EX200 · domain
Manage containers
The Manage containers domain of EX200 covers running and inspecting OCI containers with Podman on RHEL, including rootless operation, bind mounts, SELinux labeling, and persistent storage. Questions are task-oriented: you read command output or a scenario, then choose the podman command, flag, or conclusion that satisfies the stated requirement.
Focused practice
Practice Manage containers questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Manage containers
Be able to run, inspect, and troubleshoot Podman containers on RHEL, especially rootless containers with bind mounts. The single most important thing: get SELinux labeling and host directory ownership right so the container can actually read and write mounted storage.
Running rootless containers with podman run --user and mapping host UID/GID ownership
Bind-mounting host directories with -v and applying :Z or :z SELinux relabeling
Inspecting container network and storage config via podman inspect output fields
Managing persistent container data with named volumes and podman volume commands
Watch out for
Common Manage containers exam traps
- ▸Assuming a bind-mounted directory is writable without matching host ownership or SELinux labels, so the container fails despite correct --user settings.
- ▸Confusing :Z (private relabel) with :z (shared relabel), which breaks access when multiple containers use the same host path.
- ▸Treating podman inspect fields as runtime guarantees; misreading network or mount output and drawing wrong conclusions about the container.
Question index
All Manage containers questions (35)
Click any question to see the full explanation, or start a practice session above.
Based on the exhibit, which command should be used to start the container named 'mycontainer'?
Easy2A system administrator needs to ensure that data written to a container's `/var/lib/mysql` directory persists after the container is removed. Which TWO methods accomplish this requirement?
Hard3A container is running but cannot be accessed from the network. Which TWO commands could help diagnose the issue? (Select exactly two.)
Hard4A system administrator wants to run a container that uses the rootless mode available in Podman. Which requirement must be met for rootless containers to work correctly?
Easy5A team wants to run a container as a non-root user inside the container for security. Which instruction should be included in the Containerfile?
Medium6An administrator is building a container image with a Containerfile. They want to ensure that a specific RUN command always executes without using the build cache. Which build option should they use?
Hard7A container running a database service needs to persist data across restarts. The administrator decides to use a named volume. Which command creates a named volume and mounts it correctly?
Hard8A system administrator wants to run a container as a systemd service that restarts automatically after a system reboot. Which approach follows Red Hat best practices?
Hard9Put the steps to configure NFS server to export /nfsshare to a specific client in order.
Medium10Which THREE statements about container storage in podman are correct? (Choose THREE.)
Medium11Based on the exhibit, which statement about the container 'webserver' is true?
Medium12A system administrator needs to run a container that remains running in the background and executes a web server. Which podman command will correctly run the container detached and map host port 8080 to container port 80?
Medium13A container exits immediately with status 1. The administrator runs 'podman logs container' but sees no output. What is the most likely reason for the missing logs?
Hard14A container fails to start because the port it needs is already in use. Which command can the administrator use to identify the process using the port?
Easy15A container named 'web1' was created and ran briefly before exiting with status 0. The administrator needs to restart it and attach to the running container's console. Which command should be used?
Easy16Match each log file to its typical content.
Medium17Which THREE actions are required to enable a non-root user to run containers using Podman on Red Hat Enterprise Linux 8?
Hard18A company runs a critical web application in a container on a Red Hat Enterprise Linux 9 server. The container is started via a systemd service called 'webapp.service'. The service unit file was generated using 'podman generate systemd --new --name webapp'. Recently, after a kernel update and reboot, the service fails to start the container. The administrator runs 'systemctl status webapp.service' and sees 'Active: failed (Result: exit-code)' and 'Process: 1234 ExecStart=/usr/bin/podman run ... (code=exited, status=125)'. The administrator also checks 'journalctl -u webapp.service' and sees: 'Error: unable to start container: container create failed: OCI runtime error: container_linux.go:380: starting container process caused: exec: "/usr/bin/app.sh": stat /usr/bin/app.sh: no such file or directory'. The container image was built locally using a Containerfile that includes 'COPY app.sh /usr/bin/app.sh'. The administrator verifies the image is present locally. What should the administrator do to resolve this issue?
Hard19A developer is running Podman as a non-root user on a Red Hat Enterprise Linux 8 system. The developer successfully runs a container, but notices that after logging out of the SSH session, the container stops. The developer wants the container to continue running even after disconnecting from the SSH session. The container is a simple web server that listens on port 8080. The developer has already enabled lingering for the user account using 'loginctl enable-linger'. However, the container still stops upon logout. What additional step should the developer take to ensure the container persists after logout?
Easy20Which TWO options to podman run can be used to persist data outside the container? (Select exactly two.)
Easy21Which TWO statements are true regarding container images and containers in Podman?
Medium22A containerized application writes logs to stdout. The administrator wants to view only the last 50 lines of logs from a container named 'app1'. Which command accomplishes this?
Medium23An administrator wants to run a container with --user 1001:1001 to avoid running as root. After starting, the container cannot write to a bind-mounted directory owned by root. What is the best practice to allow write access?
Medium24Which TWO options correctly describe the use of 'podman exec'? (Choose TWO.)
Easy25An administrator needs to ensure that a container always runs with a specific SELinux context for security reasons. The container uses a volume mount from the host. Which command should be used to start the container?
Hard26Refer to the exhibit. A container named 'db' is running on the host. An administrator runs `podman inspect db` and sees the above output snippet. What can be concluded about the container's network configuration?
Easy27An administrator needs to pull a container image from a private registry at registry.example.com:5000. The registry requires authentication. Which command should be used first?
Easy28Which THREE options to podman run can be used to publish container ports to the host? (Select exactly three.)
Medium29A system administrator is troubleshooting a container that fails to start with the error: 'Error: cannot start container: listen tcp4 :80: bind: address already in use'. The container is intended to serve HTTP traffic on port 80. What is the most appropriate first step to resolve this issue?
Hard30An administrator needs to run a container with a bind mount of the host directory /data to /var/lib/data inside the container. The container image is web:latest. Which command correctly achieves this?
Easy31A database container crashes repeatedly. The administrator wants to see the last 10 lines of the container's logs before it exited. Which command should be used?
Hard32A user wants to run a container that will restart automatically unless explicitly stopped by the administrator. Which podman run option should be used?
Easy33Which file should be present in a directory to build a container image using 'podman build'?
Easy34A containerized web server needs to persist logs outside the container. Which podman run option allows the administrator to specify a bind mount with mount propagation options?
Medium35A container needs to share the host's network namespace for performance monitoring. Which podman run option achieves this?
HardOther domains
All EX200 exam domains
Frequently asked questions
- What does the Manage containers domain cover on the EX200 exam?
- Be able to run, inspect, and troubleshoot Podman containers on RHEL, especially rootless containers with bind mounts. The single most important thing: get SELinux labeling and host directory ownership right so the container can actually read and write mounted storage.
- How many questions are in this domain?
- This page lists all 35 Manage containers questions in the EX200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Manage containers questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.