EX294 Manage automation security and operations Practice Question
A Red Hat Ansible Automation Platform installation uses a custom execution environment. The playbook runs fail with 'execution environment not found'. The execution environment is stored in a private registry requiring authentication. What must be configured?
⚠ Common exam trap
Many exam-takers confuse setting the image name (Option A) with providing registry authentication, or they mistakenly think inventory or project settings can handle container registry access, when in fact only a dedicated container registry credential in automation controller can authenticate to a private registry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the registry URL to the automation controller's container registry credentials
When an execution environment is stored in a private registry that requires authentication, the automation controller must have the registry's URL and credentials configured as a container registry credential. This credential is then used by the controller to authenticate and pull the execution environment image during job runs. Without this, the controller cannot access the private registry, resulting in the 'execution environment not found' error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the execution_environment_image variable in the playbook
Why it's wrong here
Setting execution_environment_image in the playbook only names the image; it supplies no registry credentials, so the authenticated pull still fails. It is tempting because the variable does select which image runs, and it would be correct when the image sits in a public registry needing no authentication.
- ✗
Configure the execution environment in the inventory
Why it's wrong here
Inventory files define managed hosts and connection variables, not container registry credentials, so the authenticated pull still fails. It is tempting because inventory can carry host-level variables, and it would be correct for setting per-host connection details rather than sourcing an execution environment image.
- ✓
Add the registry URL to the automation controller's container registry credentials
Why this is correct
The controller must authenticate to the private registry before pulling the execution environment image, so adding the registry URL and credentials under container registry credentials satisfies that constraint. Without this, image pulls fail with 'not found' despite the image existing.
- ✗
Add the registry to the project's source control
Why it's wrong here
Source control stores playbook and configuration files; it holds no registry credentials, so the authenticated pull still fails. It is tempting because projects reference execution environments, but that linkage is metadata, not authentication. Credentials belong in an execution environment credential attached to the organisation or job.
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.