COA Certified OpenStack Administrator Exam — Questions and Answers
Question 1: Which Cinder volume status indicates that a volume is attached to an instance and in active use?
- attaching
- in-use (Correct answer)
- available
- reserved
Correct answer: in-use
The 'in-use' status means the volume is currently attached to a running instance.
Question 2: What is the effect of setting 'net.ipv4.ip_forward=1' on a Neutron network node?
- Permits VXLAN UDP encapsulation
- Enables DHCP relay across subnets
- Allows the kernel to route packets between network interfaces, required for L3 NAT (Correct answer)
- Enables ARP proxy responses
Correct answer: Allows the kernel to route packets between network interfaces, required for L3 NAT
IP forwarding must be enabled in the kernel so the L3 agent can perform routing and SNAT between tenant and external networks.
Question 3: An instance is in 'ACTIVE' state but the user reports it is unreachable over SSH. The security group allows port 22. What should you check next?
- Restart the nova-network service
- Re-upload the SSH keypair to Glance
- Verify the Keystone service catalog
- Check iptables/nftables rules on the compute node for the instance's tap interface (Correct answer)
Correct answer: Check iptables/nftables rules on the compute node for the instance's tap interface
When security groups look correct, the next step is verifying that iptables rules on the compute node's tap interface correctly implement those security group rules.
Question 4: What is the primary consideration when designing system architecture?
- Scalability, reliability, and alignment with business requirements (Correct answer)
- Matching competitor architectures
- Minimizing the number of components
- Using the newest technology available
Correct answer: Scalability, reliability, and alignment with business requirements
System architecture must prioritize scalability, reliability, and alignment with business requirements to ensure long-term viability and value delivery.
Question 5: A Keystone domain administrator needs to create users only within their domain, not in other domains. Which built-in role should be assigned to them at the domain scope?
- admin (Correct answer)
- reader
- domain_admin
- member
Correct answer: admin
Assigning the 'admin' role scoped to a specific domain gives that user administrative rights only within that domain, not globally.
Question 6: What does the OpenStack Heat service use to describe infrastructure as code?
- JSON CloudFormation templates only
- Terraform HCL files
- HOT (Heat Orchestration Templates) (Correct answer)
- YAML-based Ansible playbooks
Correct answer: HOT (Heat Orchestration Templates)
Heat uses its own Heat Orchestration Template (HOT) format in YAML to describe cloud infrastructure as code.
Question 7: An administrator wants to update the quota for a specific project to allow 50 instances. Which command accomplishes this?
- nova quota-update --instances 50 <project-id>
- openstack limits set --instances 50 <project-id>
- openstack quota set --instances 50 <project-id> (Correct answer)
- openstack project set --instances 50 <project-id>
Correct answer: openstack quota set --instances 50 <project-id>
'openstack quota set --instances' updates the Nova instance count quota for the specified project using the Unified CLI.
Question 8: A Nova instance is stuck in 'ERROR' state after a failed build. What is the safest first step an administrator should take to investigate?
- openstack server rebuild <instance-id>
- openstack server reboot --hard <instance-id>
- openstack server show <instance-id> and check the 'fault' field (Correct answer)
- openstack server delete <instance-id> immediately
Correct answer: openstack server show <instance-id> and check the 'fault' field
'openstack server show' displays the 'fault' field containing the error message and code that caused the build failure.
Question 9: What is the purpose of the 'OS::Heat::AutoScalingGroup' resource?
- To create a group of identical resources that can scale in or out (Correct answer)
- To automatically resize Cinder volumes based on usage
- To balance load across multiple Heat stacks
- To auto-recover failed instances using Ceilometer alarms
Correct answer: To create a group of identical resources that can scale in or out
OS::Heat::AutoScalingGroup manages a collection of identical resources (typically servers) and works with scaling policies to add or remove members dynamically.
Question 10: Which Swift command uploads an object and sets a custom metadata header named 'X-Object-Meta-Project'?
- swift upload -H 'X-Object-Meta-Project: value' container object (Correct answer)
- swift stat --meta Project:value container object
- swift upload --meta Project:value container object
- swift post --meta Project:value container object
Correct answer: swift upload -H 'X-Object-Meta-Project: value' container object
The -H flag on swift upload passes raw HTTP headers, allowing custom X-Object-Meta-* metadata to be set at upload time.
Question 11: After resizing a Nova instance, the instance is in 'VERIFY_RESIZE' state. What command must the administrator run to finalize the resize?
- openstack server start <instance-id>
- openstack server confirm resize <instance-id> (Correct answer)
- openstack server resume <instance-id>
- openstack server reboot <instance-id>
Correct answer: openstack server confirm resize <instance-id>
'openstack server confirm resize' finalizes the resize, releases the old allocation, and transitions the instance to ACTIVE state.
Question 12: Which component in the Neutron architecture is responsible for implementing security group rules on compute nodes?
- DHCP agent
- OVS/iptables firewall driver on the compute node (Correct answer)
- Neutron server (neutron-server)
- L3 agent
Correct answer: OVS/iptables firewall driver on the compute node
Security group rules are enforced by the firewall driver (iptables or OVS-based) running on the compute node, not by central Neutron components.
Question 13: Why is post-implementation review important?
- It is only required by auditors
- It identifies lessons learned and confirms objectives were met (Correct answer)
- It is optional if the implementation was successful
- It delays the next project
Correct answer: It identifies lessons learned and confirms objectives were met
Post-implementation reviews confirm that objectives were met, identify areas for improvement, and capture lessons learned for future projects.
Question 14: How should configuration changes be tracked?
- Verbally between team members
- Through version control systems with documented change rationale (Correct answer)
- Only in emergency situations
- In personal notes
Correct answer: Through version control systems with documented change rationale
Version control with documented rationale provides an audit trail, enables rollbacks, and ensures team visibility into all configuration changes.
Question 15: What does the 'availability zone' concept in OpenStack Nova allow administrators to do?
- Control which users can create flavors
- Limit the number of floating IPs per project
- Group compute nodes into logical failure domains for workload placement (Correct answer)
- Restrict image formats available to tenants
Correct answer: Group compute nodes into logical failure domains for workload placement
Availability zones let administrators partition compute nodes into named groups representing failure domains so users can distribute workloads across them.
Question 16: Which OpenStack CLI command lists all available Heat template versions?
- openstack stack template list
- openstack orchestration version list
- openstack heat template-version-list
- openstack orchestration template version list (Correct answer)
Correct answer: openstack orchestration template version list
The 'openstack orchestration template version list' command displays all HOT and CFN template versions supported by the Heat service.
Question 17: In OpenStack's shared-nothing architecture, what is the primary communication mechanism between services?
- Direct database access
- Message queue (AMQP) (Correct answer)
- Shared NFS storage
- SSH tunnels
Correct answer: Message queue (AMQP)
OpenStack services communicate asynchronously via AMQP message queues (typically RabbitMQ), enabling a loosely coupled shared-nothing architecture.
Question 18: During a rolling upgrade of OpenStack services, which service must typically be upgraded first to maintain compatibility across mixed-version deployments?
- Nova compute
- Cinder
- Keystone (Correct answer)
- Horizon
Correct answer: Keystone
Keystone is upgraded first because all other services depend on it for authentication; a compatible Keystone must be in place before API services begin accepting tokens from a new version.
Question 19: When designing an OpenStack deployment for maximum resiliency, which of the following best describes the purpose of using multiple availability zones?
- To separate development and production workloads logically
- To isolate failure domains so a single hardware failure does not affect all instances (Correct answer)
- To enforce different billing rates for different tenant groups
- To reduce network latency between geographically distant users
Correct answer: To isolate failure domains so a single hardware failure does not affect all instances
Availability zones isolate failure domains — a power outage or hardware failure in one zone should not impact instances running in another zone.
Question 20: Which OpenStack component defines the compute flavors?
- Glance
- Swift
- Cinder
- Nova (Correct answer)
Correct answer: Nova
Nova, the compute service, is responsible for defining and managing flavors, which are pre-defined templates for virtual machine resource allocation. Flavors specify the amount of vCPUs, RAM, and root disk size an instance will receive, allowing users to choose appropriate compute capacities.
Question 21: In the context of OpenStack Keystone federation, what does Identity Provider (IdP) federation allow?
- Multiple Keystone services to share a single MySQL database
- Users from an external identity system to authenticate and receive OpenStack tokens (Correct answer)
- Nova to bypass Keystone for internal service-to-service calls
- Automatic replication of project quotas across multiple regions
Correct answer: Users from an external identity system to authenticate and receive OpenStack tokens
Federation allows users authenticated by an external IdP (e.g., SAML, OIDC) to receive mapped Keystone tokens without needing a local Keystone account.
Question 22: What is the role of the Neutron metadata agent?
- Proxies instance HTTP requests to the Nova metadata API (Correct answer)
- Provides DNS resolution for instance hostnames
- Assigns floating IPs to instances
- Manages DHCP leases for all subnets
Correct answer: Proxies instance HTTP requests to the Nova metadata API
The metadata agent forwards requests from instances to the Nova metadata service (169.254.169.254) through a secure proxy chain.
Question 23: What is the purpose of a floating IP in OpenStack?
- Enables external network access (Correct answer)
- Used only for DNS
- Configures VLAN tagging
- Provides internal routing
Correct answer: Enables external network access
A floating IP in OpenStack is a public IP address that can be dynamically associated with a virtual machine instance. It allows external traffic from the internet to reach the instance and enables the instance to initiate outbound connections to external networks, providing public accessibility.
Question 24: In Cinder, which command creates a volume from an existing bootable volume snapshot?
- cinder snapshot-create --volume <id>
- cinder upload-to-image --snapshot <id>
- cinder create --snapshot-id <id> (Correct answer)
- cinder extend --snapshot <id>
Correct answer: cinder create --snapshot-id <id>
cinder create --snapshot-id <id> provisions a new volume pre-populated with the snapshot's data.
Question 25: Which component is used to assign user roles in OpenStack?
- Neutron
- Keystone (Correct answer)
- Cinder
- Horizon
Correct answer: Keystone
Keystone is OpenStack's identity service, responsible for providing authentication and authorization for all OpenStack components. It manages users, projects (tenants), and roles, making it the central component for assigning and controlling user access and permissions within the cloud environment.
Question 26: A Glance image upload fails with an error indicating the image exceeds the allowed size. Which configuration parameter in glance-api.conf controls maximum image size?
- max_image_members
- image_size_cap (Correct answer)
- upload_limit_bytes
- max_upload_size
Correct answer: image_size_cap
The 'image_size_cap' parameter in glance-api.conf sets the maximum size in bytes for any single image upload.
Question 27: What is the primary role of Pacemaker/Corosync in an OpenStack HA controller deployment?
- Routing network packets between nodes
- Managing stateful service failover and virtual IP resources (Correct answer)
- Optimizing database queries
- Load balancing API requests
Correct answer: Managing stateful service failover and virtual IP resources
Pacemaker/Corosync manages cluster resources such as virtual IPs and stateful services, triggering automatic failover when a node fails.
Question 28: How can persistent storage be attached to an OpenStack instance?
- Assign floating IP
- Use Nova console
- Attach Glance image
- Attach Cinder volume (Correct answer)
Correct answer: Attach Cinder volume
Persistent storage in OpenStack is primarily provided by Cinder volumes. These block storage volumes can be created independently and then attached to a running instance, ensuring that data persists even if the instance is terminated or re-provisioned.
Question 29: Why is regular security training important for all staff?
- Employees are often the weakest link in security and training reduces human error (Correct answer)
- It replaces the need for technical security controls
- It is only required annually for compliance
- It is only needed for IT staff
Correct answer: Employees are often the weakest link in security and training reduces human error
Regular security training reduces human error, the most common cause of security breaches, by keeping all staff aware of current threats and proper procedures.
Question 30: Which storage service is used for object storage in OpenStack?
- Heat
- Nova
- Cinder
- Swift (Correct answer)
Correct answer: Swift
Swift is OpenStack's highly scalable, fault-tolerant object storage service, designed for storing large amounts of unstructured data. It provides a RESTful API for storing and retrieving objects, making it suitable for backups, archives, and static web content, distinct from block or file storage.
Question 31: In Aodh, which alarm type triggers when a Gnocchi metric crosses a defined threshold?
- composite
- loadbalancer_member_health
- event
- gnocchi_resources_threshold (Correct answer)
Correct answer: gnocchi_resources_threshold
The 'gnocchi_resources_threshold' alarm type in Aodh evaluates Gnocchi metric values against a threshold to trigger alarms.
Question 32: What is the purpose of verifying a fix after implementation?
- To close the support ticket faster
- To document the fix for billing purposes
- To confirm the solution resolved the issue without creating new problems (Correct answer)
- It is unnecessary if the fix seems to work
Correct answer: To confirm the solution resolved the issue without creating new problems
Verification confirms the solution actually resolved the issue and did not introduce new problems, ensuring complete and reliable problem resolution.
Question 33: When importing a large Glance image using the interoperable image import workflow, which task stage accepts the image data URI and downloads it into Glance staging?
- glance-direct import method
- image-conversion import method
- web-download import method (Correct answer)
- copy-image import method
Correct answer: web-download import method
The 'web-download' import method instructs Glance to download the image directly from a URI, useful for large images to avoid client-side transfers.
Question 34: Which OpenStack component provides container orchestration engine management as a service?
- Magnum (Correct answer)
- Zun
- Kuryr
- Fuxi
Correct answer: Magnum
Magnum is the OpenStack Containers-as-a-Service project that provisions and manages Kubernetes, Docker Swarm, and Mesos clusters.
Question 35: What is the first step in a systematic troubleshooting approach?
- Start replacing components randomly
- Restart everything and hope it resolves
- Escalate to management immediately
- Identify and clearly define the problem symptoms (Correct answer)
Correct answer: Identify and clearly define the problem symptoms
Clearly defining problem symptoms is the essential first step that guides all subsequent troubleshooting activities and prevents wasted effort on incorrect diagnoses.
Question 36: When configuring Neutron with the ML2 plugin, what is the role of a 'mechanism driver'?
- It validates CIDR ranges submitted in subnet creation requests
- It maps external router gateway IPs to floating IP addresses
- It implements the actual network plumbing on the underlying infrastructure (e.g., OVS, OVN, LinuxBridge) (Correct answer)
- It enforces quota limits on the number of ports per tenant
Correct answer: It implements the actual network plumbing on the underlying infrastructure (e.g., OVS, OVN, LinuxBridge)
ML2 mechanism drivers implement how virtual network constructs are realized on the physical or virtual infrastructure, such as configuring OVS flows or OVN logical switches.
Question 37: Which Swift feature allows clients to retrieve only a byte range of a stored object?
- Object chunking
- Segment manifest
- HTTP Range header support (Correct answer)
- Bulk retrieval
Correct answer: HTTP Range header support
Swift honors the standard HTTP Range header, returning the requested byte range from an object without downloading the full file.
Question 38: Which command correctly creates a Cinder volume from an existing snapshot?
- cinder create --snapshot-id <snapshot-id> myvol
- openstack volume snapshot restore <snapshot-id> --name myvol
- openstack volume create --snapshot <snapshot-id> --size 10 myvol (Correct answer)
- openstack volume create --from-snapshot <snapshot-id> myvol
Correct answer: openstack volume create --snapshot <snapshot-id> --size 10 myvol
The correct syntax is `openstack volume create --snapshot <snapshot-id> --size <size> <name>` to create a volume from a snapshot.
Question 39: Which Keystone endpoint type should be configured for internal service-to-service communication within the OpenStack control plane?
- internal (Correct answer)
- public
- private
- admin
Correct answer: internal
The 'internal' endpoint type is used for service-to-service API calls within the control network, separate from the public-facing endpoint.
Question 40: Which command lists all subnets associated with a specific Neutron network by its ID?
- neutron subnet-list --network-id <id>
- openstack subnet list --network <id>
- Both A and B are valid (Correct answer)
- openstack network show <id>
Correct answer: Both A and B are valid
Both 'openstack subnet list --network <id>' and 'openstack network show <id>' (which lists subnet IDs) reveal subnets for a given network.
Question 41: What does the 'admin' role in OpenStack grant by default, and why is it considered risky?
- Full administrative access across all services system-wide; risky because it bypasses project-level isolation (Correct answer)
- Read-only access to all services; risky because it exposes configuration data
- Access to Keystone only; risky because identity changes are irreversible
- Access to Nova only; risky because compute changes affect all users
Correct answer: Full administrative access across all services system-wide; risky because it bypasses project-level isolation
The admin role provides cross-project, system-wide privileges to all services, making it a high-value target for privilege escalation.
Question 42: In a Ceph-backed Glance + Cinder deployment, what optimization allows Cinder to create volumes from images without transferring data through the API host?
- Glance direct_url download
- Image volume cache
- Cinder image-to-volume pipeline
- Copy-on-write cloning via librbd (Correct answer)
Correct answer: Copy-on-write cloning via librbd
When both Glance and Cinder use the same Ceph pool, the Cinder RBD driver clones the image as a copy-on-write child volume instantly without data movement.
Question 43: In OpenStack Keystone, what is the difference between a 'domain' and a 'project'?
- Domains map to availability zones; projects map to host aggregates
- A domain is a top-level namespace for users and projects; a project is a resource allocation boundary within a domain (Correct answer)
- Domains group physical hosts; projects group virtual networks
- Projects are for admin users only; domains are for regular tenants
Correct answer: A domain is a top-level namespace for users and projects; a project is a resource allocation boundary within a domain
A Keystone domain is an administrative namespace containing users, groups, and projects, while a project (formerly tenant) is the resource quota and ownership boundary.
Question 44: When configuring Nova for SR-IOV networking, what must be enabled on the physical host?
- VT-d (IOMMU) in the BIOS and the sriov_numvfs setting on the NIC (Correct answer)
- Neutron L2 population driver for ARP suppression
- OVN southbound database with hardware offload rules
- Open vSwitch with VXLAN tunneling
Correct answer: VT-d (IOMMU) in the BIOS and the sriov_numvfs setting on the NIC
SR-IOV requires IOMMU (VT-d on Intel) enabled in BIOS and the number of Virtual Functions configured on the physical NIC via sriov_numvfs.
Question 45: Which Nova mechanism allows an administrator to group compute hosts so that instances can be constrained or spread across physically isolated fault domains?
- Server groups
- Availability zones (Correct answer)
- Placement groups
- Host aggregates
Correct answer: Availability zones
Availability zones are the user-facing abstraction of host aggregates, allowing tenants to select isolated fault domains when launching instances.
Question 46: What is the purpose of Keystone in OpenStack architecture?
- Object storage
- Image storage
- Networking
- Identity and authentication (Correct answer)
Correct answer: Identity and authentication
Keystone serves as the identity service for OpenStack, providing authentication and authorization for all OpenStack services. It manages users, tenants (projects), and roles, ensuring that only authorized users can access specific resources and services within the cloud.
Question 47: What is required before launching a new instance in OpenStack?
- A block storage volume
- Image, flavor, and network settings (Correct answer)
- Floating IPs and snapshots
- An SSH key only
Correct answer: Image, flavor, and network settings
To launch an OpenStack instance, you need an image (the operating system template), a flavor (defining compute resources like CPU, RAM, and disk size), and network settings (to connect the instance to a virtual network). These three elements are fundamental for defining and deploying a functional virtual machine.
Question 48: Which command displays all Neutron agents running in the deployment and their alive status?
- openstack network agent list (Correct answer)
- openstack agent show --all
- neutron agent-list
- neutron net-list --agents
Correct answer: openstack network agent list
openstack network agent list is the unified CLI command that shows all Neutron agents with their host, type, and alive flag.
Question 49: Which component provides a web-based user interface for OpenStack?
- Heat
- Swift
- Keystone
- Horizon (Correct answer)
Correct answer: Horizon
Horizon is the official web-based dashboard for OpenStack, providing a graphical user interface (GUI) for users and administrators. It allows for easy management of OpenStack resources such as instances, images, networks, and volumes through a web browser, simplifying cloud operations.
Question 50: Which Swift storage policy feature allows administrators to define different replica counts or erasure coding schemes per container?
- Object versioning
- Storage policies (Correct answer)
- Container ACLs
- Bulk delete
Correct answer: Storage policies
Storage policies let operators create named tiers with distinct replication or EC configurations, selectable per container at creation time.
Question 51: What Swift container ACL grants any authenticated user read access?
- .r:*,.rlistings
- *:* (Correct answer)
- .rlistings
- .r:*
Correct answer: *:*
The ACL value *:* grants read access to any authenticated OpenStack user across all projects.
Question 52: Which file must be modified on a Nova compute node to enable encrypted inter-instance communication using QEMU's built-in encryption?
- /etc/nova/nova.conf with libvirt encryption settings (Correct answer)
- nova.conf [libvirt] section with hw_machine_type
- /etc/neutron/neutron.conf
- /etc/qemu/qemu.conf with vnc_tls options
Correct answer: /etc/nova/nova.conf with libvirt encryption settings
Nova's nova.conf under the [libvirt] section contains settings to configure encrypted storage and communication options for QEMU/KVM instances.
Question 53: Which Cinder option configures the minimum free space percentage that must remain on a storage backend before it stops accepting new volumes?
- reserved_percentage (Correct answer)
- volume_clear
- lvm_type
- max_over_subscription_ratio
Correct answer: reserved_percentage
reserved_percentage tells Cinder to keep that fraction of backend capacity free and report it as unavailable for scheduling.
Question 54: A Nova flavor has vcpus=4, ram=8192, disk=20, and an extra spec 'aggregate_instance_extra_specs:ssd=true'. What does the extra spec control?
- It constrains instance placement to host aggregates tagged with ssd=true (Correct answer)
- It sets the swap space to SSD partition
- It enables faster network I/O for the instance
- It limits the flavor to SSD-backed ephemeral storage only
Correct answer: It constrains instance placement to host aggregates tagged with ssd=true
The 'aggregate_instance_extra_specs' prefix causes the Nova scheduler to match the flavor's extra specs against host aggregate metadata, restricting placement.
Question 55: A developer wants their application to authenticate against Keystone without using the user's password. Which Keystone feature should they use?
- Application credentials (Correct answer)
- EC2 credentials
- Trust delegation
- Federated identity
Correct answer: Application credentials
Application credentials allow applications to authenticate as a specific user without storing the user's password, with optional role and expiry restrictions.
Question 56: What architectural component allows OpenStack to support multiple hypervisor types (KVM, VMware, Hyper-V) simultaneously in the same deployment?
- A shared libvirt daemon that translates API calls to each hypervisor
- The Placement service enforcing hypervisor-specific resource classes
- Nova's virt driver abstraction layer, with separate compute hosts running each hypervisor type (Correct answer)
- The Ironic virt driver that abstracts bare-metal from VMs
Correct answer: Nova's virt driver abstraction layer, with separate compute hosts running each hypervisor type
Nova uses a pluggable virt driver per compute host; each host runs one driver type, allowing a single Nova deployment to manage heterogeneous hypervisor environments.
Question 57: What happens to resources in a project when that project is deleted in Keystone?
- Resources become orphaned and must be manually cleaned up per service (Correct answer)
- Resources are transferred to the default project
- Keystone blocks deletion if resources exist
- All resources are automatically deleted by each service
Correct answer: Resources become orphaned and must be manually cleaned up per service
Keystone does not cascade-delete resources; orphaned instances, volumes, and networks must be cleaned up individually in each service.
Question 58: What is the primary function of Keystone in OpenStack?
- Block storage
- Identity and access management (Correct answer)
- Image storage
- Network provisioning
Correct answer: Identity and access management
Keystone is the central identity service for OpenStack, handling authentication and authorization for all components. It manages users, projects (tenants), and roles, ensuring secure access control and single sign-on capabilities across the entire OpenStack deployment.
Question 59: An OpenStack administrator needs to allow a specific project to use GPU resources in a particular server group. Which Keystone construct should be used to grant this targeted access?
- Domain
- Role assignment on the project (Correct answer)
- Service endpoint
- Application credential
Correct answer: Role assignment on the project
Role assignments on a project grant users or groups specific permissions scoped to that project, allowing fine-grained access control.
Question 60: A user runs 'openstack server create' with --user-data pointing to a cloud-init script. Where does the running instance retrieve this user data by default?
- From a Swift object named user-data
- From a Glance image property
- From a Cinder volume attached at boot
- From the Nova metadata API at 169.254.169.254 (Correct answer)
Correct answer: From the Nova metadata API at 169.254.169.254
Instances retrieve user data and instance metadata from the Nova metadata API at the link-local address 169.254.169.254, which Nova proxies.
COA Certified OpenStack Administrator Exam
The Linux Foundation COA (Certified OpenStack Administrator) Exam tests hands-on skills in OpenStack architecture, identity and image management, compute operations, networking, storage configuration, and security access control.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds