Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.
Start practicing
Manage inventories and credentials — choose a session length
Free · No account required
Domain overview
This domain covers Ansible inventory construction and credential handling for automation execution. On EX294 you build static and dynamic inventories, assign host and group variables, and configure credentials used by automation controller job templates. Questions test correct YAML structure for inventory files, plugin configuration, and credential-to-template association rather than memorized menu paths.
Exam objectives
Building static INI and YAML inventories with host groups, children, and group_vars directories
Configuring dynamic inventory plugins such as amazon.aws.aws_ec2 and community.general.proxmox with plugin YAML files
Defining group_vars and host_vars precedence for variables applied across inventory hosts
Associating machine, source control, and custom credential types with job templates in automation controller
Placing group_vars in the wrong directory level so variables are not picked up by the intended group or hosts
Forgetting to enable a dynamic inventory plugin in ansible.cfg or omitting the plugin key in its configuration file
Confusing credential types when a job template needs both machine and source control credentials attached separately
Click any question to see the full explanation and answer options, or start a focused practice session above.
A team uses Ansible Automation Controller with multiple organizations. Each organization has its own set of machines that require different SSH keys. The administrator wants to ensure that users from one organization cannot use credentials from another organization. What is the best way to achieve this isolation?
2An Ansible playbook uses the `ansible_password` variable to connect to a Windows host. The value is stored in an encrypted Ansible Vault file. Which credential type in Automation Controller would allow the vault password to be supplied at runtime?
3An administrator wants to create a custom credential type to store a third-party API key. The API key must be passed to the playbook as an environment variable `MY_API_KEY`. What is the correct Injector configuration in the custom credential type definition?
4A junior admin is troubleshooting why a job template fails with 'Permission denied' when connecting to a target host. The job template uses a machine credential that appears correct. What is the first thing to check?
5Which THREE of the following are best practices for managing credentials in Ansible Automation Controller?
6The inventory above is used in a job template in Automation Controller. The job template also has a machine credential assigned that specifies username 'root' and an SSH key. When the job runs against host web1, which username will Ansible use to connect?
7Which TWO statements about machine credentials in Ansible Tower are correct? (Choose two.)
8Refer to the exhibit. A user runs a playbook that creates hosts and then attempts to use a constructed inventory plugin. However, the constructed inventory does not group hosts by OS distribution. What is the most likely cause?
9A company manages its infrastructure using Ansible Tower. There are two teams: Team Alpha manages web servers in the 'webservers' group, and Team Beta manages database servers in the 'dbservers' group. Both teams need to use the same SSH credential to connect to their respective servers. The credential is stored in Tower as 'shared_ssh_key'. Team Alpha reports that they can launch jobs against the 'webservers' group, but Team Beta gets an error when trying to launch jobs against the 'dbservers' group: 'You do not have permission to use this credential.' Both teams are members of the same organization. The inventory is a single inventory source with separate groups. The credential has been assigned to the organization. What is the most likely cause of Team Beta's issue, and what is the correct solution?
10Drag and drop the steps to configure a systemd service to start automatically at boot in the correct order.
11Match each Linux file system path to its typical content.
12Match each storage concept to its description.
13A systems administrator needs to use a different SSH private key for a group of hosts in an Ansible inventory. Which inventory variable should be set at the group level?
14An Ansible administrator wants to use an encrypted vault file to store sensitive variables. Which command creates a new vault file and prompts for a password?
15A junior admin wants to remove a credential from Ansible Tower. Which role-based access control permission is required to delete a credential?
16An Ansible Tower administrator needs to create a custom credential type that uses an SSH private key and a username. Which THREE components should be defined in the credential type's configuration?
17Refer to the exhibit. A playbook includes this vars file and runs `systemctl restart httpd`. The playbook fails because it cannot decrypt the vault. Which of the following is the most likely cause?
18Ansible Tower is configured with a dynamic inventory source from VMware vCenter. The playbook needs to limit execution to hosts with a specific custom attribute. How should this be achieved?
19An organization uses multiple Satellite servers for inventory. They want to combine data from all satellites into one unified inventory in Ansible Tower. Which approach is best?
20Which THREE considerations are important when using dynamic inventories in Ansible Tower?
21A sysadmin receives an error when running a job template: 'ERROR! the role 'common' was not found in the specified roles path'. The role exists in a source control repository referenced in the project. What is the most likely cause?
22An administrator needs to provide a set of credentials to a job template that requires a machine credential for SSH and a source control credential for the project. What is the correct way to associate these credentials?
23An inventory is sourced from an external dynamic inventory plugin. The plugin returns hosts with groups including 'webservers' and 'dbservers'. An administrator wants to add a custom variable to all hosts in the 'webservers' group without modifying the plugin script. How can this be achieved?
24Which TWO statements about inventory groups in Ansible Automation Platform are correct? (Choose exactly two.)
25Which THREE considerations are important when designing a credential strategy in Ansible Automation Platform? (Choose exactly three.)
26A team uses a single Ansible Tower inventory called 'Production' containing hosts for multiple environments (dev, stage, prod). They want to apply different variables to hosts based on environment. Which inventory structure meets this requirement with minimal administrative overhead?
27Which THREE of the following are valid ways to define host variables in an Ansible inventory? (Choose exactly three.)
28An administrator manages a mixed fleet of Linux servers and Windows servers using Ansible Automation Platform. The Linux hosts are accessed via SSH keys, while the Windows hosts require WinRM with username and password. The administrator wants to define connection credentials in an inventory file so that playbooks can target both groups without specifying credentials in the playbook. Which inventory variable should be used to set the username for WinRM connections?
29An administrator maintains a project directory with an inventory file `inventory.ini` that contains a group `db_servers` with hosts `db1.example.com` and `db2.example.com`. The playbook `site.yml` must run only against these two hosts, but the inventory also contains other groups. The administrator wants to avoid modifying the inventory file and instead use a command-line option to limit execution to `db_servers`. Which command should be used?
30An administrator uses an inventory file with a group 'web' and a host 'web1' that also belongs to group 'db'. The group_vars/web.yml file sets 'http_port: 80', and group_vars/db.yml sets 'http_port: 3306'. The playbook uses 'http_port' to configure a service. What will be the value of http_port for web1 when the playbook runs?
31An administrator manages a static inventory file with a group `web` defined as children of `production`. The inventory also defines a group variable `http_port=80` at the `all` group level and `http_port=8080` at the `web` group level. A playbook targets `hosts: web` and uses `{{ http_port }}` in a template. Which value will be used for hosts in the `web` group?
32An administrator is running `ansible-playbook -i inventories/prod site.yml` against the `prod` inventory, which contains a group `web` and a group `db`. The play is defined with `hosts: web:&db`. Which hosts will the play target?
33An administrator needs to store sensitive credentials for a playbook that will be run from a control node. The credentials include an SSH password and a sudo password. The administrator wants to keep these encrypted at rest and avoid hardcoding them in the playbook. Which TWO methods are valid for providing these credentials securely? (Choose two.)
34An automation engineer manages two data centers with Ansible Automation Platform 2.4. The production inventory file is located at /etc/ansible/prod_inventory.ini and the staging inventory at /etc/ansible/stage_inventory.ini. The engineer wants to run a playbook against both inventories in a single ansible-playbook command, but the host groups must remain separate so that group_vars/prod and group_vars/stage apply correctly. Which command should the engineer use?
35A playbook run against a Windows host fails at the connection stage with an authentication error, although the inventory specifies `ansible_user: Administrator` and the correct password. Which inventory variable must be set so that Ansible uses the password-based WinRM connection instead of trying Kerberos or certificate authentication?
36An administrator maintains a static inventory file at /home/student/inventory that defines a group 'webservers' and a group 'dbservers'. A host named 'web1.example.com' must belong to both groups. Which INI snippet correctly assigns web1.example.com to both groups without creating duplicate host entries?
37A junior administrator needs to create an encrypted Ansible Vault password file for use with ansible-playbook. The vault password must be stored in a file named vault_pass.txt in the current directory. Which command should the administrator run?
38An administrator is creating a new inventory file for a small environment. The inventory must define a group `app` containing hosts `app1` and `app2`, and a group `db` containing host `db1`. The administrator wants to use the INI format. Which inventory file content correctly defines these groups?
39You provision a new RHEL 9 control node and create a project directory at /home/devops/ansible. While testing connectivity with `ansible all -m ping`, every host returns UNREACHABLE, yet `ssh` from the shell to those same hosts works without a password. The inventory file at /home/devops/ansible/inventory defines the group `web` with `web1 ansible_host=10.20.30.41`. Which action most directly resolves the failure?
40You run 'ansible-playbook -i inventory site.yml' and notice that a host defined in the inventory file is not targeted by a play with 'hosts: all'. The inventory file contains a group named 'ungrouped' with several hosts and a group named 'all_servers' with the same hosts. Which command most directly reveals whether Ansible is parsing the intended inventory source and listing that host under the expected groups?
41An administrator maintains a dynamic inventory script that outputs JSON. The script is placed at `/etc/ansible/inventory/aws_inventory.py` and is executable. The administrator runs `ansible-playbook -i /etc/ansible/inventory/aws_inventory.py site.yml` but receives an error: "Unable to parse /etc/ansible/inventory/aws_inventory.py as an inventory source". Which action is most likely to resolve the issue?
42Your team stores two inventories: a static file at inventories/prod and a dynamic inventory plugin configuration at inventories/aws_ec2.yml. The static file defines the group `db` with `db1 ansible_host=172.16.5.10`, while the plugin also returns a host named db1 with the address 172.16.5.99. You run `ansible-inventory -i inventories/prod -i inventories/aws_ec2.yml --host db1`. Which host variable value does Ansible report for ansible_host?
43A playbook must connect to hosts using a non-default SSH private key stored at /home/student/.ssh/prod_key and a non-default remote user 'deploy'. The inventory file should apply these settings to all hosts in the 'production' group without editing the playbook. Which inventory variable combination is correct?
44You must store a database password that a playbook will use on managed nodes. Your security policy forbids clear-text secrets in the repository and requires that the secret remain usable with `ansible-playbook --vault-password-file /home/devops/.vault_pass`. Which two actions satisfy the policy? (Choose two.)
45A playbook must run only against hosts that belong to both the `webservers` group and the `production` group. Your inventory defines these as separate groups, and a host named web3 is a member of both. Which inventory pattern restricts the play's hosts to exactly that intersection?
46An administrator creates a group named `webservers` in an INI-style inventory and a group named `webservers` in a YAML inventory under the same inventory directory. Both groups define different hosts. What is the result when Ansible loads the inventory?
47An administrator needs to connect to a set of servers that use different SSH users: 'admin' for the 'web' group and 'deploy' for the 'db' group. The inventory file contains these groups. The administrator wants to avoid specifying the user in the playbook and wants the correct user to be used automatically for each group. Which method should be used?
48Your inventory directory `inventory/prod` contains a static hosts file plus a group_vars subdirectory with webservers.yml. A dynamic inventory plugin in the same directory returns the group `webservers` with a host-level variable `http_port` set to 8080. The static group_vars/webservers.yml sets `http_port: 80`. When a play runs against the webservers group, which value does the managed host receive for http_port?
49An administrator is using ansible-playbook with an inventory file that defines a group 'webservers' and a group 'dbservers'. The administrator wants to run a playbook only against hosts in 'webservers' but exclude any host that is also in 'dbservers'. Which inventory pattern should be used with the --limit option?
50An administrator needs to encrypt a sensitive variable file 'secrets.yml' using Ansible Vault so that it can be safely stored in a Git repository. The file should remain encrypted at rest but be automatically decrypted during playbook runs when the vault password is supplied. Which command correctly creates the encrypted file?
51An administrator is using Ansible Vault to protect sensitive variables in an inventory project. The project has a vault-encrypted file 'secrets.yml' that contains the variable 'db_password'. The playbook needs to use this variable. Which TWO statements are correct about using vault-encrypted variables in this scenario? (Choose two.)
52A Red Hat Certified Engineer is managing an Ansible inventory that includes a mix of Linux and network devices. The network devices are running Cisco IOS and require the network_cli connection plugin. The engineer needs to specify the username and password for these devices in the inventory. Which inventory variables should be used to provide the credentials for the network devices?
Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.
The Courseiva EX294 question bank contains 52 questions in the Manage inventories and credentials domain, covering the 13% of the exam attributed to this domain in the official Red Hat blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Manage inventories and credentials domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included