EX294 Manage inventories and credentials Practice Question
A playbook run against a Windows host fails at the connection stage with an authentication error, although the inventory specifies `ansible_user: Administrator` and the correct password. Which inventory variable must be set so that Ansible uses the password-based WinRM connection instead of trying Kerberos or certificate authentication?
⚠ Common exam trap
The trap here is assuming that `ansible_connection: winrm` alone determines how Windows authentication happens, when the authentication protocol is actually chosen by a separate transport variable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ansible_winrm_transport: ntlm
For Windows targets, authentication over WinRM is governed by `ansible_winrm_transport`. With a username and password and no Kerberos infrastructure, setting it to `ntlm` forces NTLM authentication and resolves the connection failure. Connection type, SSH password, and become settings do not select the WinRM authentication protocol.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ansible_winrm_transport: ntlm
Why this is correct
On Windows, the `ansible_winrm_transport` inventory variable selects the authentication protocol used by the WinRM connection plugin. Setting it to `ntlm` forces basic NTLM authentication with the supplied user and password, avoiding Kerberos or certificate attempts. This directly addresses the authentication failure when a password is provided and the environment does not have Kerberos configured.
- ✗
ansible_become: true
Why it's wrong here
`ansible_become` enables privilege escalation after a connection is established; it does not change how the initial connection authenticates. The failure occurs before any task runs, so become settings are irrelevant. This option mistakes an authorization control for an authentication mechanism and would not fix the WinRM login problem.
- ✗
ansible_ssh_pass: <password>
Why it's wrong here
`ansible_ssh_pass` is used by the SSH connection plugin, not by WinRM. Windows hosts are normally managed over WinRM, and providing an SSH password variable would not influence the WinRM authentication negotiation. This option confuses the Linux connection path with the Windows one and would leave the original authentication error unresolved.
- ✗
ansible_connection: winrm
Why it's wrong here
Setting the connection plugin to `winrm` is necessary for Windows management, but it does not by itself select password authentication. WinRM can authenticate with Kerberos, NTLM, or certificates. The connection plugin choice only determines the transport; the authentication method is controlled by a separate variable, so this setting alone would not resolve the password issue.
Visual reference
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.