EX294 Manage inventories and credentials Practice Question
A playbook must connect to hosts using a non-default SSH private key stored at /home/student/.ssh/prod_key and a non-default remote user 'deploy'. The inventory file should apply these settings to all hosts in the 'production' group without editing the playbook. Which inventory variable combination is correct?
⚠ Common exam trap
The trap here is using plausible but incorrect variable names such as private_key_file or ansible_remote_user instead of the actual Ansible connection variables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
[production:vars] ansible_ssh_private_key_file=/home/student/.ssh/prod_key ansible_user=deploy
Ansible uses connection variables prefixed with ansible_ to override SSH behavior. ansible_ssh_private_key_file specifies the key, and ansible_user sets the remote user. Placing them in a group vars section applies them to all hosts in that group, satisfying the scenario without modifying the playbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
[production:vars] private_key_file=/home/student/.ssh/prod_key remote_user=deploy
Why it's wrong here
private_key_file and remote_user are not valid Ansible inventory connection variables. The correct names are ansible_ssh_private_key_file and ansible_user. Using these incorrect names would cause Ansible to ignore them and fall back to defaults, likely failing authentication or using the wrong user.
- ✓
[production:vars] ansible_ssh_private_key_file=/home/student/.ssh/prod_key ansible_user=deploy
Why this is correct
The ansible_ssh_private_key_file variable tells Ansible which private key to use for SSH authentication, and ansible_user sets the remote login name. Defining both under a [production:vars] section applies them to every host in the production group, exactly matching the requirement without playbook changes.
- ✗
[production:vars] ssh_private_key_file=/home/student/.ssh/prod_key user=deploy
Why it's wrong here
The variables ssh_private_key_file and user are not Ansible connection variables. Ansible expects ansible_ssh_private_key_file and ansible_user. This configuration would be ignored, and the play would attempt to connect with the default SSH key and the local username, which is unlikely to work for the deploy account.
- ✗
[production:vars] ansible_ssh_key=/home/student/.ssh/prod_key ansible_remote_user=deploy
Why it's wrong here
ansible_ssh_key and ansible_remote_user are not recognized connection variables in current Ansible. The correct variables are ansible_ssh_private_key_file and ansible_user. This snippet would not change SSH behavior, so the play would use the default key and user, causing connection failures.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.