Courseiva
Automation →hardMultiple Choice

CCNP Automation Practice Question

A network team uses Ansible to automate VLAN configuration on Cisco IOS devices. The playbook fails with the error 'Failed to connect to the host via ssh: Permission denied (publickey)'. The control node runs Ubuntu, and the network devices are configured with SSH key authentication. Which solution should the engineer implement?

⚠ Common exam trap

Cisco often tests the misconception that setting inventory variables like ansible_ssh_private_key_file or ansible_user alone fixes SSH key issues, when the real problem is that the key is not loaded into the SSH agent on the control node.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run ssh-add on the control node to add the private key to the SSH agent

The error 'Permission denied (publickey)' indicates that the SSH key is not being presented to the IOS device. Running ssh-add on the control node loads the private key into the SSH agent, which Ansible uses by default when connecting via SSH. This resolves the authentication failure without requiring a passphrase or changing the inventory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set ansible_ssh_private_key_file in the inventory but omit the passphrase

    Why it's wrong here

    Setting ansible_ssh_private_key_file in the inventory tells Ansible which private key file to use for SSH connections, but it does not unlock that key. If the key is encrypted with a passphrase, Ansible cannot read it without the passphrase, and simply omitting the passphrase from the inventory or command line will not bypass that requirement. The key must be decrypted and loaded into the SSH agent, which is exactly what ssh-add accomplishes; otherwise, the SSH connection will fail with a 'Permission denied' error, even though the key file path is correct.

  • ✗

    Set ansible_user to the correct username in the inventory

    Why it's wrong here

    Configuring ansible_user to the correct username in the inventory is necessary for any SSH connection, but it only defines the SSH login identity, not the authentication mechanism. A username alone cannot authenticate to a device that requires a specific private key, especially one protected by a passphrase. Ansible still needs an available, decrypted key, either via the SSH agent or an explicit passphrase, so this setting alone does not solve the passphrase issue or load the key into the agent.

  • ✓

    Run ssh-add on the control node to add the private key to the SSH agent

    Why this is correct

    Running ssh-add on the control node is the correct solution because it loads the passphrase-protected private key into the running SSH agent, where its decrypted form is retained for the duration of the agent session. Once the key is in the agent, Ansible's SSH connections can use it transparently without prompting for the passphrase, since the agent responds to authentication requests. This directly addresses the root cause: the key must be pre-authenticated to the SSH agent before Ansible attempts to connect, and ssh-add is the standard way to do that in an automated, non-interactive workflow.

  • ✗

    Enable keyboard-interactive authentication on the IOS devices

    Why it's wrong here

    Enabling keyboard-interactive authentication on the IOS devices would allow interactive password or challenge-response authentication, but it is unrelated to SSH key authentication. The problem here is a passphrase-protected private key, not a password prompt needing a keyboard-interactive exchange. IOS devices would still require the key to be presented, and keyboard-interactive would not make Ansible supply the passphrase, so this option fails to address the key-loading requirement and could even introduce an unintended security weakness by enabling interactive login methods.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.