EX294 Manage inventories and credentials Practice Question
A company manages its infrastructure using Ansible Tower. There are two teams: Team Alpha manages web servers in the 'webservers' group, and Team Beta manages database servers in the 'dbservers' group. Both teams need to use the same SSH credential to connect to their respective servers. The credential is stored in Tower as 'shared_ssh_key'. Team Alpha reports that they can launch jobs against the 'webservers' group, but Team Beta gets an error when trying to launch jobs against the 'dbservers' group: 'You do not have permission to use this credential.' Both teams are members of the same organization. The inventory is a single inventory source with separate groups. The credential has been assigned to the organization. What is the most likely cause of Team Beta's issue, and what is the correct solution?
⚠ Common exam trap
Test-takers frequently assume assigning a credential to an organization automatically grants all members the right to use it, but Tower requires explicit 'Use' role assignment for each team or user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant Team Beta the 'Use' role on the credential 'shared_ssh_key'.
In Ansible Tower, credentials are assigned to an organization, but users or teams must be explicitly granted the 'Use' role on a credential to be able to use it in a job template. Team Alpha can use the credential because they likely have the 'Use' role, while Team Beta does not. Granting Team Beta the 'Use' role on 'shared_ssh_key' resolves the permission error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant Team Beta the 'Use' role on the credential 'shared_ssh_key'.
Why this is correct
Tower roles are scoped per object, not inherited from organisation membership. Team Alpha holds a Use role on the credential; Team Beta does not, so job launch is refused. Granting Team Beta the Use role on 'shared_ssh_key' satisfies the credential-permission constraint.
- ✗
Create a new credential with the same SSH key and assign it to Team Beta.
Why it's wrong here
Duplicating the credential does not grant Team Beta access; the real cause is that the credential lacks a team or user assignment permitting dbservers use. Cloning credentials is tempting for isolating team access, but it is correct only when teams genuinely need separate secrets, not a shared one.
- ✗
Assign the credential to the dbservers group in the inventory.
Why it's wrong here
Tower grants credential access through organisations, teams, and users, never through inventory groups; groups only partition hosts. It tempts because group-scoped permissions exist for inventories, but the 'dbservers' group cannot hold a credential, so Team Beta still lacks the role grant.
- ✗
Move the credential from the organization to the project level.
Why it's wrong here
Credentials attach to organisations, teams, or users in Tower; projects hold playbooks, not credentials, so this move is impossible. It tempts because project-level resources feel granular, yet credential sharing is governed by role-based access grants on the credential object itself.
Visual reference
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.