EX294 Manage automation security and operations Practice Question
A Red Hat Certified Engineer is configuring Ansible to run playbooks against managed nodes. The security policy requires that all communication between the control node and managed nodes is encrypted and authenticated. The engineer decides to use SSH keys for authentication. Which Ansible configuration parameter should be set to specify the private key file to use for SSH connections?
⚠ Common exam trap
Watch out — candidates often confuse `ansible_ssh_common_args` with the dedicated private key variable; while you can pass `-i` via common args, the correct parameter is `ansible_ssh_private_key_file`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
`ansible_ssh_private_key_file`
To specify a private key file for SSH connections in Ansible, the connection variable `ansible_ssh_private_key_file` is used. It can be set in the inventory, in group_vars, host_vars, or as an extra variable. This ensures that Ansible uses the designated key for authentication, meeting the security policy. The other options either specify a password, username, or additional SSH arguments, none of which directly designate the private key file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
`ansible_ssh_common_args`
Why it's wrong here
`ansible_ssh_common_args` allows passing additional arguments to the SSH command, such as `-i` to specify a key file. However, it is not the dedicated parameter for setting the private key file. Using it for this purpose is possible but less direct and more error-prone than using `ansible_ssh_private_key_file`. The scenario asks for the parameter to specify the private key file, which is `ansible_ssh_private_key_file`.
- ✗
`ansible_ssh_pass`
Why it's wrong here
`ansible_ssh_pass` specifies the password for SSH authentication, not a private key file. Using passwords is less secure and not aligned with the requirement to use SSH keys. This variable would be used in inventory or playbooks to provide a password, but it does not reference a key file. Therefore, it does not meet the scenario's need for key-based authentication.
- ✓
`ansible_ssh_private_key_file`
Why this is correct
`ansible_ssh_private_key_file` is an Ansible connection variable that specifies the path to the private key file used for SSH authentication. Setting this variable in the inventory or as a host variable ensures that Ansible uses the correct key when connecting to managed nodes. This directly satisfies the requirement to use SSH keys for encrypted and authenticated communication.
- ✗
`ansible_user`
Why it's wrong here
`ansible_user` specifies the remote username to use for SSH connections, not the private key file. While it is essential for authentication, it does not provide the key. Without the private key, key-based authentication cannot occur. This variable is part of the connection details but does not fulfill the need to specify a private key file.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.