EX294 Manage inventories and credentials Practice Question
A systems administrator needs to use a different SSH private key for a group of hosts in an Ansible inventory. Which inventory variable should be set at the group level?
⚠ Common exam trap
Many candidates confuse the variable name with similar-sounding but invalid options like `ansible_ssh_key` or `ansible_private_key`, forgetting that Ansible requires the exact `ansible_ssh_private_key_file` syntax to specify a private key file path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ansible_ssh_private_key_file
`ansible_ssh_private_key_file` is the Ansible inventory variable that specifies the path to the SSH private key file for a host or group. When set at the group level, it applies to all hosts in that group, allowing the administrator to use a different key for authentication without modifying individual host definitions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ansible_ssh_key
Why it's wrong here
Ansible's connection plugin reads ansible_ssh_private_key_file, not ansible_ssh_key, so this variable is silently ignored and the default key is used. It is tempting because the name mirrors the ssh -i flag, and ansible_ssh_key would be the natural choice if Ansible had adopted that naming convention.
- ✓
ansible_ssh_private_key_file
Why this is correct
ansible_ssh_private_key_file is the inventory variable that specifies the SSH private key used for authentication. Setting it at group level applies that key to every host in the group, satisfying the requirement to use a different key for those hosts.
- ✗
ansible_ssh_key_file
Why it's wrong here
Ansible's connection plugin reads ansible_ssh_private_key_file, not ansible_ssh_key_file, so this variable is silently ignored and the default key is used. It is tempting because it closely resembles the correct variable, and ansible_ssh_key_file would be the natural choice if Ansible had adopted that shorter naming convention.
- ✗
ansible_private_key
Why it's wrong here
Ansible's connection plugin reads ansible_ssh_private_key_file, not ansible_private_key, so this variable is silently ignored and the default key is used. It is tempting because the name describes exactly what is being supplied, and ansible_private_key would be the natural choice if Ansible had adopted that naming convention.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.