Exam integrity and accuracy: EX280 is a 100% hands-on performance exam based on OpenShift Container Platform 4.18. Duration: Verify official exam page. Red Hat does not publish objective percentages or a task count on the cited pages. Every practice item here is an original best-action or task-planning check, never a replica or recalled task.
Verified exam snapshot — August 21, 2026
The official page says EX280 tests the knowledge, skills, and ability to create, configure, and manage a cloud application platform. Red Hat lists RHCSA as strongly recommended but not required and recommends DO180 and DO280 or comparable experience. The credential page lists nine capability groups.
Non-official internal practice allocation — exactly 50
6 Manage OpenShift Container Platform
6 Work with resource manifests
6 Deploy applications
6 Manage authentication and authorization
6 Configure network security
5 Expose non-HTTP/SNI applications
5 Enable developer self-service
5 Manage OpenShift operators
5 Configure application security
This is not a Red Hat weighting. It is only PrepKloud's balanced allocation across Red Hat's public groups.
1
Platform, CLI, projects, and declarative resources
Weeks 1–2Start by making scope and evidence habitual. A performance-based exam rewards correct outcomes, but production-grade practice also requires knowing what changed and how to recover.
- Use explicit contexts and projects; inspect API resources, status, events, and logs
- Create projects with ownership, labels, ResourceQuota, LimitRange, and service accounts
- Author, validate, apply, patch, export, compare, and clean reusable YAML manifests
- Separate ConfigMaps from Secrets and eliminate server-generated fields from desired state
- Diagnose Pending, image-pull, restart, and quota failures from evidence
- Practice idempotent changes and verify both expected success and expected denial
2
Applications, images, Services, probes, and rollouts
Weeks 3–4Deploy applications as connected control loops rather than isolated objects.
- Create Deployments, Services, configuration, and image references with consistent labels
- Trace selector matching, ready endpoints, DNS, and application request paths
- Design startup, readiness, and liveness probes with distinct purposes
- Set requests and limits, scale inside quota, and investigate OOM and scheduling behavior
- Promote immutable image content, observe rollout history, inject a bad revision, and roll back
- Preserve prior logs and revision evidence before remediation
3
Authentication, authorization, and developer boundaries
Week 5Distinguish identity establishment from permission evaluation, then delegate narrowly.
- Configure or reason about OAuth identity providers, identity mapping, groups, and recovery access
- Create Roles, ClusterRoles, RoleBindings, and ClusterRoleBindings at the correct scope
- Test effective access using the intended user or service account
- Avoid wildcards, shared credentials, and unnecessary service-account token mounts
- Build self-service with Templates, clear parameters, secure Secret generation, quota, and admission
- Run complete self-service tests as a developer rather than only as administrator
4
Network security and external exposure
Week 6Convert observed traffic requirements into tested policy and choose exposure by protocol.
- Build source, destination, port, protocol, DNS, ingress, probe, and monitoring matrices
- Apply default-deny ingress and egress, then narrowly allow required paths
- Understand directional isolation and additive NetworkPolicy behavior
- Configure edge, re-encrypt, and passthrough Routes at appropriate TLS boundaries
- Use SNI correctly and avoid claiming HTTP path routing through passthrough encryption
- Evaluate LoadBalancer and NodePort Services for approved non-HTTP traffic
- Test public versus private reachability, certificates, source controls, health, and rollback
5
Operators, application security, and performance readiness
Weeks 7–8+Finish with controller lifecycle and constrained workloads, then practice complete operations under time pressure.
- Review Operator sources, channels, scopes, permissions, dependencies, approval, and support
- Trace Subscription, InstallPlan, CSV, CRD, custom resource, controller, and operand state
- Plan compatible updates, custom-resource migration, finalizers, and safe uninstall
- Run images with arbitrary non-root UIDs and avoid unnecessary SCC privilege
- Constrain capabilities, volumes, writable paths, Secrets, and workload API identity
- Complete all three projects including failure injection, recovery, cost, security, and cleanup
- Use the 50 checks to explain decisions, then repeat equivalent original lab tasks from a clean environment
- Read the current Red Hat program guide and official exam page immediately before scheduling
Three evidence-driven projects
OpenShift project baseline
Operate manifests, quota, images, probes, rollout, rollback, five failure classes, restricted execution, and teardown.
Open projectIdentity and network control plane
Build synthetic OAuth, least-privilege RBAC, segmentation, Routes, SNI, and private raw TCP exposure.
Open projectOperator-backed self-service
Govern OLM lifecycle, custom resources, templates, SCC, Secrets, upgrades, failures, and uninstall.
Open project
Use every learning surface
50 original EX280 checks
Two files of 25, four options, zero-based answer arrays, explanations, and official HTTPS references.40 unique flashcards
Recall architecture, objects, identity, network, Operators, and security.3 hands-on projects
Practice real administration outcomes in authorized disposable labs.Complete EX280 study guide
Read the objective groups, practical workflow, and readiness method.RHCSA roadmap
Strengthen the Linux administration foundation Red Hat recommends.Editorial policy
Review sourcing, originality, corrections, and independence.
Primary official references
EX280 exam pageVersion, audience, prerequisites, and public exam description.
Red Hat EX280 OpenShift 4.18 documentationCurrent administration, application, networking, security, and Operator guidance.
OpenShift 4.18 docs
Frequently asked questions
Is EX280 active and which OpenShift version does it use?
The official Red Hat exam page is active as of August 21, 2026 and states that EX280 is based on OpenShift Container Platform 4.18. Always recheck before purchase.
How long is EX280?
Verify official exam page. The cited public page does not publish a duration, so this roadmap does not supply one.
Is EX280 hands-on?
Yes. It is a performance-based examination. Practice complete administrative outcomes in authorized disposable environments, not proprietary or recalled tasks.
Does Red Hat publish EX280 weights?
The cited pages do not publish percentages. The exact 50-question allocation shown here is explicitly non-official internal practice allocation.
Is RHCSA required?
The official page strongly recommends RHCSA but says it is not required. It also recommends DO180 and DO280 or comparable OpenShift experience.
Are these real exam tasks?
No. The questions are independent original best-action and task-planning checks based on public groups and official documentation. No live, recalled, leaked, or proprietary task is used.
Independence disclaimer: Red Hat and OpenShift names belong to Red Hat. PrepKloud is independent and is not affiliated with or endorsed by Red Hat. This roadmap does not guarantee a pass, reproduce exam content, certify production readiness, or replace official training. Features, objectives, policies, and delivery terms change. Verify official sources, use authorized labs, protect credentials, and obtain production review.