EX294 Practice Question: Create content collections and execution environments
A team wants to use a certified collection from Red Hat Automation Hub but cannot access it directly due to firewall restrictions. What is the best practice?
⚠ Common exam trap
It's easy for candidates to assume manual download (Option A) is acceptable for firewall restrictions, but Red Hat's best practice emphasizes using a private Automation Hub to maintain supportability and consistency across the enterprise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up a private Automation Hub and sync the collection.
Setting up a private Automation Hub and syncing the certified collection is the best practice for environments with firewall restrictions. This approach ensures that the collection remains in a trusted, curated state, is automatically updated, and can be consumed by all team members via `ansible-galaxy` without manual intervention, maintaining compliance with Red Hat's support policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Download the collection manually and install from a tarball.
Why it's wrong here
A manual tarball install works technically but bypasses the signed, supported content pipeline, so dependency resolution, updates and certification provenance are lost. It is tempting under firewall restrictions, yet the best practice is synchronising certified collections to an internal Automation Hub or Galaxy mirror and installing from that configured source.
- ✓
Set up a private Automation Hub and sync the collection.
Why this is correct
A private Automation Hub mirrors certified collections internally, so the firewall-restricted team syncs content from an on-premises repository rather than reaching Red Hat Automation Hub directly. This preserves certified content while satisfying network isolation requirements.
- ✗
Copy the collection from another team's workspace.
Why it's wrong here
Copying from a colleague's workspace bypasses validation and provenance, risking tampered or outdated artefacts and no signature verification. It is tempting when the Hub is unreachable and a local copy exists, but the supported route is syncing the certified content into a private Automation Hub or Galaxy mirror inside the firewall.
- ✗
Use ansible-galaxy collection install with --offline flag.
Why it's wrong here
The --offline flag only suppresses Galaxy server lookups for already-cached requirements; it cannot fetch a collection that was never downloaded. It appeals because it sounds like an air-gapped install, but the correct approach is mirroring certified content to an internal Automation Hub and configuring that as the source.
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.