EX294 Deploy Ansible Automation Platform Practice Question
A company is deploying Ansible Automation Platform (AAP) in a three-node cluster: one automation controller node, one private automation hub node, and one database node (PostgreSQL). The deployment uses an execution environment that pulls from the private automation hub. After a successful installation, all nodes are reachable and services are running. However, when launching a job template that uses the execution environment, the job fails with the error: 'Unable to pull execution environment image from automation-hub.example.com:5000/ee/my-ee:latest - request to registry failed with status 403 Forbidden'. The administrator confirms that the execution environment image exists in the private automation hub and that the automation controller node can reach the registry via curl. What is the most likely cause and solution?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a container registry credential in automation controller that uses the pull token from private automation hub, and associate it with the execution environment.
The 403 Forbidden error indicates that the automation controller cannot authenticate to the private automation hub container registry. Even though the image exists and network connectivity works, the controller needs a container registry credential configured with the pull token from the private automation hub. This credential must be associated with the execution environment. Option A is wrong because disabling authentication compromises security and is not the intended solution. Option B is wrong because SELinux would produce a different error (e.g., permission denied), not a 403. Option D is wrong because the 'pull' field does not affect authentication; the error is about authentication, not pull policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The private automation hub is configured to allow unauthenticated access; change the hub configuration to disable authentication.
Why it's wrong here
A 403 means the registry rejected the request as unauthorised, so disabling authentication would remove the credential check rather than satisfy it; the controller needs valid registry credentials configured. Anonymous pull is tempting for a fully public registry, but a private automation hub requires authentication for image pulls.
- ✗
SELinux on the controller node is blocking container pulls; temporarily set SELinux to permissive.
Why it's wrong here
SELinux denials produce permission errors or AVC messages, not an HTTP 403 returned by the registry itself; the registry answered, so the block is authorisation. Permissive mode is tempting when diagnosing container runtime denials, but here the controller must authenticate to the private automation hub.
- ✓
Create a container registry credential in automation controller that uses the pull token from private automation hub, and associate it with the execution environment.
Why this is correct
The 403 Forbidden comes from the registry rejecting an unauthenticated pull, not from network reachability. Automation controller needs a container registry credential holding the private automation hub pull token, associated with the execution environment, so it can authenticate.
- ✗
The execution environment definition in the controller is missing the 'pull' field; add 'pull: always' to the job template.
Why it's wrong here
A 403 from the registry indicates authentication or authorisation failure, so the controller needs valid registry credentials configured for the execution environment; the pull field only controls image-fetch behaviour. It is tempting because pull policy does govern image retrieval, but it cannot resolve a permissions rejection.
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.