Courseiva

EX294 Manage automation security and operations Practice Question

A company uses Ansible Automation Platform and wants to ensure that all playbook runs are logged for audit purposes. What is the simplest way to achieve centralized logging of job runs?

⚠ Common exam trap

Candidates often think they need to modify playbooks (Option A) or write custom callback plugins (Option C) to achieve logging, when the platform already provides a simple, built-in configuration option for centralized syslog forwarding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the syslog server in the automation controller settings.

Automation Controller (formerly Ansible Tower) has a built-in setting under 'System → Logging' where you can configure a syslog server (e.g., using RFC 5424). Once configured, all job runs, playbook output, and audit events are automatically forwarded to that central syslog server without modifying any playbooks or adding custom callbacks. This is the simplest, most centralized, and most maintainable approach for audit logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the logging module in each playbook to write to a central syslog.

    Why it's wrong here

    The logging module writes only what each playbook explicitly emits, so it cannot capture job-run events centrally without editing every playbook. It suits application-level messages inside a task, not Automation Platform job auditing, where controller-level logging of all runs is required.

  • ✓

    Configure the syslog server in the automation controller settings.

    Why this is correct

    Configuring the syslog server in automation controller settings forwards job-run audit records directly to a central collector, satisfying the requirement for centralised logging without extra tooling. Automation controller emits job events, activity stream entries and login attempts over syslog, so a single setting delivers the audit trail the stem demands.

  • ✗

    Add a playbook callback that sends output to a file on each node.

    Why it's wrong here

    A callback writing to a file on each managed node scatters logs across hosts rather than centralising them, and callback plugins execute on the controller, not the nodes. Callbacks are for customising controller-side output handling, such as streaming job events to an external endpoint.

  • ✗

    Enable verbose logging in the inventory file.

    Why it's wrong here

    The inventory file defines hosts, groups and connection variables; it holds no logging verbosity setting, so enabling anything there cannot capture job-run detail. Verbosity is controlled by the ansible.cfg or command-line flags, which govern console output rather than centralised audit logging.

About these practice questions

This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.