you to the private registry, using the username and password you supply to create an entry in your local credentials store (typically $XDG_RUNTIME_DIR/containers/auth.json). This grants your user session permission to read image metadata and layers from that registry's namespace. Only after a successful login will a subsequent 'podman pull' be able to authenticate and retrieve the image. Therefore, this is the correct prerequisite step to enable the pull.

  • ✗

    podman tag registry.example.com:5000/myimage

    Why it's wrong here

    Though 'podman tag' can assign a new registry-qualified name to an existing image, it operates purely on images already present in your local container storage. It does not contact registry.example.com:5000, does not transmit credentials, and never downloads anything; if the source image tag does not exist locally, the command will simply return an error. Tagging is a local naming operation, not a method for acquiring a remote image.

  • ✗

    podman images

    Why it's wrong here

    'podman images' lists only the images currently stored in your local container engine's storage layer, such as those you've previously pulled or committed. It has no networking component and does not query any registry, so it provides no access to remote images. It is a diagnostic or inventory command, not an operation that can initiate or facilitate a registry pull.

  • ✗

    podman pull registry.example.com:5000/myimage

    Why it's wrong here

    Issuing 'podman pull registry.example.com:5000/myimage' attempts to fetch the image directly, but if you have not previously authenticated, the registry will reject the request with a 401 Unauthorized (or 403 Forbidden) before any layers are transferred. The pull command is the action you want to perform, but it presumes credentials are already in place. Without a preceding 'podman login', the pull fails against a private registry, so this command is not a valid first operation.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.