HomeRoadmaps › EX280
Active Red Hat performance certification

Red Hat Certified System Administrator in OpenShift EX280 Roadmap

Build practical OpenShift 4.18 administration skill across projects, manifests, deployments, identity, network security, non-HTTP exposure, self-service, Operators, and application security—without dumps, recalled tasks, or invented exam details.

5 phases9 public objective groups50 original checks40 flashcards3 deep projects
Exam integrity and accuracy: EX280 is a 100% hands-on performance exam based on OpenShift Container Platform 4.18. Duration: Verify official exam page. Red Hat does not publish objective percentages or a task count on the cited pages. Every practice item here is an original best-action or task-planning check, never a replica or recalled task.

Verified exam snapshot — August 21, 2026

The official page says EX280 tests the knowledge, skills, and ability to create, configure, and manage a cloud application platform. Red Hat lists RHCSA as strongly recommended but not required and recommends DO180 and DO280 or comparable experience. The credential page lists nine capability groups.

Non-official internal practice allocation — exactly 50

6 Manage OpenShift Container Platform
6 Work with resource manifests
6 Deploy applications
6 Manage authentication and authorization
6 Configure network security
5 Expose non-HTTP/SNI applications
5 Enable developer self-service
5 Manage OpenShift operators
5 Configure application security

This is not a Red Hat weighting. It is only PrepKloud's balanced allocation across Red Hat's public groups.

1

Platform, CLI, projects, and declarative resources

Weeks 1–2

Start by making scope and evidence habitual. A performance-based exam rewards correct outcomes, but production-grade practice also requires knowing what changed and how to recover.

  • Use explicit contexts and projects; inspect API resources, status, events, and logs
  • Create projects with ownership, labels, ResourceQuota, LimitRange, and service accounts
  • Author, validate, apply, patch, export, compare, and clean reusable YAML manifests
  • Separate ConfigMaps from Secrets and eliminate server-generated fields from desired state
  • Diagnose Pending, image-pull, restart, and quota failures from evidence
  • Practice idempotent changes and verify both expected success and expected denial
2

Applications, images, Services, probes, and rollouts

Weeks 3–4

Deploy applications as connected control loops rather than isolated objects.

  • Create Deployments, Services, configuration, and image references with consistent labels
  • Trace selector matching, ready endpoints, DNS, and application request paths
  • Design startup, readiness, and liveness probes with distinct purposes
  • Set requests and limits, scale inside quota, and investigate OOM and scheduling behavior
  • Promote immutable image content, observe rollout history, inject a bad revision, and roll back
  • Preserve prior logs and revision evidence before remediation
3

Authentication, authorization, and developer boundaries

Week 5

Distinguish identity establishment from permission evaluation, then delegate narrowly.

  • Configure or reason about OAuth identity providers, identity mapping, groups, and recovery access
  • Create Roles, ClusterRoles, RoleBindings, and ClusterRoleBindings at the correct scope
  • Test effective access using the intended user or service account
  • Avoid wildcards, shared credentials, and unnecessary service-account token mounts
  • Build self-service with Templates, clear parameters, secure Secret generation, quota, and admission
  • Run complete self-service tests as a developer rather than only as administrator
4

Network security and external exposure

Week 6

Convert observed traffic requirements into tested policy and choose exposure by protocol.

  • Build source, destination, port, protocol, DNS, ingress, probe, and monitoring matrices
  • Apply default-deny ingress and egress, then narrowly allow required paths
  • Understand directional isolation and additive NetworkPolicy behavior
  • Configure edge, re-encrypt, and passthrough Routes at appropriate TLS boundaries
  • Use SNI correctly and avoid claiming HTTP path routing through passthrough encryption
  • Evaluate LoadBalancer and NodePort Services for approved non-HTTP traffic
  • Test public versus private reachability, certificates, source controls, health, and rollback
5

Operators, application security, and performance readiness

Weeks 7–8+

Finish with controller lifecycle and constrained workloads, then practice complete operations under time pressure.

  • Review Operator sources, channels, scopes, permissions, dependencies, approval, and support
  • Trace Subscription, InstallPlan, CSV, CRD, custom resource, controller, and operand state
  • Plan compatible updates, custom-resource migration, finalizers, and safe uninstall
  • Run images with arbitrary non-root UIDs and avoid unnecessary SCC privilege
  • Constrain capabilities, volumes, writable paths, Secrets, and workload API identity
  • Complete all three projects including failure injection, recovery, cost, security, and cleanup
  • Use the 50 checks to explain decisions, then repeat equivalent original lab tasks from a clean environment
  • Read the current Red Hat program guide and official exam page immediately before scheduling

Three evidence-driven projects

OpenShift project baseline

Operate manifests, quota, images, probes, rollout, rollback, five failure classes, restricted execution, and teardown.

Open project

Identity and network control plane

Build synthetic OAuth, least-privilege RBAC, segmentation, Routes, SNI, and private raw TCP exposure.

Open project

Operator-backed self-service

Govern OLM lifecycle, custom resources, templates, SCC, Secrets, upgrades, failures, and uninstall.

Open project

Use every learning surface

Primary official references

EX280 exam page

Version, audience, prerequisites, and public exam description.

Red Hat EX280
Credential page

Certification outcome and nine public capability groups.

Red Hat certification
OpenShift 4.18 documentation

Current administration, application, networking, security, and Operator guidance.

OpenShift 4.18 docs

Frequently asked questions

Is EX280 active and which OpenShift version does it use?

The official Red Hat exam page is active as of August 21, 2026 and states that EX280 is based on OpenShift Container Platform 4.18. Always recheck before purchase.

How long is EX280?

Verify official exam page. The cited public page does not publish a duration, so this roadmap does not supply one.

Is EX280 hands-on?

Yes. It is a performance-based examination. Practice complete administrative outcomes in authorized disposable environments, not proprietary or recalled tasks.

Does Red Hat publish EX280 weights?

The cited pages do not publish percentages. The exact 50-question allocation shown here is explicitly non-official internal practice allocation.

Is RHCSA required?

The official page strongly recommends RHCSA but says it is not required. It also recommends DO180 and DO280 or comparable OpenShift experience.

Are these real exam tasks?

No. The questions are independent original best-action and task-planning checks based on public groups and official documentation. No live, recalled, leaked, or proprietary task is used.

Independence disclaimer: Red Hat and OpenShift names belong to Red Hat. PrepKloud is independent and is not affiliated with or endorsed by Red Hat. This roadmap does not guarantee a pass, reproduce exam content, certify production readiness, or replace official training. Features, objectives, policies, and delivery terms change. Verify official sources, use authorized labs, protect credentials, and obtain production review.

Build repeatable OpenShift administration skill

Move from public objectives to observed outcomes, denied paths, recovery evidence, and clean teardown.

Start practice checksReview flashcardsBuild projects