EX200 Manage containers Practice Question
Which THREE options to podman run can be used to publish container ports to the host? (Select exactly three.)
⚠ Common exam trap
Red Hat often tests the distinction between --expose (which does not publish ports) and -p/--publish (which does), and the fact that --port is not a valid podman option, causing candidates to confuse it with the correct --publish flag.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-p
(-p) is correct because it is the short form of --publish, which maps a container port to a host port. Option B (--publish) is the long form of -p and explicitly publishes container ports to the host. Option D (-P) is correct because it publishes all exposed container ports to random high-numbered ports on the host (typically in the range 32768-60999).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
-p
Why this is correct
The lowercase -p option is the short form of --publish and is the primary way to map a container port to a host port. It accepts the syntax -p hostPort:containerPort/protocol, such as -p 8080:80/tcp, and can be repeated to publish multiple ports. By default, it binds to all host interfaces (0.0.0.0) unless you prefix an IP address, making the container's service reachable from the host or external network.
- ✓
--publish
Why this is correct
The long-form --publish option performs the exact same port mapping as -p but offers greater readability in scripts and documentation. It supports the same syntax, including an optional bind address, for example --publish 127.0.0.1:8080:80. Because it is simply an alias for -p, it is a valid and correct way to publish a container port to the host in a podman run command.
- ✗
--expose
Why it's wrong here
The --expose option is incorrect because it does not map any port to the host. It only tells Podman that the container listens on a particular port, and that port is communicated to other containers on the same network or via a pod. No host-side port binding is created, so the exposed port is not reachable from the host or from the outside world unless you separately publish a port with -p or -P.
- ✓
-P
Why this is correct
The uppercase -P option publishes all ports that the container image declares through the EXPOSE instruction in its Dockerfile or Podmanfile. For each such port, Podman automatically assigns a random ephemeral host port, typically in the 49152–65535 range. This is a valid way to publish container ports, but it is unsuitable when you need a specific host port, because the chosen port is unpredictable and may change between container runs.
- ✗
--port
Why it's wrong here
The --port option is not a valid Podman run option. Podman's CLI for publishing ports is -p or --publish, while -P publishes every exposed port; there is no single --port flag. Attempting to use it results in an 'unknown flag: --port' error from Podman. Therefore, it cannot be used to publish container ports and is the wrong choice for this question.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.