20+ practice questions focused on Manage inventories and credentials — one of the most tested topics on the Red Hat Certified Engineer EX294 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Manage inventories and credentials PracticeAn administrator needs to store a secret API token in Ansible Automation Controller so that it can be used in job templates without exposing the token in plain text. Which type of credential should be used?
Explanation: A Vault credential in Ansible Automation Controller stores an encrypted password that can be used to decrypt Ansible Vault files. While originally designed for vault files, it can also be used to securely store any secret, such as an API token, by referencing it via the {{ vault_password }} variable in job templates. This ensures the token is never exposed in plain text. Machine credentials are for SSH authentication, Network credentials for network devices, and Cloud credentials for cloud provider APIs—none are suitable for storing arbitrary API tokens.
Which TWO of the following are valid methods to supply a credential password in Ansible Automation Controller?
Explanation: Option A is correct because Automation Controller supports the 'Prompt on launch' setting on credentials, which makes the job template ask the user for the credential password at job run time instead of storing it, and this is a documented way to supply a password. Option E is correct because a Vault credential in Automation Controller is used to supply the vault password (or vault password file) that decrypts vault-encrypted variables/content, which is a valid method for supplying a credential password to a job. Option B is not a supported mechanism: job templates do not have a setting to inject a credential password via an environment variable; environment variables in Automation Controller are used for other purposes and would not securely supply a credential password. Option C is not valid because storing a password in a file in the project repository exposes the secret in source control and is not a supported credential-supply method. Option D is not valid because Automation Controller encrypts credential inputs and does not support storing a credential password in plain text in the credential definition.
The job template running against host db1 uses a machine credential with an SSH key. The key is correctly configured in Automation Controller. However, the job fails with the error shown. What is the most likely cause?
Explanation: The error indicates that Automation Controller cannot authenticate to host db1 using the SSH key. Since the key is correctly configured in the controller, the most likely cause is that the corresponding public key is not present in the target host's ~/.ssh/authorized_keys file. SSH key-based authentication requires the private key on the client (controller) and the public key installed on the target host; without the public key, the server rejects the connection attempt.
A company uses Ansible Automation Controller to manage a mix of Linux and Windows servers. Each server is in a separate inventory group. The Linux servers use SSH keys stored in machine credentials, and the Windows servers use username/password stored in machine credentials. Recently, a new security policy requires that all credentials must be rotated every 90 days. The automation team has 50 Linux servers and 20 Windows servers. They want to minimize manual effort and avoid exposing secrets in plain text during rotation. They currently have a Jenkins pipeline that can run scripts on the controller node. Which approach best meets the requirements?
Explanation: It uses the Automation Controller API to programmatically update credential inputs (SSH keys or passwords) after rotating them on the target servers, which minimizes manual effort, avoids exposing secrets in plain text (the API call uses HTTPS and authentication tokens), and satisfies the 90-day rotation policy. The Jenkins pipeline can invoke a script that first rotates the secret on each server (e.g., via SSH or WinRM) and then calls the API's PATCH endpoint for the credential to update the stored value, ensuring the credential remains synchronized without manual UI intervention.
A system administrator is managing Ansible Tower and wants to use an Azure Resource Manager credential to provision virtual machines. However, the credential fails authentication with the error '401 Unauthorized'. Which action should the administrator take to resolve the issue?
Explanation: The 401 Unauthorized error when using an Azure Resource Manager credential in Ansible Tower indicates that the authentication token or secret used to authenticate with Microsoft Entra ID is invalid or mismatched. Option B is correct because verifying that the client secret stored in the Tower credential exactly matches the one configured in Microsoft Entra ID resolves the authentication failure, as Microsoft Entra ID uses OAuth 2.0 client credentials flow where the client secret is required for token acquisition.
+15 more Manage inventories and credentials questions available
Practice all Manage inventories and credentials questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Manage inventories and credentials. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Manage inventories and credentials questions on the EX294 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Manage inventories and credentials is tested as part of the Red Hat Certified Engineer EX294 blueprint. Practicing with targeted Manage inventories and credentials questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free EX294 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Manage inventories and credentials is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Manage inventories and credentials practice session with instant scoring and detailed explanations.
Start Manage inventories and credentials Practice →