Red Hat · Free Practice Questions · Last reviewed May 2026
48real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
13% of exam · 6 sample questions below
An organization wants to deploy Ansible Automation Platform 2.x in a highly available configuration. Which component must be deployed in an active-active cluster to ensure controller failover?
PostgreSQL database
Automation controller
Automation controller nodes form an active-active cluster behind a load balancer, so any node can accept and execute jobs; if one fails, the remaining nodes continue running playbooks without manual intervention. This satisfies the stem's controller failover requirement, since the control plane itself must be redundant rather than relying on a single instance.
Private Automation Hub
Automation mesh
Which TWO statements are true about deploying Red Hat Ansible Automation Platform using the automation mesh?
Execution nodes can be located in different geographic regions.
Execution nodes in an automation mesh can span distinct geographic regions, since the mesh replaces the single-hop SSH model with peer-to-peer overlay routing between nodes. This satisfies the stem's requirement for distributed, resilient deployment, allowing execution capacity to sit close to managed hosts across regions without a central hop.
Existing Ansible Tower nodes can be added to the mesh without modification.
Automation mesh requires two separate ports for control and data plane traffic.
The mesh topology is organized as a parent/child relationship between nodes.
Automation mesh arranges nodes hierarchically: control and hybrid nodes act as parents, while execution nodes are children that connect upstream to receive work. This parent/child structure lets execution capacity sit in remote networks while the control plane stays centralised, satisfying the stem's requirement for a true statement about mesh deployment topology.
All execution nodes must have direct network access to the automation controller.
A company is deploying Red Hat Ansible Automation Platform 2.3 in a hybrid cloud environment. The automation controller is installed on a RHEL 8 server in the on-premises data center. Execution nodes are distributed: four in the same data center, two in a remote branch office connected via VPN, and three in AWS EC2 instances. The VPN connection to the branch office is low-bandwidth and high-latency. The AWS nodes use a direct connect with stable bandwidth. During initial testing, playbooks running on the branch office execution nodes frequently timeout or hang, while on-premises and AWS nodes work fine. The automation mesh topology is configured with all nodes as direct children of the controller. The team wants to minimize latency and ensure reliable execution for the branch office nodes. Which course of action should the administrator take?
Deploy an additional automation mesh node in the branch office and make the branch office execution nodes children of that node.
Introducing an intermediate hop node in the branch office lets execution nodes connect over the low-latency LAN rather than the high-latency VPN, satisfying the requirement to minimise latency and prevent timeouts. Direct children of the controller force every job hop across the constrained VPN link.
Configure the controller to use the AWS execution nodes for all branch office jobs via a proxy.
Increase the `ansible_timeout` setting in the controller configuration to 120 seconds.
Reduce the forks value for branch office execution nodes to 1.
Which TWO statements are true regarding the deployment of Ansible Automation Platform in a highly available configuration?
The automation hub requires an external PostgreSQL database to store collections and execution environments.
Execution nodes must have direct network access to the automation controller database.
The automation controller requires a PostgreSQL database that must be configured with replication for high availability.
The automation controller persists its configuration, jobs and credentials in PostgreSQL, so a highly available deployment requires that database to be replicated across nodes; without database replication, a controller node failure would lose or block access to this shared state.
The automation controller can use an embedded SQLite database for production deployments.
The automation mesh component is used to provide resilient, fault-tolerant execution across multiple nodes.
Automation mesh replaces the legacy isolated node model, using hop nodes and receptor-based connections to route execution across nodes. This satisfies the fault-tolerant execution constraint, letting jobs continue on surviving nodes when one becomes unreachable.
Drag and drop the steps to configure a basic NFS server to export a directory in the correct order.
Install NFS packages, create directory, configure /etc/exports, start NFS service, verify export
This is the correct order because you must first install the software, then create the directory to be shared, configure the exports file, start the service to apply the configuration, and finally verify that the export is active.
Install NFS packages, create directory, start NFS service, configure /etc/exports, verify export
Create directory, install NFS packages, configure /etc/exports, start NFS service, verify export
Install NFS packages, configure /etc/exports, create directory, start NFS service, verify export
Match each Ansible module to its primary function.
yum: Manages packages using the yum package manager
Correct: The yum module is used for package management on RHEL/CentOS systems.
service: Manages services (start, stop, restart, enable)
Correct: The service module controls system services.
copy: Copies files from local to remote hosts
Correct: The copy module transfers files from the control node to managed hosts.
yum: Manages services (start, stop, restart, enable)
service: Manages packages using the yum package manager
copy: Copies files from remote to local hosts
Want more Deploy Ansible Automation Platform practice?
Practice this domain13% of exam · 6 sample questions below
A systems administrator needs to run a playbook that installs packages on a group of managed nodes. The playbook should run only on nodes that are part of the 'web_servers' group in the inventory. Which approach is best practice?
Set 'hosts: web_servers' in the play.
Setting `hosts: web_servers` scopes the play directly to the inventory group, so Ansible targets only those managed nodes and skips all others. This satisfies the constraint that execution must be limited to the 'web_servers' group, using Ansible's native group pattern matching rather than conditional logic or delegation.
Set 'hosts: all' and use '--limit web_servers' when running ansible-playbook.
Set 'hosts: localhost' and delegate tasks to web_servers.
Set 'hosts: all' and use a 'when' condition to check if the node is in the web_servers group.
A team is writing an Ansible role to configure a web server. They want to include default variables that can be easily overridden by playbook variables. Which directory and file should they use to define these variables?
vars/defaults.yml
defaults/main.yml
Placing variables in defaults/main.yml gives them the lowest precedence in Ansible's variable hierarchy, so playbook vars, host vars and role params all override them automatically. This satisfies the stem's requirement for easily overridden role defaults, unlike vars/main.yml, whose higher precedence resists such overrides.
default_vars/main.yml
vars/main.yml
Refer to the exhibit. The playbook uses the 'yum' module to install 'httpd' on a RHEL 8 system. Which of the following is the most likely cause of the failure?
The 'yum' module is deprecated for RHEL 8; must use 'dnf'.
The AppStream repository is not enabled on the target host.
On RHEL 8, httpd ships in the AppStream repository rather than BaseOS. If AppStream is disabled, the yum module cannot resolve the package and the task fails, so enabling that repository is the required fix.
The remote host does not have subscription-manager access.
The package name is misspelled; it should be 'apache2'.
An Ansible playbook needs to ensure a service is enabled and running on boot. Which combination of parameters should be used with the 'systemd' module?
enabled: yes, state: reloaded
enabled: yes, state: started
Setting enabled: yes registers the unit for start on boot, while state: started ensures it is running now. Together they satisfy both halves of the stem's requirement, unlike state alone or enabled alone, which leave one condition unmet.
enabled: yes, daemon_reload: yes
enabled: yes, state: restarted
Which best practice should be followed when using Ansible to manage task execution across multiple hosts?
Use 'ignore_errors: yes' on all tasks to prevent playbook failures.
Ensure tasks are idempotent so they can be run multiple times without changing the system state beyond the desired state.
Idempotence means repeated runs converge on the same desired state without side effects, which is essential when a play targets many hosts and some tasks may be retried or partially applied. It keeps multi-host execution predictable and safe.
Always use serial execution to avoid race conditions.
Write tasks that rely on the previous task's output to ensure correct order.
Which TWO statements about Ansible roles are correct?
Roles must follow a specific directory structure.
Ansible roles enforce a defined directory hierarchy — tasks, handlers, defaults, vars, files, templates and meta — so the role loader can locate content automatically. This structure satisfies the stem's requirement that roles follow a specific layout, since deviating from these conventional paths prevents Ansible from resolving tasks and variables correctly.
Roles can be shared via Ansible Galaxy.
Ansible Galaxy serves as the public repository for distributing and installing reusable roles, satisfying the requirement for sharing content across teams or projects. Roles packaged with the correct directory structure can be published and retrieved using the ansible-galaxy command, enabling standardised reuse rather than manual copying between control nodes.
Ansible Galaxy is a continuous integration tool for testing roles.
Role dependencies must be defined in a file named dependencies.yml.
Role names must have a .role extension.
Want more Manage task execution and roles practice?
Practice this domain12% of exam · 6 sample questions below
A playbook needs to set a fact 'total_memory' by summing the 'memory_mb' values from a list of servers. Which filter should be used?
{{ servers | map(attribute='memory_mb') | sum }}
The `map` filter extracts the `memory_mb` attribute from each server dictionary, producing a list of integers, which `sum` then totals into `total_memory`. This satisfies the stem's requirement to aggregate values across a list without a loop, using Jinja2 filters natively supported in Ansible playbooks.
{{ servers | map('memory_mb') | sum }}
{{ servers | sum }}
{{ servers | sum(attribute='memory_mb') }}
The playbook uses the community.general.parse_csv filter. Assuming the collection is installed, what is the type and structure of the 'parsed' variable?
A list of dictionaries: [{'name': 'Alice', 'age': '30'}, {'name': 'Bob', 'age': '25'}]
The community.general.parse_csv filter converts CSV text into a list of dictionaries, using the header row as keys and each subsequent row as values. Fields remain strings, so age appears as '30' rather than an integer, matching the structure shown.
A single string: 'Alice,30\nBob,25'
A list of strings: ['name,age', 'Alice,30', 'Bob,25']
A dictionary: {'Alice': '30', 'Bob': '25'}
A playbook uses the 'debug' module to print a variable 'my_var' but the output is 'VARIABLE IS UNDEFINED'. The variable is defined in group_vars/all.yml. Which filter could be used to provide a default value and avoid this error?
{{ my_var | mandatory }}
{{ my_var | default('fallback') }}
The default filter substitutes 'fallback' when my_var is undefined, preventing the undefined-variable error. It resolves the stem's problem because group_vars/all.yml evidently is not being loaded for this host, so the variable never reaches the template.
{{ my_var | ternary('yes', 'no') }}
{{ my_var | dflt('fallback') }}
Drag and drop the steps to set up a cron job that runs a script every day at 2 AM in the correct order.
Prepare script, test script, edit crontab, add entry with correct syntax, verify
This is the correct order because you first prepare the script, then test it manually to ensure it works, then edit the crontab, add the entry with the correct syntax for 2 AM daily, and finally verify that the cron job is active and will run.
Edit crontab, add entry, prepare script, test, verify
Prepare script, edit crontab, add entry, test, verify
Test script, prepare script, edit crontab, add entry, verify
A playbook uses `{{ my_var | default('fallback') }}`. What is the effect?
If `my_var` is defined but empty, the expression evaluates to 'fallback'.
If `my_var` is defined but equal to None, the expression evaluates to 'fallback'.
The filter raises an error because 'default' is not a valid filter.
If `my_var` is undefined, the expression evaluates to 'fallback'.
The Jinja2 default filter returns its argument only when the preceding variable is undefined; otherwise the variable's value passes through unchanged. So an undefined my_var yields 'fallback', while a defined my_var keeps its own value.
You have a list `my_list` containing `[0, 1, 2, '', 'hello']`. You want to extract the first truthy element that exists. Which chain achieves this?
`my_list | select('truthy') | first | default('')`
Correct; select truthy, then first, then default.
`my_list | list | first | default('')`
`my_list | select('string') | first | default('')`
`my_list | first | default('')`
Want more Transform data with filters and plugins practice?
Practice this domain12% of exam · 6 sample questions below
An administrator wants to reuse a set of tasks that configure a firewall across multiple playbooks. Which Ansible feature should be used to achieve this?
Create a role for firewall configuration.
Roles bundle tasks, handlers, defaults and templates into a reusable, structured unit that playbooks can invoke via the roles keyword or include_role. This satisfies the requirement to reuse firewall configuration tasks across multiple playbooks without duplication.
Add the tasks to the inventory file under a group.
Define the tasks in a vars file and include it.
Define the tasks as handlers and notify them.
A playbook uses the 'include_tasks' module to dynamically include tasks based on a variable. The playbook runs successfully on some hosts but fails on others with a 'template error' message. What is the most likely cause?
The included task file does not exist on the control node.
The variable used in the 'include_tasks' path has a Jinja2 template error.
A Jinja2 template error in the variable used to build the include_tasks path renders an invalid filename on some hosts, causing the failure. This satisfies the scenario where the same playbook succeeds elsewhere because that variable resolves cleanly.
The included task file has incorrect permissions.
The included tasks contain a syntax error.
An Ansible playbook is designed to run on a group of database servers. The administrator wants to ensure that a task runs only on the primary database server, which is defined in the inventory with a variable 'primary: true'. Which conditional should be used?
ignore_errors: yes
when: primary
Using `when: primary` evaluates the host variable directly as a boolean condition, so the task executes only where the inventory sets `primary: true`. This satisfies the stem's constraint of restricting execution to the primary database server, since Ansible treats the variable's truthiness as the conditional test without requiring an explicit comparison.
run_once: true
delegate_to: "{{ primary }}"
A playbook uses the 'block' and 'rescue' keywords to handle errors. The block contains three tasks. The first task fails. What happens next?
The rescue section runs and retries the failed task.
The rescue section runs immediately after the failure.
Ansible aborts the remaining tasks inside the block as soon as one fails, then transfers execution to the rescue section, which runs immediately. The rescue handles the error, allowing the playbook to continue rather than halting.
The playbook fails with an error message.
The remaining tasks in the block run, then the rescue section runs.
An administrator needs to securely pass a database password to a playbook without exposing it in logs or the command line. Which approach is the most secure?
Store the password in an Ansible Vault-encrypted variable file and include it.
Ansible Vault encrypts the variable file at rest with AES-256, so the password is decrypted only in memory during playbook execution and never appears in logs, process listings or command-line arguments. This satisfies the stem's requirement to avoid exposure in logs or on the command line.
Set the password in a variable and use 'no_log: true' on tasks that use it.
Store the password in a host_vars file with restricted file permissions.
Prompt for the password and pass it as an extra variable using -e.
An Ansible playbook includes a role that defines default variables in 'defaults/main.yml' and role variables in 'vars/main.yml'. A playbook sets the same variable in the play's 'vars' section. Which variable value takes precedence?
Role defaults
Inventory group vars
Role vars
Play vars
Play vars outrank both role defaults and role vars in Ansible's precedence order, sitting above role vars/main.yml and far above defaults/main.yml. Because the play explicitly sets the variable, that value overrides the role's defaults and vars, satisfying the stem's precedence question.
Want more Implement advanced Ansible automation practice?
Practice this domain13% of exam · 6 sample questions below
A team uses Ansible Automation Controller with multiple organizations. Each organization has its own set of machines that require different SSH keys. The administrator wants to ensure that users from one organization cannot use credentials from another organization. What is the best way to achieve this isolation?
Create credentials within each organization and assign organization-level access
Credentials scoped to an organisation are only visible to members of that organisation, so users cannot select or reference another organisation's SSH keys. This satisfies the stem's isolation constraint, since Ansible Automation Controller enforces credential ownership boundaries at the organisation level rather than through playbook logic or host grouping.
Store credentials in separate projects and restrict project access
Set 'Use' permission on credentials only for specific users
Place users in different teams and restrict credential access by team
An Ansible playbook uses the `ansible_password` variable to connect to a Windows host. The value is stored in an encrypted Ansible Vault file. Which credential type in Automation Controller would allow the vault password to be supplied at runtime?
Cloud credential
Machine credential
Vault credential
A Vault credential stores the Ansible Vault password separately from machine credentials, letting Automation Controller decrypt vault-encrypted variables such as ansible_password at runtime. It satisfies the requirement to supply the vault password without embedding it in the playbook.
Network credential
An administrator wants to create a custom credential type to store a third-party API key. The API key must be passed to the playbook as an environment variable `MY_API_KEY`. What is the correct Injector configuration in the custom credential type definition?
file: {MY_API_KEY: "{{ api_key }}"}
env: {"MY_API_KEY": api_key}
extra_vars: {MY_API_KEY: "{{ api_key }}"}
env: {MY_API_KEY: "{{ api_key }}"}
The env dictionary maps credential inputs to environment variables.
A junior admin is troubleshooting why a job template fails with 'Permission denied' when connecting to a target host. The job template uses a machine credential that appears correct. What is the first thing to check?
Verify the inventory contains the correct host IP
Check the credential's username and private key / password
A 'Permission denied' error during connection typically stems from an invalid credential, so verifying the username and private key or password is the first check. The credential may appear correct while containing a mismatched key or wrong user.
Check the vault credential used in the job template
Check the project sync status
Which THREE of the following are best practices for managing credentials in Ansible Automation Controller?
Avoid using external secret management systems; keep all secrets in Automation Controller
Share the same credential across multiple organizations for simplicity
Restrict credential 'Use' permissions to specific users or teams
This ensures only authorized users can use the credential.
Use custom credential types to store secrets for third-party APIs
Custom types allow secure injection of non-standard secrets.
Use Vault credentials to store and encrypt sensitive variables in playbooks
Vault credentials protect sensitive data at rest.
The inventory above is used in a job template in Automation Controller. The job template also has a machine credential assigned that specifies username 'root' and an SSH key. When the job runs against host web1, which username will Ansible use to connect?
admin (from inventory host variable)
Inventory host variables take precedence over the machine credential's username when Ansible resolves connection parameters for a host. The web1 host variable ansible_user set to admin therefore overrides root, satisfying the precedence rule demonstrated in the inventory.
The username set in the job template's 'extra variables'
The first defined username in the credential chain
root (from credential)
Want more Manage inventories and credentials practice?
Practice this domain13% of exam · 6 sample questions below
An operations team is designing a rolling update for a stateful application that requires quorum (minimum 3 out of 5 nodes online). They plan to use Ansible's serial keyword. Which serial value ensures the update proceeds without breaking quorum while still being efficient?
serial: 2
Serial 2 updates two nodes at a time, leaving three of five online, which preserves the quorum minimum throughout the rolling update. Larger values risk dropping below three; serial 1 is safe but slower, so 2 balances safety with efficiency.
serial: 1
serial: 3
serial: 5
Which TWO options are best practices for coordinating rolling updates with Ansible? (Choose exactly two.)
Set ignore_errors: yes to ensure the playbook continues even if some hosts fail.
Use the serial keyword to update hosts in batches.
The serial keyword partitions the play's host list into batches, so each batch completes before the next begins. This limits blast radius during rolling updates, satisfying the requirement to update hosts incrementally rather than all at once.
Use the default serial setting (all hosts) for simplicity.
Set max_fail_percentage to limit the number of failed hosts before aborting.
max_fail_percentage aborts a play once the proportion of failed hosts exceeds the threshold, preventing a faulty rollout from cascading across the whole inventory. It satisfies the requirement to halt rolling updates automatically when failures exceed acceptable limits.
Run all hosts in parallel to minimize total update time.
An Ansible Engineer is planning a rolling update for a web application deployed across 10 nodes. The playbook uses the 'delegate_to' directive to manage load balancer health checks. Which of the following best describes the recommended approach to minimize downtime?
Use 'serial: 1' and delegate load balancer disable/enable tasks to localhost, ensuring each node is taken out of rotation before updating.
Using `serial: 1` updates one node at a time, so the remaining nine keep serving traffic. Delegating the load balancer disable and enable tasks to localhost runs them once from the controller rather than on each managed node, satisfying the rolling-update constraint of removing a node from rotation before patching and restoring it afterwards.
Run the update playbook with 'serial: 10' to update all nodes at once, then run a separate playbook to update the load balancer.
Run the update on each node manually using 'ansible-playbook --limit' and skip load balancer management to save time.
Use 'strategy: free' to allow nodes to update independently without controlling the load balancer.
Which TWO of the following are best practices when coordinating rolling updates with Ansible?
Define a 'max_fail_percentage' to abort the update if too many hosts fail.
Setting `max_fail_percentage` halts the play once failed hosts exceed the threshold, preventing a faulty update from cascading across the remaining batch. This directly satisfies the stem's coordination requirement by bounding blast radius during rolling updates, rather than letting Ansible continue through every host regardless of accumulating failures.
Use the 'serial' keyword to update a subset of hosts at a time.
The serial keyword splits the host inventory into batches, so each batch completes before the next begins. This keeps most servers serving traffic while a small subset is updated, preserving availability during the rolling update.
Use 'strategy: free' to allow hosts to run tasks independently.
Use 'gather_facts: no' to speed up the playbook.
Set 'any_errors_fatal: true' to stop the update on the first failure.
An administrator needs to update a web application that runs as a Kubernetes Deployment with 5 replicas. The application is stateless, but the update must not cause any downtime. Which TWO strategies ensure zero-downtime rolling updates?
Omit the liveness probe from the pod spec.
Set strategy type to RollingUpdate with maxUnavailable=0 and maxSurge=1.
maxUnavailable=0 guarantees all five existing pods stay ready during the rollout, while maxSurge=1 allows one extra pod to be created first. New pods must pass readiness before old ones terminate, preserving continuous availability throughout the update.
Set maxUnavailable=1 and maxSurge=0.
Use the Recreate strategy.
Configure a readiness probe that checks the application's health endpoint.
A readiness probe gates traffic: Kubernetes only routes requests to a pod once the probe succeeds, and removes it from Service endpoints when it fails. During rolling updates this prevents sending traffic to pods still starting, which is essential for zero downtime.
Drag and drop the steps to configure a firewall rule using firewalld to allow HTTPS traffic in the correct order.
Step 1: Check the current default zone. Step 2: Add the HTTPS service permanently using --permanent. Step 3: Reload firewalld. Step 4: Verify the rule is active. Step 5: Test connectivity.
This is the correct order because you first identify the zone, make the change permanent, reload to apply, verify the change, and finally test that the service works.
Step 1: Add the HTTPS service without --permanent. Step 2: Reload firewalld. Step 3: Verify the rule. Step 4: Test connectivity.
Step 1: Add the HTTPS service with --permanent. Step 2: Verify the rule without reloading. Step 3: Reload firewalld. Step 4: Test connectivity.
Step 1: Reload firewalld. Step 2: Add the HTTPS service with --permanent. Step 3: Verify the rule. Step 4: Test connectivity.
Want more Coordinate rolling updates practice?
Practice this domain12% of exam · 6 sample questions below
An Ansible playbook uses 'become: yes' to install packages. The playbook works when run manually by the administrator but fails when run from automation controller with 'Missing sudo password'. The administrator has configured a machine credential with the SSH key and the 'Become password' field is blank. What is the most likely issue?
The machine credential does not include the become password.
With become enabled, Ansible escalates via sudo, which needs the privilege password when NOPASSWD is not configured. The blank Become password field in the machine credential leaves sudo without credentials, producing the 'Missing sudo password' error.
The become method is set to 'su' instead of 'sudo'.
The remote user is not in the sudoers file.
The SSH private key is not loaded into the automation controller.
A managed node is configured with an Ansible vault-encrypted variable file. When running a playbook that uses these variables, the user receives a 'decryption failed' error. Which two steps should the user take to resolve the issue?
Verify the file permissions are set to 600.
Check that the SSH private key has access to the managed node.
Make sure the vault password file contains the path to the vault file.
Ensure the vault ID matches the one used when encrypting the file.
Vault matches decryption to the vault ID recorded in the file's header. If the playbook supplies a different ID, or none, decryption fails even with the right password, so aligning the vault ID used at encryption with the one supplied at runtime resolves it.
Verify the correct vault password is being provided.
Decryption requires the exact password that encrypted the file. If the wrong password is supplied, or none at all, the vault payload cannot be decrypted, producing the 'decryption failed' error. Verifying the correct password is provided restores successful decryption.
Drag and drop the steps to configure a container using Podman with a custom Dockerfile in the correct order.
Create a Dockerfile, then build the image using podman build, then list images using podman images, then run the container using podman run, then verify the container is running using podman ps.
This is the correct order because you must first create the Dockerfile that defines the container, then build the image from it, list available images to confirm, run a container from the image, and finally verify the container is running.
Build the image using podman build, then create a Dockerfile, then run the container using podman run, then list images using podman images, then verify the container is running using podman ps.
Create a Dockerfile, then list images using podman images, then build the image using podman build, then run the container using podman run, then verify the container is running using podman ps.
Run the container using podman run, then create a Dockerfile, then build the image using podman build, then list images using podman images, then verify the container is running using podman ps.
An automation team wants to securely store SSH private keys for use in playbooks. Which Ansible feature should they use?
Ansible Collections
Ansible Vault
Ansible Vault encrypts sensitive files and variables at rest using AES-256, so SSH private keys can be stored in encrypted form and decrypted at runtime with the vault password. This satisfies the requirement for secure storage rather than plaintext in the repository.
Ansible Fact Cache
Ansible Galaxy
An organization uses Automation Controller with multiple teams. They want to ensure that team members can only launch job templates that are explicitly assigned to their team. Which configuration approach should be used?
Assign each team to an organization and set organization-level permissions
Set 'allow simultaneous' to false on job templates
Use an Identity Provider (IdP) to restrict access
Create roles and assign them at the job template level using team roles
Assigning team roles directly on each job template grants the team execute permission only for that template, satisfying the constraint that members launch solely explicitly assigned templates. Organisation-wide roles would over-grant access, so template-level role assignment is required.
A developer wants to encrypt a string in a playbook variable file. Which command should they use?
ansible-vault rekey
ansible-vault create
ansible-vault edit
ansible-vault encrypt_string
The ansible-vault encrypt_string subcommand encrypts a single string value inline, producing ciphertext suitable for embedding directly in a variable file. This satisfies the requirement to encrypt one string rather than an entire file, which encrypt would handle.
Want more Manage automation security and operations practice?
Practice this domain12% of exam · 6 sample questions below
An automation team is designing a content collection to distribute internal Ansible modules across the organization. The collection should be installed from a private Galaxy server. To minimize namespace conflicts and ensure discoverability, which naming convention should be used for the collection?
collection_name.namespace
namespace_collection_name
namespace-collection_name
namespace.collection_name
The namespace.collection_name format is mandatory for Galaxy-hosted collections, where the namespace scopes ownership and prevents conflicts between organisations. This satisfies the stem's requirement to minimise namespace conflicts and ensure discoverability on a private Galaxy server.
When building an execution environment with ansible-builder, a developer notices that the build process fails with an error about missing dependencies. The developer wants to ensure all required Python packages are installed in the execution environment. Which file should be used to specify additional Python packages?
meta/runtime.yml
galaxy.yml
bindep.txt
requirements.txt
Listing Python packages in requirements.txt lets ansible-builder install them into the execution environment image during the build, resolving the missing-dependency failure. The bindep.txt file handles system-level packages instead, so requirements.txt is the correct file for the Python dependencies the stem requires.
A system administrator wants to publish a custom Ansible collection to a private Automation Hub. What is the correct command to build the collection before publishing?
ansible-galaxy collection init mycollection
ansible-galaxy collection publish ./mycollection-1.0.0.tar.gz
ansible-galaxy collection install .
ansible-galaxy collection build
The ansible-galaxy collection build command packages the collection directory into a tarball artefact containing the galaxy.yml manifest, roles, plugins and modules. This tarball is the required input for ansible-galaxy collection publish, so building must precede uploading to the private Automation Hub.
A DevOps engineer is creating an execution environment for a team that needs both Ansible and the 'requests' Python library. The engineer creates an execution environment definition file (EE.yml) with the following content: --- version: 3 images: base_image: name: registry.redhat.io/ansible-automation-platform-22/ee-minimal-rhel8:latest options: package_manager_path: /usr/bin/microdnf dependencies: python: requirements.txt system: bindep.txt
What is missing from this definition to ensure the 'requests' library is installed?
The package_manager_path should be /usr/bin/yum.
The requirements.txt file must contain 'requests'.
The definition references requirements.txt under dependencies.python, so pip installs whatever that file lists. Because the file's contents are not shown, the 'requests' library is only guaranteed to be present if requirements.txt explicitly names it; otherwise nothing installs it.
The galaxy.yml file must be added to the dependencies section.
The base image should be ee-supported-rhel8 instead.
Which TWO statements about Ansible content collections are correct?
Collections can be installed only from Galaxy.
The collection name must be a single word without namespace.
Collections can be distributed via Automation Hub or Galaxy.
Collections are distributed as tarballs through Galaxy, Automation Hub, or private Galaxy servers, which is the standard distribution mechanism. This satisfies the statement's requirement, distinguishing collections from standalone roles shared via Git or Galaxy alone.
A collection can contain only roles and playbooks.
A collection must have a galaxy.yml file in its root directory.
galaxy.yml at the collection root defines metadata such as namespace, name, version and dependencies, and is required for building and publishing. This satisfies the statement's requirement, as Ansible Galaxy rejects collections lacking this manifest file.
Which THREE files are commonly used when building an execution environment with ansible-builder?
bindep.txt
bindep.txt lists system-level package dependencies, which ansible-builder installs into the execution environment's base image before Python requirements. This satisfies the stem's need for build-input files: bindep.txt supplies OS packages, complementing requirements.txt and ansible.cfg as the three commonly used files.
ansible.cfg
galaxy.yml
execution-environment.yml
The `execution-environment.yml` file defines the build specification: base image, dependencies, and collections. It satisfies the stem's requirement for files used when building an execution environment with `ansible-builder`, serving as the primary definition file that `ansible-builder build` consumes to construct the container image.
requirements.txt
The requirements.txt file lists Python dependencies installed into the execution environment image, satisfying the need to bundle libraries your playbooks or collections import. Ansible-builder reads it alongside execution-environment.yml and bindep.txt, ensuring runtime modules are present without manual pip installs inside containers.
Want more Create content collections and execution environments practice?
Practice this domainThe EX294 exam is performance-based — there are no multiple-choice questions. It is a hands-on lab exam completed within 240 minutes. You complete practical tasks in a live or simulated environment. Courseiva practice questions cover the underlying concepts.
Hands-on automation tasks using Ansible in a live RHEL environment.
The exam covers 8 domains: Deploy Ansible Automation Platform, Manage task execution and roles, Transform data with filters and plugins, Implement advanced Ansible automation, Manage inventories and credentials, Coordinate rolling updates, Manage automation security and operations, Create content collections and execution environments. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Red Hat EX294 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.