Courseiva

Red Hat Certified Engineer EX294 (EX294) — Questions 226–300

392 questions total · 6pages · All types, answers revealed

Page 3

Page 4 of 6

Page 5
226
MCQeasy

An administrator is creating a new inventory file for a small environment. The inventory must define a group `app` containing hosts `app1` and `app2`, and a group `db` containing host `db1`. The administrator wants to use the INI format. Which inventory file content correctly defines these groups?

A.app: app1, app2 db: db1
B.[app] app1, app2 [db] db1
C.[app] app1 app2 [db] db1
D.group app host app1 host app2 group db host db1
AnswerC

This content correctly uses INI section headers to define groups. The group `app` contains app1 and app2, and the group `db` contains db1. There are no syntax errors, and the format matches Ansible's INI inventory requirements. This is the valid and straightforward way to define static groups in an INI inventory file.

Why this answer

Ansible INI inventory files use square-bracketed group names followed by one host per line. The correct content defines the `app` group with app1 and app2 on separate lines, and the `db` group with db1. The other options use invalid syntax such as key-value pairs, non-standard keywords, or comma-separated hosts, which Ansible would not parse as intended.

Exam trap

The trap here is assuming that comma-separated hosts or YAML-like structures are valid in INI inventory files, when each host must be on its own line.

227
Matchingmedium

Match each Ansible fact variable to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Fully qualified domain name

OS family (e.g., RedHat)

Total memory in MB

Number of CPU cores

Default IPv4 interface info

Why these pairings

The correct matches are: ansible_distribution -> OS distribution name, ansible_os_family -> OS family, ansible_architecture -> CPU architecture. Common confusions include mistaking memory units (MB vs GB) and hostname vs IP address.

228
Multi-Selecthard

Which THREE of the following are valid Ansible lookup plugins? (Select exactly three.)

Select 3 answers
A.`csvfile`
B.`map`
C.`file`
D.`password`
E.`select`
AnswersA, C, D

Correct; csvfile is a lookup plugin to parse CSV files.

Why this answer

`csvfile` is a built-in Ansible lookup plugin that reads data from CSV files, allowing playbooks to parse structured tabular data. It is documented in the official Ansible lookup plugin list and is commonly used for dynamic inventory or configuration values.

Exam trap

The trap here is that candidates confuse Jinja2 filters (like `map` and `select`) with Ansible lookup plugins, as both are used in templating but serve fundamentally different purposes—filters transform data, while lookups retrieve external data.

229
MCQeasy

A team uses Ansible to update a web application across 10 servers with minimal downtime. Which playbook directive achieves one-at-a-time updates?

A.run_once: true
B.delegate_to: localhost
C.serial: 1
D.throttle: 1
E.forks: 10
AnswerC

Setting serial to 1 makes Ansible run the play against a single host per batch, so only one of the ten servers restarts at a time. Remaining hosts keep serving traffic, satisfying the minimal-downtime constraint.

Why this answer

C is correct because the `serial: 1` directive in an Ansible playbook controls the number of hosts that are updated simultaneously. Setting `serial: 1` forces Ansible to execute the playbook on one host at a time, ensuring that the web application is updated sequentially across the 10 servers, which minimizes downtime by keeping the other 9 servers available during each individual update.

Exam trap

The trap here is that candidates confuse `serial` with `forks` or `throttle`, mistakenly thinking that limiting parallel connections (`forks: 1`) or task concurrency (`throttle: 1`) achieves the same sequential host behavior as `serial`, but only `serial` controls the batch size of hosts processed by the playbook.

How to eliminate wrong answers

Option A is wrong because `run_once: true` executes a task on only one host in the batch, not sequentially across all hosts, and is typically used for one-time setup tasks like generating a shared secret. Option B is wrong because `delegate_to: localhost` runs a task on the Ansible control node instead of the target servers, which does not control the order or batch size of host updates. Option D is wrong because `throttle: 1` limits the number of concurrent forks for a specific task but does not enforce sequential host processing across the entire play; it can still allow parallel execution of other tasks.

Option E is wrong because `forks: 10` sets the maximum number of parallel connections Ansible can make, but it does not guarantee one-at-a-time updates; with 10 forks, Ansible could attempt to update all 10 servers simultaneously.

230
Multi-Selectmedium

An engineer is preparing to build an execution environment using `ansible-builder`. The build must include several collections and also install additional Python packages. Which two files are used to declare these dependencies? (Choose two.)

Select 2 answers
A.requirements.yml
B.galaxy.yml
C.execution-environment.yml
D.bindep.txt
E.requirements.txt
AnswersA, E

`requirements.yml` is used to list Ansible collections and roles that should be installed into the execution environment. It is the standard file for declaring collection dependencies, including those from Automation Hub or Galaxy. This file ensures the required collections are present.

Why this answer

The correct files are `requirements.yml` for Ansible collections and roles, and `requirements.txt` for Python packages. These are referenced by the `execution-environment.yml` file and are used by `ansible-builder` to install the necessary dependencies into the execution environment.

Exam trap

The trap here is confusing `bindep.txt` (system packages) with `requirements.txt` (Python packages), or assuming that `execution-environment.yml` directly lists all dependencies.

231
MCQmedium

An administrator has a role named 'web' that must run a package installation task before any other tasks in the role. The role contains a tasks/main.yml file and a meta/main.yml file. The administrator wants the package installation to be a separate role named 'common' that is always executed first when the 'web' role is applied. Which approach should the administrator use?

A.Add the 'common' role to the roles list in the play before the 'web' role.
B.Add a dependencies section to meta/main.yml in the 'web' role listing the 'common' role.
C.Use include_role with a when condition in tasks/main.yml of the 'web' role.
D.Use import_tasks in tasks/main.yml to import a tasks file from the 'common' role.
AnswerB

Role dependencies defined in meta/main.yml cause the listed roles to execute before the current role. This ensures the 'common' role runs first, installing packages before any 'web' tasks. Dependencies are resolved at playbook parse time and are the standard mechanism for ordering role execution without modifying the play itself.

Why this answer

Role dependencies declared in meta/main.yml cause the dependent role to execute before the current role. This ensures the 'common' role's package installation runs first whenever 'web' is applied, regardless of the playbook. It is the intended way to express that one role requires another, keeping the relationship self-contained within the role.

Exam trap

The trap here is assuming that listing roles in a play is equivalent to defining a dependency, but a play-level list only orders roles for that specific play and does not enforce the dependency for other playbooks.

232
MCQeasy

Refer to the exhibit. An administrator wants to view the decrypted value of 'db_password' without modifying the file. Which command should be used?

A.ansible-vault rekey file.yml
B.ansible-vault decrypt file.yml
C.ansible-vault view file.yml
D.ansible-vault edit file.yml
AnswerC

ansible-vault view decrypts and displays the file contents to standard output without altering the encrypted file on disk, satisfying the requirement to read db_password without modification. The edit subcommand would decrypt and re-encrypt, risking changes.

Why this answer

The `ansible-vault view` command decrypts the file in memory and displays its contents to stdout without modifying the encrypted file on disk. This is the correct choice because the administrator only needs to see the decrypted value of 'db_password' and does not want to change the file.

Exam trap

The trap here is that candidates often confuse `ansible-vault view` with `ansible-vault decrypt`, mistakenly thinking they must permanently decrypt the file to see its contents, when `view` provides a read-only decrypted output without altering the file.

How to eliminate wrong answers

Option A is wrong because `ansible-vault rekey` changes the vault password used to encrypt the file, not decrypt or display its contents. Option B is wrong because `ansible-vault decrypt` permanently decrypts the file and writes the plaintext to disk, which modifies the file. Option D is wrong because `ansible-vault edit` decrypts the file, opens it in an editor, and re-encrypts it upon saving, which modifies the file even if no changes are made.

233
MCQhard

An organization runs Red Hat Ansible Automation Platform 2.5 with a containerized automation controller. Administrators want job output and automation logs centralized so that a security team can search historical runs and correlate them with SIEM events. Which supported capability should the administrator configure to forward controller logs to an external logging endpoint?

A.Mount the controller container's /var/log/tower directory onto the host and ship those files with a log forwarder.
B.Enable the callback plugin in each project's ansible.cfg so every task posts its result to a remote HTTP endpoint.
C.Create a scheduled job template that queries the controller API for job events and writes them to a shared NFS export.
D.Configure the controller's external logging settings to send activity stream and job output to a syslog or aggregator endpoint.
AnswerD

Automation controller supports external logging, which forwards activity stream records and job events to an external aggregator such as Splunk, Elastic, or a syslog server. Enabling this with the appropriate host, port, and protocol settings centralizes logs so the security team can search and correlate them without querying the controller database directly.

Why this answer

Automation controller includes external logging configuration that forwards activity stream data and job events to syslog, Splunk, Elastic, or other aggregators. Enabling it centralizes logs for search and SIEM correlation without custom plugins, host mounts, or API polling jobs.

Exam trap

The trap here is assuming a callback plugin or host-mounted log directory replaces the controller's built-in external logging integration for audit and job events.

234
MCQhard

A team uses Ansible Automation Controller with multiple organizations. Each organization has its own set of machines that require different SSH keys. The administrator wants to ensure that users from one organization cannot use credentials from another organization. What is the best way to achieve this isolation?

A.Create credentials within each organization and assign organization-level access
B.Store credentials in separate projects and restrict project access
C.Set 'Use' permission on credentials only for specific users
D.Place users in different teams and restrict credential access by team
AnswerA

Credentials scoped to an organisation are only visible to members of that organisation, so users cannot select or reference another organisation's SSH keys. This satisfies the stem's isolation constraint, since Ansible Automation Controller enforces credential ownership boundaries at the organisation level rather than through playbook logic or host grouping.

Why this answer

In Ansible Automation Controller, credentials are scoped to organizations. By creating credentials within each organization and assigning organization-level access, the administrator ensures that credentials are only visible and usable by members of that organization. This leverages the built-in role-based access control (RBAC) that isolates resources by organization, preventing cross-organization credential access.

Exam trap

The trap here is that candidates often confuse team-based access control with organization-level isolation, assuming that restricting credentials to a team within an organization provides cross-organization security, but teams do not span organizations and cannot prevent access from users in other organizations.

How to eliminate wrong answers

Option B is wrong because projects in Ansible Automation Controller are used to store playbooks and source code, not credentials; credentials are stored separately in the Credentials resource and are not scoped by project. Option C is wrong because setting 'Use' permission on credentials for specific users does not prevent users from other organizations from accessing those credentials if they are not properly scoped to an organization; organization-level isolation is required. Option D is wrong because teams are subgroups within an organization and do not provide cross-organization isolation; users from different organizations could still be placed in the same team, and team-based restrictions do not enforce organizational boundaries.

235
MCQeasy

An administrator needs to run a playbook that applies a configuration only to hosts that have a specific fact, `ansible_processor_vcpus`, greater than 4. The playbook should skip hosts that do not meet this condition. Which approach should be used?

A.Set `gather_facts: no` and use a custom fact to check vCPU count.
B.Use the `serial` keyword to limit execution to hosts with more than 4 vCPUs.
C.Create a dynamic inventory script that only includes hosts with more than 4 vCPUs.
D.Add a `when` condition to each task: `when: ansible_processor_vcpus > 4`.
AnswerD

Using a when condition on tasks that checks ansible_processor_vcpus > 4 is the straightforward way to conditionally execute tasks based on a fact. Ansible gathers facts by default, so ansible_processor_vcpus is available. This ensures that only hosts with more than 4 vCPUs run the configuration tasks, while others skip them.

Why this answer

The most direct method to conditionally run tasks based on a fact is to use a when condition on the tasks. Since Ansible gathers facts by default, ansible_processor_vcpus is available, and the condition will evaluate correctly per host. This ensures that only hosts with more than 4 vCPUs execute the configuration, while others skip it.

Exam trap

The trap here is thinking that the serial keyword can filter hosts based on facts, when it only controls batch size.

236
MCQhard

A DevOps engineer is creating an execution environment for a team that needs both Ansible and the 'requests' Python library. The engineer creates an execution environment definition file (EE.yml) with the following content: --- version: 3 images: base_image: name: registry.redhat.io/ansible-automation-platform-22/ee-minimal-rhel8:latest options: package_manager_path: /usr/bin/microdnf dependencies: python: requirements.txt system: bindep.txt What is missing from this definition to ensure the 'requests' library is installed?

A.The package_manager_path should be /usr/bin/yum.
B.The requirements.txt file must contain 'requests'.
C.The galaxy.yml file must be added to the dependencies section.
D.The base image should be ee-supported-rhel8 instead.
AnswerB

The definition references requirements.txt under dependencies.python, so pip installs whatever that file lists. Because the file's contents are not shown, the 'requests' library is only guaranteed to be present if requirements.txt explicitly names it; otherwise nothing installs it.

Why this answer

The execution environment definition file (EE.yml) specifies dependencies via external files like requirements.txt for Python packages. To install the 'requests' library, the requirements.txt file must explicitly list 'requests' as a dependency. Without it, the build process will not include the library, regardless of other configuration options.

Exam trap

The trap here is that candidates may focus on the package manager or base image details, overlooking that the Python dependency must be explicitly declared in the requirements.txt file referenced by the definition.

How to eliminate wrong answers

Option A is wrong because the package_manager_path is correctly set to /usr/bin/microdnf for the specified RHEL 8 base image, which uses microdnf as its package manager; changing it to /usr/bin/yum would be incorrect. Option C is wrong because the galaxy.yml file is used for Ansible Galaxy content collections, not for Python package dependencies like 'requests'. Option D is wrong because the base image 'ee-minimal-rhel8' is appropriate for this execution environment; 'ee-supported-rhel8' is not a standard Red Hat image name and would not resolve the missing Python dependency.

237
MCQmedium

Your team maintains a collection that includes custom modules and plugins. You have been tasked with creating a content collection that adheres to the Red Hat Ansible Content Collection requirements. You have created the directory structure and written the collection code. Now you need to package the collection for distribution to your internal automation hub. You run 'ansible-galaxy collection build' and it completes successfully, generating a tarball. However, when you try to publish it to your private automation hub using 'ansible-galaxy collection publish', you get an authentication error. You have verified that your automation hub server URL and API token are correct. What is the most likely cause of the error?

A.The automation hub server is not reachable from your network.
B.The collection tarball is corrupted and needs to be rebuilt.
C.The collection contains a module that violates a content policy enforced by the hub.
D.The 'namespace' or 'name' in galaxy.yml does not match the namespace you are allowed to publish to on the automation hub.
AnswerD

Publishing authenticates the token, but authorisation is scoped per namespace. If galaxy.yml's namespace differs from the one your automation hub account may publish to, the server rejects the upload with an authentication-style error even though the token itself is valid.

Why this answer

The authentication error despite correct server URL and API token indicates that the issue is not with credentials or connectivity, but with authorization. Ansible Automation Hub enforces namespace-based access control: the `namespace` field in `galaxy.yml` must match a namespace you are permitted to publish to. If the namespace does not match, the hub rejects the upload with an authentication/authorization error, even though the token itself is valid.

Exam trap

The trap here is that candidates assume any error during `publish` with a valid token must be a network or credential issue, overlooking the namespace authorization check that Ansible Automation Hub performs before allowing upload.

How to eliminate wrong answers

Option A is wrong because the user verified the server URL is correct, and a connectivity issue would typically produce a timeout or connection refused error, not an authentication error. Option B is wrong because the `ansible-galaxy collection build` command completed successfully, which includes integrity checks; a corrupted tarball would likely cause a build failure or a checksum mismatch during upload, not an authentication error. Option C is wrong because content policy violations (e.g., disallowed modules) would result in a policy rejection error message, not an authentication error — the hub would accept the token but refuse the content based on policy rules.

238
Multi-Selectmedium

Which THREE files are commonly used when building an execution environment with ansible-builder?

Select 3 answers
A.bindep.txt
B.ansible.cfg
C.galaxy.yml
D.execution-environment.yml
E.requirements.txt
AnswersA, D, E

bindep.txt lists system-level package dependencies, which ansible-builder installs into the execution environment's base image before Python requirements. This satisfies the stem's need for build-input files: bindep.txt supplies OS packages, complementing requirements.txt and ansible.cfg as the three commonly used files.

Why this answer

ansible-builder builds an execution environment from a definition directory, and the three commonly used input files are execution-environment.yml, requirements.txt, and bindep.txt. Option D (execution-environment.yml) is the main definition file that declares the base image, dependencies, and additional build steps for the execution environment. Option E (requirements.txt) lists the Python packages (such as ansible-core, ansible-runner, and collections' Python dependencies) to install into the image.

Option A (bindep.txt) specifies system-level (RPM/OS) package requirements that must be installed in the container image. Option B (ansible.cfg) is an Ansible runtime configuration file and is not a standard ansible-builder input, and Option C (galaxy.yml) is a collection metadata file used when building or publishing Ansible collections, not for building execution environments.

Exam trap

Red Hat often tests the misconception that `ansible.cfg` is part of the execution environment build process, but it is only used at runtime by Ansible, not by `ansible-builder` to construct the container image.

239
MCQeasy

An Ansible developer needs to use the `podman_container` module in a playbook. The module is part of the `containers.podman` collection. Which command must be run first to make the module available?

A.`ansible-galaxy install containers.podman`
B.`ansible-galaxy collection install containers.podman`
C.`ansible-galaxy collection search containers.podman`
D.`ansible-galaxy collection install containers.podman:1.0.0`
AnswerB

`ansible-galaxy collection install containers.podman` retrieves the collection from Galaxy and places it in the configured collections path, so the `podman_container` module resolves during playbook execution. This satisfies the stem's requirement to make the module available before use, since collections must be installed rather than bundled with ansible-core.

Why this answer

The `podman_container` module is part of the `containers.podman` collection, which must be installed from Ansible Galaxy before it can be used in a playbook. The correct command is `ansible-galaxy collection install containers.podman`, which downloads and installs the collection into the local collections path, making all its modules and plugins available.

Exam trap

The trap here is that candidates may confuse `ansible-galaxy install` (for roles) with `ansible-galaxy collection install` (for collections), or mistakenly think that searching for a collection makes it available for use.

How to eliminate wrong answers

Option A is wrong because `ansible-galaxy install` is used for installing roles, not collections; collections require the `collection` subcommand. Option C is wrong because `ansible-galaxy collection search` only searches for collections in Galaxy but does not install them, so the module would remain unavailable. Option D is wrong because while it specifies a version (`1.0.0`), the question does not require a specific version; the generic install command is sufficient, and pinning an arbitrary version may cause compatibility issues or fail if that version does not exist.

240
MCQmedium

An organization wants to include custom Python packages in their execution environment to support custom modules. Which method should be used to define these Python dependencies?

A.List them in the `galaxy-requirements.yml` file.
B.Use `ansible-navigator` to install them during runtime.
C.Create a `requirements.txt` file and reference it in the `execution-environment.yml` under `dependencies: python:`.
D.Add them to the `collection-requirements.yml` file.
AnswerC

Ansible Builder reads the python section of dependencies and passes the referenced requirements.txt to pip inside the build, so custom Python packages land in the execution environment image and the custom modules can import them at runtime.

Why this answer

The `execution-environment.yml` file supports a `dependencies` key with a `python` subkey that points to a `requirements.txt` file. This is the standard method defined by the Ansible Builder specification for including custom Python packages in an execution environment, ensuring they are installed during the build process.

Exam trap

The trap here is that candidates confuse the file used for Ansible collections (`galaxy-requirements.yml` or `collection-requirements.yml`) with the file used for Python dependencies, leading them to pick options A or D instead of recognizing the correct `execution-environment.yml` structure.

How to eliminate wrong answers

Option A is wrong because `galaxy-requirements.yml` is used to specify Ansible Galaxy content collections, not Python packages. Option B is wrong because `ansible-navigator` is a runtime tool for running execution environments, not for installing dependencies during the build; Python dependencies must be defined at build time. Option D is wrong because `collection-requirements.yml` is another name for a file that lists Ansible collections, not Python packages.

241
MCQmedium

An administrator needs to ensure that a task runs only on the first host in a batch and that its result is applied to all hosts in the batch. Which Ansible directive should be used?

A.run_once: true
B.delegate_to: localhost
C.serial: 1
D.any_errors_fatal: true
AnswerA

'run_once: true' forces the task to execute on only one host (the first host in the current batch) and applies the results to all hosts in the play. This is exactly the requirement. It is commonly used for tasks like database migrations or cluster initialization that should happen only once, with the outcome affecting all hosts.

Why this answer

The 'run_once: true' directive ensures a task runs only on the first host in the batch and that the results are applied to all hosts. This is ideal for one-time operations. The other options either delegate to the control node, change batching, or affect error handling, none of which satisfy the specific requirement.

Exam trap

The trap here is confusing 'run_once' with delegation or serial batching, which control different aspects of execution.

242
MCQmedium

You are performing a rolling update of a 12-node web server fleet managed by Ansible. The playbook uses `serial: 4`. During the second batch, the task `Restart httpd` fails on one host because the service name is misspelled. The playbook aborts with an error. You fix the typo and rerun the playbook. What is the default behavior regarding the hosts that were already updated successfully in the first batch?

A.The playbook re-runs all tasks on every host, including the first batch, because Ansible is idempotent and will simply reapply the configuration.
B.The playbook fails immediately because the inventory still marks the failed host as unreachable, blocking any further execution.
C.The playbook starts over from the first batch and processes all hosts again, applying tasks to hosts that were already updated.
D.The playbook resumes from the failed batch, skipping the first batch entirely, because Ansible tracks successful hosts in a fact cache.
AnswerC

By default, Ansible targets all hosts in the inventory when you rerun a playbook. It does not remember which hosts succeeded in a previous run. Therefore, the first batch will be processed again, and tasks will be reapplied. This is why idempotent tasks and careful use of `serial` with external tracking are important in rolling updates.

Why this answer

Ansible does not persist playbook progress between runs. When you rerun a playbook, it targets the entire inventory by default, so hosts from the first batch are processed again. To avoid re-updating already-successful hosts, you would need to use `--limit` with a list of remaining hosts or implement a custom serial strategy that records completed batches externally.

Exam trap

The trap here is assuming Ansible remembers which hosts succeeded and automatically resumes from the failed batch.

243
MCQmedium

A developer is preparing a collection for distribution and must declare its metadata, including version, license, and the list of collections it depends on. Which file at the collection root contains these declarations?

A.requirements.yml
B.meta/runtime.yml
C.plugins/README.md
D.galaxy.yml
AnswerD

`galaxy.yml` is the collection manifest. It carries the namespace, name, version, authors, license, tags, and a `dependencies` mapping that lists other collections and their version constraints. When the collection is built and published, this file supplies the metadata the Galaxy server records and the resolver uses to pull dependent collections.

Why this answer

The manifest that describes a collection to Galaxy and to dependency resolution is `galaxy.yml`, which holds version, license, and the `dependencies` mapping. Runtime requirements live elsewhere, and consumer-side requirement files are unrelated to how the collection itself is described when packaged.

Exam trap

The trap here is mixing up a collection's own manifest with a consumer `requirements.yml` that merely lists collections to install into an environment.

244
MCQhard

You are using Ansible Automation Platform to manage a large number of servers. You need to ensure that playbooks that run against production servers use a separate set of credentials than those used for development servers. The production credentials must be stored securely and audited. Which Ansible Automation Platform feature should you use to achieve this?

A.Use the `--ask-pass` and `--ask-become-pass` options when launching playbooks from the command line.
B.Use Ansible Vault to encrypt the production credentials and store them in the playbook repository.
C.Configure the production inventory with a separate `ansible_user` and `ansible_ssh_pass` in the inventory file.
D.Create separate credentials in automation controller and assign them to different job templates based on the environment.
AnswerD

Automation controller allows you to create multiple credentials, each with its own secrets, and associate them with job templates. By creating distinct credentials for production and development, you ensure that playbooks use the appropriate set. Credentials are stored encrypted in the controller's database and their usage is audited in job runs. This directly meets the requirement for secure storage and auditing.

Why this answer

Automation controller credentials are designed for secure storage and auditing. By creating separate credentials for production and development and assigning them to the appropriate job templates, you ensure that each environment uses its own set of secrets. The controller encrypts credentials and logs their usage, providing the required audit trail.

The other options either store credentials insecurely or lack centralized management and auditing.

Exam trap

The trap here is thinking that Ansible Vault alone can provide the same level of secure storage and auditing as automation controller credentials.

245
MCQeasy

A junior administrator needs to perform a rolling update of 8 web servers where exactly 2 servers are updated at a time. Which play-level keyword and value should be used in the Ansible playbook?

A.throttle: 2
B.max_fail_percentage: 2
C.forks: 2
D.serial: 2
AnswerD

serial: 2 instructs Ansible to process hosts in batches of two during the play. Each batch completes the full task list before the next batch begins, so exactly two servers are updated at a time, which matches the administrator's requirement for this 8-node fleet.

Why this answer

The serial keyword is the standard way to define rolling update batch size in an Ansible play. Setting serial: 2 causes the play to process two hosts at a time through the full task list, ensuring only two of the eight web servers are updated concurrently. This is the direct and correct control for the administrator's requirement.

Exam trap

The trap here is mixing up forks, which controls parallel connections, with serial, which controls rolling batch size.

246
MCQeasy

A junior administrator needs to rotate the password for a database user stored in an Ansible Vault-encrypted file (secrets.yml). The current password is unknown to the admin, but they have the vault password file (vault-pass.txt). The admin wants to edit the file securely without exposing the decrypted content in the terminal history or logs. Which command should they run?

A.ansible-vault edit --vault-password-file vault-pass.txt secrets.yml
B.ansible-vault decrypt --vault-password-file vault-pass.txt secrets.yml
C.ansible-vault rekey --vault-password-file vault-pass.txt secrets.yml
D.ansible-vault view --vault-password-file vault-pass.txt secrets.yml
AnswerA

ansible-vault edit decrypts into a temporary file and opens the editor, so plaintext never enters shell history or terminal output; supplying --vault-password-file avoids an interactive prompt. This satisfies the requirement to edit securely without exposing decrypted content.

Why this answer

`ansible-vault edit` decrypts the file to a temporary file, opens it in the default editor (e.g., vi), and upon saving, re-encrypts it transparently. This prevents the decrypted content from ever being written to the terminal history or logs, as the editing happens in a secure temporary location that is cleaned up after the editor closes.

Exam trap

The trap here is that candidates may confuse `edit` with `decrypt` (thinking they need to decrypt first, then edit, then re-encrypt), or they may think `rekey` is for changing the content, when in fact it only changes the vault encryption password.

How to eliminate wrong answers

Option B is wrong because `ansible-vault decrypt` permanently decrypts the file to plaintext on disk, which would expose the password in the filesystem and potentially in logs or history if the file is later read. Option C is wrong because `ansible-vault rekey` is used to change the vault password (encryption key) itself, not to edit the content of the encrypted file. Option D is wrong because `ansible-vault view` only displays the decrypted content to stdout (terminal), which would expose the password in the terminal output and potentially in scrollback or logs, without allowing any editing.

247
MCQhard

A playbook uses a task with 'delegate_to: localhost' to generate a report file. The task must run only once, even if the play targets multiple hosts. Which keyword should be added to the task to ensure it executes only on the first host?

A.throttle: 1
B.run_once: true
C.any_errors_fatal: true
D.serial: 1
AnswerB

run_once: true forces the task to execute only on the first host in the play, and any results are applied to all hosts. Combined with delegate_to: localhost, the task runs once on the control node, producing a single report. This avoids redundant execution when the play targets many hosts.

Why this answer

The run_once keyword ensures the task is executed only on the first host in the play, regardless of how many hosts are targeted. When combined with delegate_to: localhost, the task runs once on the control node, generating a single report. Other keywords like serial, throttle, or any_errors_fatal affect batching, concurrency, or error handling, not single execution.

Exam trap

The trap here is confusing serial, which controls play batching, with run_once, which controls task execution frequency. serial does not prevent a task from running on every host.

248
Multi-Selecthard

Which THREE of the following are valid uses of the 'ansible.builtin.include_role' module?

Select 3 answers
A.Pass variables to the included role using the 'vars' keyword.
B.Include a role from a collection by specifying 'namespace.collection.role_name'.
C.Dynamically set the role name using a variable without the 'name' parameter.
D.Conditionally include a role based on a variable.
E.Apply tags to all tasks within the included role.
AnswersA, B, D

Variables can be passed to the role via the 'vars' parameter.

Why this answer

The 'ansible.builtin.include_role' module supports the 'vars' keyword to pass variables directly to the included role. This allows you to override or supply role variables at the point of inclusion, which is a common pattern for reusing roles with different configurations.

Exam trap

The trap here is that candidates often confuse 'include_role' with 'import_role', assuming that tags applied to the include statement will automatically apply to all tasks inside the role, but in Ansible, tags on a dynamic include only affect the include task itself, not the included tasks.

249
MCQhard

An administrator manages a static inventory file with a group `web` defined as children of `production`. The inventory also defines a group variable `http_port=80` at the `all` group level and `http_port=8080` at the `web` group level. A playbook targets `hosts: web` and uses `{{ http_port }}` in a template. Which value will be used for hosts in the `web` group?

A.80, because variables defined at the `all` group take precedence over child groups.
B.80, because the play targets `web` but the variable is defined at `all` and that is the default.
C.8080, because variables defined at the `web` group override those at the `all` group.
D.8080, because the last definition in the inventory file wins regardless of group hierarchy.
AnswerC

In Ansible, group variable precedence increases with group depth. The `web` group is a child of `production`, which is a child of `all`. Variables defined at a more specific (deeper) group level override those at broader levels. Thus, http_port=8080 at the `web` group level takes precedence over http_port=80 at the `all` level for hosts in `web`. This is the correct value.

Why this answer

Ansible group variable precedence follows group depth: variables in child groups override those in parent groups. Since `web` is a child of `production` and `all` is the root, the `web` group variable http_port=8080 takes precedence over the `all` group variable http_port=80 for hosts in `web`. This ensures more specific settings are used.

The other options misstate the precedence rules.

Exam trap

The trap here is assuming that the broadest group (all) or file order dictates variable precedence, when actually child groups override parent groups.

250
MCQhard

Ansible Builder fails during the build of an execution environment with error: 'No matching manifest for linux/amd64 in the manifest list entries'. What is the most likely cause?

A.The ansible-builder version is too old.
B.The definition file has invalid syntax.
C.The container registry requires authentication.
D.The base image specified is incompatible with the host architecture.
AnswerD

The base image's manifest list lacks a linux/amd64 entry, so the container runtime cannot resolve a matching image for the host's architecture. Ansible Builder pulls the specified base image during execution environment creation, and this architecture mismatch halts the build before dependency installation begins.

Why this answer

The error 'No matching manifest for linux/amd64 in the manifest list entries' indicates that the base image specified in the execution environment definition file does not have a container image manifest for the host's CPU architecture (linux/amd64). Ansible Builder pulls the base image from a registry, and if that image only supports other architectures (e.g., linux/arm64), the build fails. This is a common issue when using a base image built for a different platform.

Exam trap

Red Hat often tests the misconception that registry authentication or syntax errors cause all build failures, but here the specific manifest list error is a clear indicator of an architecture mismatch, not a credential or syntax problem.

How to eliminate wrong answers

Option A is wrong because an outdated ansible-builder version would not cause this specific manifest mismatch error; it might cause other build failures or deprecation warnings, but the error is architecture-related. Option B is wrong because invalid syntax in the definition file typically results in YAML parsing errors or missing key errors, not a manifest list mismatch. Option C is wrong because registry authentication failures produce errors like 'unauthorized: authentication required' or 'denied: requested access to the resource is denied', not a manifest architecture mismatch.

251
MCQmedium

An automation engineer must ensure that a task in a playbook runs only once across all hosts in the play, even though the play targets 50 web servers. The task creates a shared DNS record on an external service. Which approach should be used?

A.Set `serial: 1` on the play.
B.Use `delegate_to: localhost` on the task.
C.Add `run_once: true` to the task.
D.Add `throttle: 1` to the task.
AnswerC

The `run_once` directive forces a task to execute on a single host in the current batch, and the results are applied to all hosts in the play. This ensures the DNS record is created only once, preventing duplicate entries and unnecessary API calls when scaling across many servers.

Why this answer

The `run_once` directive ensures that a task is executed only on the first host in the play, and the results are applied to all hosts. This is ideal for actions that should not be repeated per host, such as creating a shared resource. Other options either still execute per host or only control concurrency.

Exam trap

The trap here is assuming that `delegate_to: localhost` prevents multiple executions, when it actually runs the task once per host on the control node.

252
Multi-Selecthard

An administrator needs to create a custom execution environment that includes a specific Ansible collection and a Python package. Which two steps are required to build and use the execution environment? (Choose two.)

Select 2 answers
A.Create a Dockerfile that installs the collection and package.
B.Define the execution environment in ansible.cfg.
C.Build the execution environment using ansible-builder.
D.Push the execution environment to a private container registry.
E.Create a requirements.yml file listing the collection.
AnswersC, E

Correct: ansible-builder builds a container image from the execution environment definition.

Why this answer

`ansible-builder` is the official tool for building Ansible execution environments, which are container images that bundle Ansible, collections, and dependencies. It uses a definition file (execution-environment.yml) to specify collections and Python packages, then builds the container image. Option E is correct because a `requirements.yml` file is the standard way to list Ansible collections for inclusion in an execution environment, and `ansible-builder` reads this file during the build process.

Exam trap

The trap here is that candidates often confuse the manual Dockerfile approach (Option A) with the correct `ansible-builder` workflow, or they think pushing to a registry (Option D) is mandatory when the question only asks for steps to build and use the execution environment locally.

253
Matchingmedium

Match each storage concept to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Logical Volume Manager for flexible storage

Redundant array of independent disks

Default Linux filesystem (journaling)

High-performance 64-bit filesystem

Virtual memory on disk

Why these pairings

The correct matches are: LVM for flexible disk management with VGs and LVs, RAID for combining disks for redundancy/performance, Stratis for pool-based snapshots and thin provisioning, and VDO for block-level deduplication/compression. Common confusions include swapping LVM with VDO and RAID with Stratis.

254
MCQeasy

You are managing a web application deployment using Ansible. The application requires a specific version of a library (libapp) to be installed on all web servers. Your current playbook uses the role 'web' which includes a task to install libapp version 1.2. However, after a recent update, the role's defaults now specify libapp version 2.0, but you must keep version 1.2 for compatibility. You have defined a variable 'lib_version' in the playbook's vars section with value '1.2'. The role's task uses the variable 'libapp_version' (not 'lib_version'). The play fails because 'libapp_version' is undefined. What is the best way to resolve this issue without modifying the role?

A.Modify the role's defaults/main.yml to set libapp_version to 1.2.
B.Use the playbook to set libapp_version as a variable for the role: either in the play vars section or by passing it as a role parameter.
C.Rename your playbook variable from lib_version to libapp_version in the play vars.
D.Create a file roles/web/vars/main.yml with libapp_version: 1.2.
AnswerB

The role reads libapp_version, so supplying that exact variable name overrides the role default of 2.0 while leaving the role untouched. Setting it in play vars or as a role parameter satisfies the requirement to keep libapp version 1.2.

Why this answer

It allows you to set the variable `libapp_version` that the role expects without modifying the role itself. By defining `libapp_version` in the playbook's vars section or passing it as a role parameter, you override the role's default value (2.0) with the required version 1.2, ensuring the task uses the correct library version while preserving role integrity.

Exam trap

The trap here is that candidates may confuse variable names (lib_version vs libapp_version) and attempt to rename variables or modify role defaults, rather than understanding that the correct solution is to set the exact variable expected by the role at the playbook level.

How to eliminate wrong answers

Option A is wrong because modifying the role's defaults/main.yml directly changes the role, which violates the requirement to not modify the role. Option C is wrong because renaming the playbook variable from `lib_version` to `libapp_version` does not address the issue; the role's task uses `libapp_version`, and simply renaming the variable in the playbook's vars section would still leave `libapp_version` undefined unless the variable is explicitly set. Option D is wrong because creating a file roles/web/vars/main.yml modifies the role's internal structure, which is not allowed per the requirement to not modify the role.

255
MCQhard

A security team requires that all passwords in an Ansible vault be encrypted with a different key from the host variables. They want to use a custom lookup plugin that fetches secrets from an external API. Which plugin type should be developed?

A.Lookup plugin
B.Module
C.Action plugin
D.Filter plugin
AnswerA

A lookup plugin runs on the control node and returns data to Ansible, so it can query an external API for secrets at runtime. This satisfies the requirement to fetch vault passwords from a source separate from host variables, unlike vault password files or inventory variables.

Why this answer

A lookup plugin is the correct choice because it is designed to retrieve data from external sources (like an API) and return it as a string or list for use in Ansible playbooks. This aligns with the requirement to fetch secrets from an external API, and lookup plugins can be used directly in variables or templates without modifying the host state.

Exam trap

The trap here is that candidates often confuse lookup plugins with modules, thinking that any external interaction requires a module, but modules are for remote host actions, while lookups are for controller-side data retrieval.

How to eliminate wrong answers

Option B (Module) is wrong because modules are used to perform actions on remote hosts (e.g., install packages, manage services), not to fetch data from external APIs for use in variables. Option C (Action plugin) is wrong because action plugins execute on the controller and are typically used to implement complex module behavior or conditional logic, not for simple data retrieval like a lookup. Option D (Filter plugin) is wrong because filter plugins transform data within Jinja2 templates (e.g., format strings, manipulate lists), not fetch data from external sources.

256
MCQeasy

You are creating a new Ansible content collection named 'acme.corp' using the ansible-galaxy collection init command. After running the command, you need to add a module that will be part of this collection. Where should you place the module file within the collection directory structure?

A.In the roles directory under a role named after the module.
B.In the library directory at the root of the collection.
C.In the plugins/modules directory.
D.In the modules directory at the root of the collection.
AnswerC

Ansible collections follow a standard directory layout. Modules are stored in the plugins/modules directory. When the collection is installed, Ansible automatically discovers modules in this location. Placing the module file there ensures it is properly loaded and available for use in playbooks with the fully qualified collection name (FQCN).

Why this answer

Ansible collections have a defined structure where plugins, including modules, are stored under the plugins directory. Modules specifically go in plugins/modules. This structure allows Ansible to automatically discover and load the module when the collection is installed, making it available for use in playbooks via the collection's fully qualified name.

Exam trap

The trap here is confusing the collection plugin directory structure with the legacy library directory used for standalone playbook modules.

257
MCQmedium

An Ansible playbook is used to generate configuration files for network devices. The variables are defined in a vars file like: --- interfaces: - name: GigabitEthernet1 ip: 192.168.1.1/24 - name: GigabitEthernet2 ip: 10.0.0.1/24 The playbook uses a Jinja2 template to render the config. The template iterates over interfaces and writes "ip address" lines. However, the designer wants to support an additional field "secondary_ips" which is a list of IP addresses (e.g., ["192.168.2.1/24", "192.168.3.1/24"]). In the template, they want to generate multiple "ip address" lines for each interface, one for the primary IP and one for each secondary IP. The following template fragment is used: {% for iface in interfaces %} interface {{ iface.name }} ip address {{ iface.ip }} {% for sec in iface.secondary_ips|default([]) %} ip address {{ sec }} {% endfor %} {% endfor %} This works when secondary_ips is defined. However, some interfaces have secondary_ips defined as a string (e.g., "192.168.2.1/24") instead of a list. The playbook fails because the inner loop tries to iterate over a string. The engineer wants to normalize the data in the playbook before passing to the template, so that secondary_ips is always a list. Which of the following set_fact tasks will correctly transform the interfaces list to ensure secondary_ips is always a list (even if missing or a string)?

A.- set_fact: interfaces: "{{ interfaces | map('combine', {'secondary_ips': item.secondary_ips | default([]) | split(',') if item.secondary_ips is defined and item.secondary_ips is string else item.secondary_ips | default([])}) }}" loop: "{{ interfaces }}"
B.- set_fact: interfaces: "{{ interfaces | map('combine', {'secondary_ips': [item.secondary_ips | default('')] | flatten }) }}" loop: "{{ interfaces }}"
C.- set_fact: interfaces: "{{ interfaces | map('combine', {'secondary_ips': item.secondary_ips | default([]) | string | split(',') | list}) }}" loop: "{{ interfaces }}"
D.- set_fact: interfaces: "{{ interfaces | map('combine', {'secondary_ips': (item.secondary_ips is undefined or item.secondary_ips is none) | ternary([], (item.secondary_ips is string) | ternary(item.secondary_ips | split(','), item.secondary_ips))}) }}" loop: "{{ interfaces }}"
AnswerD

Correctly handles undefined, string, and list cases.

Why this answer

Ly uses the `ternary` filter to handle three cases: when `secondary_ips` is undefined or None (returns an empty list), when it is a string (splits it into a list), and when it is already a list (returns it unchanged). This ensures the template always receives a list for iteration, preventing the 'iteration over string' error.

Exam trap

The trap here is that candidates often try to use `default([])` or `split` without handling the case where the variable is already a list, leading to nested lists or string conversion errors, while the correct approach uses `ternary` to conditionally apply transformations based on the data type.

How to eliminate wrong answers

Option A is wrong because `split(',')` on a string like '192.168.2.1/24' would produce a list with one element, but the conditional logic is flawed: it uses `item.secondary_ips | default([]) | split(',')` which fails when `secondary_ips` is undefined (default returns an empty list, and `split` on a list causes an error). Option B is wrong because `[item.secondary_ips | default('')] | flatten` wraps a string in a list, but if `secondary_ips` is already a list, it nests it (e.g., `[['192.168.2.1/24']]`), and if undefined, it creates `['']` (a list with an empty string), both of which break the template. Option C is wrong because `| string` converts a list to a string representation (e.g., `['192.168.2.1/24']` becomes `['192.168.2.1/24']` as a string), then `split(',')` splits that string incorrectly, producing malformed IP entries.

258
MCQeasy

An administrator needs to provide a set of credentials to a job template that requires a machine credential for SSH and a source control credential for the project. What is the correct way to associate these credentials?

A.Define the source control token in the playbook using the 'set_fact' module
B.Create a single credential that includes both SSH key and source control token
C.Store the source control token as an extra variable in the job template
D.Assign both a machine credential and a source control credential to the job template
AnswerD

A job template accepts multiple credentials of different types simultaneously, so attaching both a machine credential for SSH and a source control credential for the project satisfies both authentication needs. Each credential type is matched to its corresponding function during job execution.

Why this answer

Ansible Tower/AWX allows multiple credentials of different types to be assigned to a single job template. A machine credential handles SSH authentication for target hosts, while a source control credential manages authentication for the project repository (e.g., Git). This separation follows Ansible's modular credential design, where each credential type serves a distinct purpose and can be independently managed.

Exam trap

The trap here is that candidates think a single credential must contain all authentication data, but Ansible Tower explicitly separates credential types by function, and a job template can accept multiple credentials of different types simultaneously.

How to eliminate wrong answers

Option A is wrong because the 'set_fact' module sets variables at runtime within a playbook, not credentials; source control tokens must be stored securely in a credential type, not hardcoded in playbooks. Option B is wrong because Ansible Tower does not support a single credential that combines SSH and source control tokens; credentials are typed (machine, source control, vault, etc.) and cannot be merged. Option C is wrong because extra variables are not designed for sensitive credentials; they are visible in job runs and logs, whereas source control tokens should be stored in a dedicated credential type with encryption.

259
MCQhard

A developer wants to reuse a set of tasks that conditionally include other task files based on variables defined per host. Which method should be used to ensure the included tasks are evaluated per host at runtime?

A.include_tasks
B.include_role
C.import_role
D.import_tasks
AnswerA

`include_tasks` is processed dynamically at runtime for each host, so conditional expressions and variables are evaluated per host as the play executes. This satisfies the requirement that included task files be selected based on host-specific variables, unlike static `import_tasks`, which resolves everything when the playbook is parsed.

Why this answer

Include_tasks, because it dynamically loads and evaluates task files at runtime, allowing conditional logic and per-host variables to be resolved when the tasks are executed. This is essential for reusing a set of tasks that conditionally include other task files based on variables defined per host, as include_tasks processes the included file fresh each time it is encountered, respecting any host-specific variable context.

Exam trap

The trap here is that candidates confuse static imports (import_tasks, import_role) with dynamic includes (include_tasks, include_role), not realizing that static imports are resolved at parse time and cannot handle per-host conditional logic at runtime.

How to eliminate wrong answers

Option B (include_role) is wrong because it dynamically includes an entire role at runtime, not a set of tasks that conditionally include other task files; it is designed for role reuse, not granular task file inclusion based on per-host variables. Option C (import_role) is wrong because it statically imports a role at playbook parse time, meaning all tasks and dependencies are pre-processed and cannot be conditionally evaluated per host at runtime. Option D (import_tasks) is wrong because it statically imports task files at parse time, so any conditional logic or variable-based inclusion is resolved before the playbook runs, preventing per-host runtime evaluation.

260
MCQeasy

An administrator manages a mixed fleet of Linux servers and Windows servers using Ansible Automation Platform. The Linux hosts are accessed via SSH keys, while the Windows hosts require WinRM with username and password. The administrator wants to define connection credentials in an inventory file so that playbooks can target both groups without specifying credentials in the playbook. Which inventory variable should be used to set the username for WinRM connections?

A.ansible_ssh_user
B.ansible_user
C.ansible_connection_user
D.ansible_winrm_user
AnswerB

ansible_user is the correct inventory variable to specify the username for a connection. For Windows hosts using WinRM, Ansible uses ansible_user to set the remote username, and ansible_password for the password. This allows the administrator to define credentials at the inventory level, such as in group_vars/windows.yml, without embedding them in playbooks.

Why this answer

The ansible_user inventory variable sets the remote username for all connection types, including WinRM. For Windows hosts, ansible_user and ansible_password are used with the winrm connection plugin. Defining these in group_vars ensures credentials are applied consistently without modifying playbooks.

Exam trap

The trap here is assuming that a WinRM-specific variable like ansible_winrm_user is required, when Ansible uses the generic ansible_user for all connection types.

261
Multi-Selecthard

An automation controller administrator must ensure that a job template handling credentials follows security best practices for both storage and execution. Which TWO actions should be taken in automation controller? (Choose two.)

Select 2 answers
A.Reference the credential from the job template so it is injected at runtime instead of hardcoding it in the playbook.
B.Enable the job template option to suppress Ansible output so sensitive data is not written to job logs.
C.Grant the operator system administrator role on the organization so they can manage all credentials centrally.
D.Store the SSH private key as a machine credential in automation controller rather than in a project repository.
E.Mark the job template as prompting for the credential on launch so operators supply secrets interactively.
AnswersA, D

Attaching the credential to the job template lets automation controller inject it into the execution environment at run time, removing hardcoded secrets from playbooks and inventories. This complements encrypted storage and ensures the value is only present transiently during the job, which is the intended best practice.

Why this answer

Automation controller stores credentials encrypted and injects them at run time, so keeping SSH keys in a machine credential and referencing that credential from the job template removes secrets from source control and from static inventories. Together these actions centralize secret storage and limit exposure to the moment of execution, which is the intended best practice.

Exam trap

The trap here is assuming that a job template option can globally hide Ansible output, when output masking is handled per task with no_log and controller's role is encrypted storage plus runtime injection.

262
MCQhard

A playbook must merge a base dictionary of defaults with an override dictionary, where the override may contain nested dictionaries that should be merged recursively rather than replaced. Which filter expression performs a recursive merge?

A.{{ base | combine(override) }}
B.{{ base | combine(override, recursive=True) }}
C.{{ base | combine(override, list_merge='keep') }}
D.{{ base | union(override) }}
AnswerB

The combine filter accepts a recursive parameter. Setting recursive=True merges nested dictionaries level by level instead of replacing them wholesale, preserving base subkeys while applying overrides. This matches the scenario where override contains nested dictionaries that must merge into the base structure rather than overwrite it entirely.

Why this answer

The combine filter merges dictionaries, and its recursive parameter controls whether nested dictionaries are merged deeply or replaced. For nested overrides that must preserve base subkeys, recursive=True is required. Parameters like list_merge affect list handling only and do not enable recursive dictionary merging.

Exam trap

The trap here is assuming combine always merges deeply, when by default it replaces nested dictionaries.

263
MCQeasy

An administrator wants to ensure a role's tasks are executed only on certain hosts. Which approach should they use?

A.Set host_vars for each target host
B.Set group_vars for the target group
C.Use a 'when' condition in the role's tasks
D.Use tags on the role
AnswerC

A 'when' condition evaluates host facts or variables at runtime, so tasks run only where the predicate is true. This satisfies the stem's constraint of restricting a role's tasks to certain hosts, though it filters per task rather than limiting which hosts the role targets.

Why this answer

Ansible's 'when' clause allows conditional execution of tasks based on variables such as inventory hostname, group membership, or custom facts. By using a 'when' condition that checks the target host's identity (e.g., 'ansible_hostname' or 'inventory_hostname'), the administrator can ensure that the role's tasks run only on specific hosts, without modifying inventory structure or using separate variable files.

Exam trap

The trap here is that candidates often confuse variable scoping (host_vars/group_vars) with conditional execution, assuming that setting variables for a host or group inherently limits task execution to those hosts, when in fact variables only provide data and do not control task flow without an explicit 'when' condition.

How to eliminate wrong answers

Option A is wrong because setting host_vars for each target host defines variables per host but does not control task execution; tasks will still run on all hosts unless a 'when' condition references those variables. Option B is wrong because group_vars define variables for all hosts in a group, but tasks will execute on every host in that group unless a 'when' condition is added; group_vars alone cannot restrict execution to a subset of hosts within the group. Option D is wrong because tags on a role are used to selectively include or exclude tasks during playbook runs via the '--tags' or '--skip-tags' options, but they do not enforce host-based restrictions; tags control which tasks run globally, not which hosts they run on.

264
Multi-Selectmedium

Which TWO statements about machine credentials in Ansible Tower are correct? (Choose two.)

Select 2 answers
A.Machine credentials can specify a 'become_method' for privilege escalation.
B.Machine credentials can use an SSH private key for authentication.
C.The SSH private key file automatically includes privilege escalation settings.
D.The username field is optional when using an SSH key.
E.SSH key credentials require a password field to be filled in.
AnswersA, B

Machine credentials in Ansible Tower store connection details for managed hosts, including privilege escalation settings. Specifying become_method lets the credential define how privilege escalation is performed, such as sudo or su, when running playbooks against those hosts.

Why this answer

Option A is correct because Ansible Tower machine credentials include a 'become_method' setting (e.g., sudo, su, pbrun, pfexec) that defines how privilege escalation is performed on the managed host. Option B is correct because machine credentials support SSH private key authentication, allowing Tower to connect to managed nodes without a password by supplying the key material. Option C is wrong because privilege escalation settings are configured as separate fields on the credential, not embedded in the SSH private key file itself.

Option D is wrong because the username field is required for machine credentials, even when an SSH key is used, so Tower knows which remote user to authenticate as. Option E is wrong because SSH key credentials do not require a password field; the password can be left blank when using key-based authentication.

Exam trap

The trap here is that candidates often assume the SSH private key file inherently includes privilege escalation settings, or that the username is optional when using SSH keys, but Ansible Tower strictly requires a username and treats privilege escalation as a separate configuration field.

265
MCQeasy

An administrator needs to securely store a database password used across multiple roles in a shared repository. Which approach is recommended?

A.Use ansible-vault to encrypt the password string and store it in a file, then include_vars.
B.Use a lookup plugin to fetch from a secrets manager.
C.Store the password in an environment variable on the controller.
D.Hardcode the password in the playbook and use .gitignore.
AnswerA

ansible-vault encrypts the password string at rest, and include_vars loads the decrypted variable into playbooks at runtime, so multiple roles in the shared repository reference one protected secret. This satisfies secure storage without exposing plaintext credentials in version control.

Why this answer

Ansible-vault encrypts sensitive data at rest using AES-256, and the encrypted file can be safely stored in a shared repository. The `include_vars` module then decrypts the file at runtime when the vault password is provided, allowing multiple roles to access the password without exposing it in plaintext.

Exam trap

The trap here is that candidates may confuse 'secure storage in a repository' with external secrets managers (Option B), but the question explicitly limits the context to a shared repository, making ansible-vault the correct built-in solution.

How to eliminate wrong answers

Option B is wrong because while a lookup plugin to fetch from a secrets manager is a valid approach, the question specifies a 'shared repository' (e.g., Git), not an external secrets management service; the recommended approach for repository-based storage is ansible-vault. Option C is wrong because storing the password in an environment variable on the controller is insecure—environment variables can be leaked via process listings, logs, or debugging tools, and they are not encrypted at rest. Option D is wrong because hardcoding the password in the playbook and using .gitignore does not prevent the password from being visible in the playbook file itself, and .gitignore only prevents accidental commits, not exposure to anyone with access to the file system.

266
MCQmedium

An organization's execution environment must include a custom RPM that is not in the default base image. How should this be added in the execution-environment.yml?

A.Add the RPM to the 'dependencies' section under 'system'.
B.Add the RPM to the 'dependencies' section under 'python'.
C.Use a 'prepended_base' directive.
D.Use a custom base image that includes the RPM.
AnswerA

The dependencies section's system subsection maps to dnf or microdnf package installation during the build, so listing the RPM there causes ansible-builder to install it into the final image. This satisfies the requirement that the custom RPM be present.

Why this answer

In an execution-environment.yml file, custom RPM packages that are not part of the default base image must be listed under the 'dependencies' section with the 'system' key. This instructs ansible-builder to install those RPMs using the system package manager (e.g., dnf or yum) during the build process, ensuring the execution environment includes the required system-level libraries or tools.

Exam trap

The trap here is that candidates often confuse the 'system' and 'python' dependency sections, mistakenly thinking RPMs can be added under 'python' because both are under 'dependencies', but 'python' is strictly for pip-installable packages.

How to eliminate wrong answers

Option B is wrong because the 'python' key under 'dependencies' is used for Python packages (e.g., pip install), not for RPM packages. Option C is wrong because there is no 'prepended_base' directive in execution-environment.yml; the correct way to modify the base image is through the 'base_image' field or by adding dependencies. Option D is wrong because while using a custom base image that includes the RPM is a valid approach, the question specifically asks how to add it in the execution-environment.yml file, and the correct method is to list it under 'dependencies: system' rather than building a separate custom base image.

267
MCQhard

An operations team is designing a rolling update for a stateful application that requires quorum (minimum 3 out of 5 nodes online). They plan to use Ansible's serial keyword. Which serial value ensures the update proceeds without breaking quorum while still being efficient?

A.serial: 2
B.serial: 1
C.serial: 3
D.serial: 5
AnswerA

Serial 2 updates two nodes at a time, leaving three of five online, which preserves the quorum minimum throughout the rolling update. Larger values risk dropping below three; serial 1 is safe but slower, so 2 balances safety with efficiency.

Why this answer

Setting serial: 2 ensures that only 2 nodes are taken down at a time during the rolling update. With a quorum requirement of 3 out of 5 nodes, taking down 2 nodes leaves 3 online, maintaining quorum. This is the most efficient value that does not risk breaking quorum.

Exam trap

The trap here is that candidates may confuse 'quorum' with 'majority' and incorrectly choose serial: 3, thinking that 3 out of 5 is a majority, but fail to realize that taking down 3 nodes leaves only 2 online, which is below the quorum threshold of 3.

How to eliminate wrong answers

Option B is wrong because serial: 1 would take down only 1 node at a time, which is safe but less efficient than serial: 2 since it increases the total update time. Option C is wrong because serial: 3 would take down 3 nodes at once, leaving only 2 online, which breaks the quorum requirement of 3 out of 5 nodes. Option D is wrong because serial: 5 would take down all 5 nodes simultaneously, completely breaking quorum and causing the application to fail.

268
MCQeasy

A junior administrator needs to create an encrypted Ansible Vault password file for use with ansible-playbook. The vault password must be stored in a file named vault_pass.txt in the current directory. Which command should the administrator run?

A.ansible-vault create vault_pass.txt
B.echo 'mysecretpassword' > vault_pass.txt
C.ansible-vault encrypt --vault-password-file vault_pass.txt
D.ansible-vault encrypt_string --vault-password-file vault_pass.txt
AnswerB

A vault password file is simply a plaintext file containing the password on the first line. Using echo to write the password to vault_pass.txt creates the required file. The file should be secured with appropriate permissions. This is the standard method to create a vault password file for non-interactive use with --vault-password-file.

Why this answer

A vault password file is a plaintext file that contains the vault password on its first line. It is created using standard file redirection or an editor, not with ansible-vault commands. This file is then referenced with --vault-password-file during playbook runs to decrypt vault-encrypted content non-interactively.

Exam trap

The trap here is confusing the creation of a vault password file with the creation of an encrypted file using ansible-vault, when the password file itself is plaintext and created with normal shell commands.

269
MCQhard

A playbook run against a Windows host fails at the connection stage with an authentication error, although the inventory specifies `ansible_user: Administrator` and the correct password. Which inventory variable must be set so that Ansible uses the password-based WinRM connection instead of trying Kerberos or certificate authentication?

A.ansible_winrm_transport: ntlm
B.ansible_become: true
C.ansible_ssh_pass: <password>
D.ansible_connection: winrm
AnswerA

On Windows, the `ansible_winrm_transport` inventory variable selects the authentication protocol used by the WinRM connection plugin. Setting it to `ntlm` forces basic NTLM authentication with the supplied user and password, avoiding Kerberos or certificate attempts. This directly addresses the authentication failure when a password is provided and the environment does not have Kerberos configured.

Why this answer

For Windows targets, authentication over WinRM is governed by `ansible_winrm_transport`. With a username and password and no Kerberos infrastructure, setting it to `ntlm` forces NTLM authentication and resolves the connection failure. Connection type, SSH password, and become settings do not select the WinRM authentication protocol.

Exam trap

The trap here is assuming that `ansible_connection: winrm` alone determines how Windows authentication happens, when the authentication protocol is actually chosen by a separate transport variable.

270
MCQhard

Refer to the exhibit. The playbook fails with an error about the package list. What is the issue?

A.The variable 'packages' is not accessible because it is defined in a vars_file.
B.The variable 'packages' is being converted to a string by the Jinja2 template, resulting in a list literal string.
C.The 'yum' module requires the 'name' parameter to be a comma-separated string, not a list.
D.The 'yum' module should use 'pkg' instead of 'name'.
AnswerB

Using "{{ packages }}" produces a string representation of the list. The correct approach is to use `name: "{{ item }}"` with a loop or pass the list directly without quotes.

Why this answer

The yum module expects a list of strings or a comma-separated string. The variable 'packages' is a list, but when used with 'name: "{{ packages }}"', Jinja2 converts it to a string representation like "['httpd', 'mariadb-server', 'php']". The yum module does not accept that format; it needs a proper list or comma-separated string.

271
MCQeasy

Refer to the exhibit. A playbook fails with the given error. What is the most likely cause?

A.The playbook syntax is wrong.
B.The vault password file is missing or incorrect.
C.The inventory file is encrypted.
D.The remote host is unreachable.
AnswerB

Ansible decrypts vaulted variables at runtime using the supplied vault password; if that file is absent or holds the wrong secret, decryption fails immediately, producing the exhibited vault error rather than a syntax or connectivity fault.

Why this answer

The error in the exhibit (typically 'Attempting to decrypt but no vault secrets found' or 'no vault password file') indicates Ansible cannot decrypt vault-encrypted content because the vault password file is missing, unreadable, or contains the wrong password. Ansible needs either --ask-vault-pass or --vault-password-file pointing to a valid file. If the file path is wrong or the password is incorrect, decryption fails before the play can run.

Exam trap

EX294 often tests the confusion between vault decryption errors and inventory/host connectivity errors, so candidates blame the inventory or SSH when the real issue is the vault password file.

How to eliminate wrong answers

Option A is wrong because a YAML syntax error produces a different message (e.g., 'Syntax Error while loading YAML') and would fail at parse time, not at vault decryption. Option C is wrong because an encrypted inventory file would produce a vault decryption error specifically tied to the inventory, but the exhibit's error is about vault secrets generally, and encrypting inventory is uncommon. Option D is wrong because an unreachable host produces 'UNREACHABLE' or SSH timeout errors, not a vault decryption failure.

272
MCQmedium

A playbook has a dictionary `config` that maps service names to ports. The team wants to iterate over both keys and values in a task. Which filter should be used to convert the dictionary into a list of key-value pairs?

A.dict2items
B.items2dict
C.flatten
D.json_query
AnswerA

The dict2items filter transforms a dictionary into a list of dictionaries, each containing key and value entries. Iterating that list exposes both service names and ports within the task, which is exactly what the playbook requires.

Why this answer

The `dict2items` filter is the correct choice because it converts a dictionary into a list of key-value pairs, each represented as a dictionary with `key` and `value` keys. This is the standard Ansible filter for iterating over both keys and values in a `loop` within a task, enabling access to `item.key` and `item.value`.

Exam trap

The trap here is that candidates often confuse `dict2items` with `items2dict` due to their similar names, or mistakenly think `flatten` or `json_query` can perform the conversion, when only `dict2items` is designed for this specific transformation.

How to eliminate wrong answers

Option B is wrong because `items2dict` performs the inverse operation, converting a list of key-value pairs back into a dictionary, not converting a dictionary into a list. Option C is wrong because `flatten` is used to reduce nested lists into a single flat list, not to transform dictionaries into key-value pair lists. Option D is wrong because `json_query` is a filter for querying JSON data using JMESPath expressions, not for converting dictionaries to a list of key-value pairs.

273
MCQhard

An administrator is deploying Ansible Automation Platform 2.4 with an external PostgreSQL database. The database administrator has created a database named `awx` and a user named `awx`, and has confirmed network connectivity from the AAP controller node to the database on port 5432. When the administrator runs the installer, the setup playbook fails during the database migration step with a permission error. Which configuration value is most likely missing or incorrect?

A.The AAP installer requires the database password to be stored in an Ansible Vault file referenced by `vault_password_file` in the inventory
B.The `postgresql.conf` file on the database server has `listen_addresses` set to `localhost` only
C.The `pg_hba.conf` on the database server does not permit the `awx` user to connect from the controller's IP address
D.The `awx` database was created with the `TEMPLATE template0` option instead of `TEMPLATE template1`
AnswerC

PostgreSQL uses `pg_hba.conf` to control which users may connect from which client addresses and with which authentication method. Even with a valid user and open port, a missing or restrictive host-based rule for the controller's address causes authentication or permission failures during migration. This is the classic cause when connectivity tests succeed but the installer's database operations fail.

Why this answer

When TCP connectivity to PostgreSQL is confirmed but the installer fails on database operations, the problem is almost always authorization. PostgreSQL's host-based authentication rules in `pg_hba.conf` determine whether the `awx` user may connect from the controller's address with the configured authentication method. Adding an appropriate host entry, then reloading PostgreSQL, resolves the migration failure.

Exam trap

The trap here is focusing on network reachability after it has already been proven, instead of checking PostgreSQL's host-based authentication rules that govern whether the user is allowed to connect.

274
MCQeasy

You need to run an Ansible playbook every hour to update a dynamic inventory file from a CMDB API. The playbook is stored in /opt/ansible/update_inventory.yml. You want to schedule the execution using a cron job on the control node. The control node runs Red Hat Enterprise Linux 9. The playbook uses Ansible Vault to decrypt API credentials, and the vault password is stored in /etc/ansible/.vault_pass. Which cron entry will execute the playbook hourly?

A.0 * * * * /usr/bin/ansible-playbook --vault-password-file ~/.vault_pass /opt/ansible/update_inventory.yml
B.* * * * * /usr/bin/ansible-playbook --vault-password-file /etc/ansible/.vault_pass /opt/ansible/update_inventory.yml
C.0 * * * * /usr/bin/ansible --vault-password-file /etc/ansible/.vault_pass /opt/ansible/update_inventory.yml
D.0 * * * * /usr/bin/ansible-playbook --vault-password-file /etc/ansible/.vault_pass /opt/ansible/update_inventory.yml
AnswerD

The cron field '0 * * * *' runs the job at minute zero of every hour, satisfying the hourly requirement. Supplying --vault-password-file lets ansible-playbook decrypt the API credentials non-interactively, which is essential because cron has no TTY for the vault prompt.

Why this answer

It specifies the correct cron schedule (0 * * * * for hourly), uses the correct command (ansible-playbook), and points to the correct vault password file (/etc/ansible/.vault_pass) as specified in the stem. Option A uses the wrong vault password file path (~/.vault_pass). Option B uses the wrong schedule (every minute).

Option C uses the wrong command (ansible instead of ansible-playbook).

275
MCQeasy

An administrator needs to execute a role named `common` on all hosts in the play, but only for hosts that are members of the `webservers` group. Which playbook construct achieves this?

A.Apply the role under a play with hosts: webservers.
B.Add a task with delegate_to: webservers before including the role.
C.Set a variable in group_vars/webservers.yml and use it in the role's tasks.
D.Use the roles keyword with a when condition on the group name.
AnswerA

Defining the play with hosts: webservers ensures the role only runs on hosts in that group. Roles applied in a play are executed on all hosts targeted by the play. This is the standard and simplest way to restrict role execution to a specific host group.

Why this answer

The most direct way to run a role only on a specific group is to target that group in the play's hosts directive. Roles run on all hosts in the play, so restricting the play's hosts restricts the role. Other options either do not filter hosts or misuse Ansible features.

Exam trap

The trap here is overcomplicating host targeting with conditions or variables when the play's hosts directive is the correct and simplest mechanism.

276
Multi-Selectmedium

An administrator is building a reusable role and must decide how to structure variables so that callers can override values while the role still ships sensible starting values. Which TWO practices are appropriate for this role design? (Choose two.)

Select 2 answers
A.Place values that must not be changed by callers in vars/main.yml so they outrank most other sources.
B.Store role variables in the inventory host file so each host can be tuned individually.
C.Place starting values in defaults/main.yml so they have low precedence and are easily overridden.
D.Require callers to pass every value as an extra variable with -e on the command line.
E.Define all role variables in the play's vars section so they are inherited by every role in the play.
AnswersA, C

Variables in vars/main.yml carry high precedence, above inventory and play variables, so they resist accidental overrides by callers. This makes them suitable for internal constants the role depends on, while still allowing extra variables or role parameters to take precedence when a deliberate change is required.

Why this answer

A well-designed role separates low-precedence starting values from high-precedence internal constants. Defaults give callers an easy override path, while vars/main.yml protects values the role must control. Play vars, inventory host data, and mandatory extra variables all bind the role to a specific context and undermine reuse.

Exam trap

The trap here is treating defaults and vars as interchangeable, when their precedence difference is what makes one overridable and the other protected.

277
Multi-Selectmedium

Which two actions are appropriate when configuring a custom execution environment for an automation controller job? (Choose two.)

Select 2 answers
A.Storing the execution environment in a public registry only
B.Building the execution environment using ansible-builder
C.Setting the execution_environment_image in the project's SCM
D.Using the default execution environment provided by controller
E.Creating a Containerfile with the required packages
AnswersB, E

ansible-builder reads an execution environment definition and produces the container image that automation controller pulls to run jobs. It satisfies the requirement for a custom execution environment by assembling dependencies into a runnable image, rather than relying on the default image.

Why this answer

Option B is correct because ansible-builder is the supported tool for creating custom execution environments; it reads an execution-environment.yml definition file and produces a container image containing the required collections, Python packages, and system dependencies. Option E is correct because the execution environment image is defined by a Containerfile (or Dockerfile) that specifies the base image and installs the needed packages, which ansible-builder uses as its build input. Option A is incorrect because execution environments can be stored in private registries (e.g., automation hub, private container registries), not only public ones, and public-only storage is not a requirement.

Option C is incorrect because execution_environment_image is configured on the job template or organization in the automation controller, not in the project's SCM repository. Option D is incorrect because using the default execution environment does not constitute configuring a custom execution environment, which is what the scenario requires.

Exam trap

The trap here is that candidates confuse the `execution_environment_image` field (set in the controller UI or API) with a setting in the project's SCM, or they assume that custom execution environments must always be stored in a public registry, ignoring private registry options.

278
MCQeasy

Which directory is the default location for installed Ansible collections on a control node for a regular user?

A.~/.ansible/collections
B./usr/share/ansible/collections
C./etc/ansible/collections
D./opt/ansible/collections
AnswerA

Ansible installs collections into `~/.ansible/collections` when a regular user runs `ansible-galaxy collection install`, satisfying the stem's non-root constraint. The system-wide path `/usr/share/ansible/collections` applies only to root installs, so the per-user default is the correct location here.

Why this answer

For a regular (non-root) user on an Ansible control node, the default location for installed collections is `~/.ansible/collections`. This is defined by Ansible's default collection search path, which includes the user's home directory under `~/.ansible/collections` for user-level installations. When a user runs `ansible-galaxy collection install` without specifying a custom path, the collection is placed in this directory by default.

Exam trap

The trap here is that candidates often confuse the system-wide default (`/usr/share/ansible/collections`) with the user-level default, forgetting that regular users lack write permissions to system directories and that Ansible defaults to the home directory for non-root installations.

How to eliminate wrong answers

Option B is wrong because `/usr/share/ansible/collections` is the default location for system-wide (root) collection installations, not for a regular user. Option C is wrong because `/etc/ansible/collections` is not a standard default path for collections; `/etc/ansible/` is typically used for configuration files like `ansible.cfg` and `hosts`, not collections. Option D is wrong because `/opt/ansible/collections` is not a default Ansible collection path; it might be used in custom setups but is not the default for any user level.

279
MCQmedium

A playbook registers the output of a command that returns a JSON string inside stdout. The string contains a top-level key 'services' with a nested list of dictionaries. You need to convert that string into native data so you can select only entries where the 'state' key equals 'running'. Which expression accomplishes this?

A.{{ (command_result.stdout | from_json).services | selectattr('state', 'equalto', 'running') | list }}
B.{{ command_result.stdout | from_json | selectattr('state', 'equalto', 'running') | list }}
C.{{ command_result.stdout | from_json | map(attribute='services') | selectattr('state', 'equalto', 'running') | list }}
D.{{ command_result.stdout | to_json | selectattr('state', 'equalto', 'running') | list }}
AnswerA

The from_json filter parses the stdout string into native data, then the '.services' lookup reaches the nested list. Applying selectattr to that list with equalto 'running' returns only matching dictionaries. The final list filter materializes a real list instead of a generator, which is important for templating and iteration.

Why this answer

Parsing the JSON string with from_json is required before any attribute-based filtering can occur. Once parsed, the nested list must be dereferenced through the 'services' key. Only then can selectattr compare each dictionary's 'state' value to 'running' and return the matching subset as a list.

Exam trap

The trap here is assuming selectattr can filter dictionaries nested under a key without first dereferencing that key in the expression.

280
Multi-Selectmedium

Which three methods can be used to pass variables to an Ansible playbook? (Select exactly 3.)

Select 3 answers
A.In the ansible.cfg file.
B.In the role's vars/main.yml.
C.In the playbook's vars_files directive.
D.In the inventory file variables.
E.Using the --extra-vars command line option.
AnswersC, D, E

vars_files includes YAML/JSON files with variables.

Why this answer

The `vars_files` directive in a playbook allows you to specify external YAML or JSON files containing variables, which are then merged into the play's variable scope at runtime. This is a standard method for passing variables to a playbook, as it separates variable definitions from the playbook logic.

Exam trap

The trap here is that candidates often confuse role-level variable files (like `vars/main.yml`) with playbook-level variable passing methods, or mistakenly think that `ansible.cfg` can hold variables, when in fact it only holds configuration directives.

281
MCQhard

An administrator deploys AAP 2.4 with an external PostgreSQL database. After the installation completes, the automation controller web UI is reachable, but jobs fail immediately with database connection errors. The administrator confirms the database host is reachable on port 5432 and the credentials in the inventory are correct. Which action should be taken to resolve the issue?

A.Change the database port in the inventory to 5433 and re-run the installer.
B.Open port 5432 in firewalld on the controller node.
C.Re-run setup.sh with the --force flag to regenerate the controller configuration.
D.Verify that the external database has been configured with the required extensions and that the pg_hba.conf allows connections from the controller node's IP address.
AnswerD

For an external database, PostgreSQL must have the necessary extensions (such as hstore and pg_trgm) and pg_hba.conf must permit the controller's IP with the correct authentication method. A reachable port alone does not guarantee authentication or extension availability, so these are the likely missing pieces.

Why this answer

When using an external PostgreSQL database with AAP, the database must be prepared with specific extensions and the pg_hba.conf must allow the controller host to authenticate. Port reachability and correct credentials in the inventory are necessary but not sufficient. The other options either target the wrong host, introduce an unrelated change, or re-run the installer without fixing the underlying database configuration.

Exam trap

The trap here is equating network reachability with database readiness, overlooking that extensions and pg_hba.conf rules are also required for an external PostgreSQL deployment.

282
MCQhard

A team develops an Ansible collection and wants to distribute it internally. They have a private Automation Hub. Which approach best ensures that collection dependencies from external sources are also available?

A.Manually install each dependency on the control node
B.Define a requirements.yml in the execution environment that references both the private hub and external sources
C.Include all dependencies directly in the collection's repository
D.Use ansible-galaxy collection download and then upload to private hub
AnswerB

A requirements.yml in the execution environment lists collections from both the private Automation Hub and external sources, so ansible-builder resolves and bundles every dependency. It satisfies the constraint that external dependencies remain available alongside internally distributed collections.

Why this answer

Defining a `requirements.yml` in the execution environment allows you to specify collections from both the private Automation Hub and external sources (e.g., Ansible Galaxy). When building the execution environment, `ansible-builder` processes this file and resolves dependencies from the listed sources, ensuring all required collections are bundled into the container image. This approach automates dependency management and avoids manual installation or repository bloat.

Exam trap

The trap here is that candidates often assume dependencies must be manually installed or bundled directly, missing the fact that `requirements.yml` in the execution environment context is the standard way to aggregate collections from multiple sources automatically.

How to eliminate wrong answers

Option A is wrong because manually installing each dependency on the control node is error-prone, not scalable, and does not ensure dependencies are available in the execution environment or to other team members. Option C is wrong because including all dependencies directly in the collection's repository violates best practices—collections should declare dependencies in `galaxy.yml` or `requirements.yml`, not bundle them, as this leads to repository bloat and version conflicts. Option D is wrong because `ansible-galaxy collection download` only downloads collections for offline use; uploading them to the private hub does not automatically resolve dependencies from external sources unless those dependencies are also downloaded and uploaded, which is not guaranteed by this approach.

283
MCQhard

A playbook uses the 'include_tasks' module to dynamically include tasks based on a variable. The playbook runs successfully on some hosts but fails on others with a 'template error' message. What is the most likely cause?

A.The included task file does not exist on the control node.
B.The variable used in the 'include_tasks' path has a Jinja2 template error.
C.The included task file has incorrect permissions.
D.The included tasks contain a syntax error.
AnswerB

A Jinja2 template error in the variable used to build the include_tasks path renders an invalid filename on some hosts, causing the failure. This satisfies the scenario where the same playbook succeeds elsewhere because that variable resolves cleanly.

Why this answer

The 'include_tasks' module dynamically resolves the path to a task file using a variable. If that variable contains a Jinja2 template error (e.g., undefined variable, syntax mistake, or filter misuse), Ansible will fail with a 'template error' message during the variable expansion phase, before the task file is even loaded. This explains why the error occurs only on hosts where the variable's value or context triggers the template failure.

Exam trap

The trap here is that candidates often confuse the source of the template error, assuming it comes from the content of the included tasks (option D) rather than from the variable used in the include path itself, which is evaluated before the included file is even accessed.

How to eliminate wrong answers

Option A is wrong because if the included task file does not exist on the control node, Ansible would produce a 'file not found' or 'could not find or access' error, not a 'template error'. Option C is wrong because file permissions on the control node affect whether Ansible can read the file, but a permissions issue would result in a 'permission denied' error, not a Jinja2 template error. Option D is wrong because a syntax error inside the included tasks would cause a playbook failure when those tasks are parsed or executed, but the error message would be a YAML or Ansible syntax error, not a 'template error' from the include path resolution.

284
MCQeasy

An administrator wants to update a web server fleet with minimal downtime. They need to update each server one at a time. Which Ansible playbook directive should be used?

A.throttle: 1
B.forks: 1
C.serial: 1
D.max_fail_percentage: 0
AnswerC

The serial directive controls how many hosts Ansible targets per batch. Setting serial: 1 processes each server individually, ensuring only one host is updated at a time, which satisfies the requirement for minimal downtime across the fleet.

Why this answer

The `serial: 1` directive in an Ansible playbook controls the batch size of hosts that are updated simultaneously. Setting it to 1 ensures that only one host is updated at a time, which minimizes downtime by allowing the rest of the fleet to remain available while each server is sequentially updated.

Exam trap

The trap here is that candidates often confuse `serial` with `forks` or `throttle`, mistakenly thinking that limiting parallel task execution (`forks: 1`) or task concurrency (`throttle: 1`) achieves the same one-at-a-time host update behavior, but only `serial` controls the batch size of hosts processed sequentially.

How to eliminate wrong answers

Option A is wrong because `throttle: 1` limits the number of concurrent tasks per host or per play, but it does not control the batch size of hosts being updated; it limits task concurrency, not the sequential update of hosts. Option B is wrong because `forks: 1` sets the number of parallel processes Ansible uses to execute tasks on hosts, but it still allows all hosts in the batch to be processed in parallel; it does not enforce a one-at-a-time update across the entire fleet. Option D is wrong because `max_fail_percentage: 0` defines the maximum percentage of hosts that can fail before the playbook aborts, but it does not control the order or batch size of updates; it is a failure threshold, not a sequencing mechanism.

285
MCQmedium

An Ansible role has a complex dependency tree. The administrator wants to ensure that dependencies are installed before the main role tasks. Which file should be used to define dependencies?

A.meta/main.yml
B.defaults/main.yml
C.tasks/main.yml
D.vars/main.yml
AnswerA

Dependencies declared in meta/main.yml are processed by Ansible before the role's tasks execute, guaranteeing prerequisite roles run first. This satisfies the constraint of ensuring dependencies install ahead of the main role in a complex dependency tree.

Why this answer

In Ansible, role dependencies are defined in the `meta/main.yml` file using the `dependencies` key. This ensures that any listed roles are executed before the main role's tasks, providing a controlled execution order. The `meta/main.yml` file is specifically designed for metadata such as dependencies, author information, and supported platforms.

Exam trap

The trap here is that candidates often confuse `meta/main.yml` with `tasks/main.yml` or `vars/main.yml`, mistakenly thinking dependencies can be defined in the same file as tasks or variables, when in fact only `meta/main.yml` supports the `dependencies` directive.

How to eliminate wrong answers

Option B is wrong because `defaults/main.yml` is used to define default variable values for the role, not dependencies. Option C is wrong because `tasks/main.yml` contains the main list of tasks to execute for the role, but it does not support dependency declarations. Option D is wrong because `vars/main.yml` is used to define variables with higher precedence than defaults, but it cannot define role dependencies.

286
MCQeasy

You are running an Ansible playbook with `serial: 2` to update a fleet of 6 web servers. The playbook includes a task that restarts the web service. After the first batch of 2 hosts is updated, you notice that both hosts are restarted simultaneously. You want to ensure that within each batch, the hosts are updated one at a time to avoid a temporary loss of capacity. Which Ansible keyword should you add to the play to achieve this?

A.`throttle: 1` on the restart task
B.`order: inventory` at the play level
C.`serial: 1` at the play level
D.`strategy: linear` at the play level
AnswerA

The `throttle` keyword limits the number of workers that can execute a task simultaneously. Setting `throttle: 1` on the restart task ensures that only one host in the batch restarts the service at a time, even though both hosts are in the same batch. This prevents simultaneous restarts and maintains capacity.

Why this answer

The `throttle` keyword limits the number of concurrent executions of a task across all hosts. By setting `throttle: 1` on the restart task, you ensure that only one host restarts the web service at a time, even within a batch of 2. This maintains the rolling update's goal of minimizing downtime while keeping the batch size efficient.

Exam trap

The trap here is thinking that `serial: 1` is the only way to serialize updates, or that `strategy: linear` serializes tasks. `serial` controls batch size, while `throttle` controls concurrency of individual tasks within those batches.

287
Multi-Selectmedium

You are preparing to publish a new version of a content collection to a private Automation Hub. The collection includes several roles and modules. Before publishing, you need to ensure the collection is properly built and packaged. Which two commands are required to build and publish the collection? (Choose two.)

Select 2 answers
A.ansible-galaxy collection build
B.ansible-galaxy collection install
C.ansible-galaxy collection publish
D.ansible-galaxy collection verify
E.ansible-galaxy collection init
AnswersA, C

The ansible-galaxy collection build command compiles the collection into a tarball (.tar.gz) that can be published. It reads the galaxy.yml file for metadata and packages all necessary files. This is a required step before publishing, as the Automation Hub expects a built collection artifact.

Why this answer

To publish a collection to Automation Hub, you first build it into a tarball using ansible-galaxy collection build, then publish that tarball using ansible-galaxy collection publish. These two commands form the standard build and publish workflow, ensuring the collection is packaged correctly and uploaded to the repository.

Exam trap

The trap here is confusing the publish workflow with installation or initialization commands, which serve different purposes in the collection lifecycle.

288
MCQhard

An OpenShift rolling update is failing because new pods crash immediately. Which parameter automatically triggers a rollback if no progress is made?

A.revisionHistoryLimit
B.maxSurge
C.progressDeadlineSeconds
D.maxUnavailable
E.minReadySeconds
AnswerC

If the deployment does not progress within this time, it is considered failed and rolls back.

Why this answer

The `progressDeadlineSeconds` parameter specifies the maximum duration (in seconds) that a deployment can make no progress before it is considered to have failed. When this deadline is exceeded, the deployment controller automatically triggers a rollback to the previous revision. This is the correct parameter for automatically rolling back a failed rolling update where new pods crash immediately.

Exam trap

The trap here is that candidates confuse `progressDeadlineSeconds` with `minReadySeconds`, thinking that a readiness check alone will trigger a rollback, but `minReadySeconds` only delays availability without initiating a rollback.

How to eliminate wrong answers

Option A is wrong because `revisionHistoryLimit` controls how many old ReplicaSets are retained for rollback, not the timing or automatic rollback trigger. Option B is wrong because `maxSurge` defines the maximum number of pods that can be created above the desired replica count during an update, not a rollback mechanism. Option D is wrong because `maxUnavailable` specifies the maximum number of pods that can be unavailable during the update process, not a progress deadline.

Option E is wrong because `minReadySeconds` determines how long a pod must be ready before it is considered available, but it does not trigger a rollback if no progress is made.

289
Multi-Selectmedium

An administrator needs to update a web application that runs as a Kubernetes Deployment with 5 replicas. The application is stateless, but the update must not cause any downtime. Which TWO strategies ensure zero-downtime rolling updates?

Select 2 answers
A.Omit the liveness probe from the pod spec.
B.Set strategy type to RollingUpdate with maxUnavailable=0 and maxSurge=1.
C.Set maxUnavailable=1 and maxSurge=0.
D.Use the Recreate strategy.
E.Configure a readiness probe that checks the application's health endpoint.
AnswersB, E

maxUnavailable=0 guarantees all five existing pods stay ready during the rollout, while maxSurge=1 allows one extra pod to be created first. New pods must pass readiness before old ones terminate, preserving continuous availability throughout the update.

Why this answer

Option B is correct because a RollingUpdate strategy with maxUnavailable=0 and maxSurge=1 guarantees that no existing pod is terminated until a new pod is fully available, so the Deployment always keeps all 5 replicas serving traffic during the update. Option E is correct because a readiness probe tied to the application's health endpoint ensures Kubernetes only routes traffic to new pods once they are actually ready, preventing requests from hitting uninitialized instances during the rollout. Together, maxUnavailable=0/maxSurge=1 plus a readiness probe are the standard mechanism for zero-downtime updates of a stateless Deployment.

Option A is wrong because omitting a liveness probe does not prevent downtime and removes Kubernetes' ability to restart unhealthy containers. Option C is wrong because maxUnavailable=1 allows a pod to be taken out of service before its replacement is ready, reducing capacity and risking dropped requests. Option D is wrong because the Recreate strategy terminates all existing pods before creating new ones, causing guaranteed downtime.

Exam trap

The trap here is that candidates often confuse `maxUnavailable` and `maxSurge` values, mistakenly thinking that allowing one unavailable pod (maxUnavailable=1) is acceptable for zero-downtime, when in fact it can cause a temporary capacity deficit if the readiness probe is not fast enough.

290
Multi-Selectmedium

Which TWO statements are true about deploying Red Hat Ansible Automation Platform using the automation mesh?

Select 2 answers
A.Execution nodes can be located in different geographic regions.
B.Existing Ansible Tower nodes can be added to the mesh without modification.
C.Automation mesh requires two separate ports for control and data plane traffic.
D.The mesh topology is organized as a parent/child relationship between nodes.
E.All execution nodes must have direct network access to the automation controller.
AnswersA, D

Execution nodes in an automation mesh can span distinct geographic regions, since the mesh replaces the single-hop SSH model with peer-to-peer overlay routing between nodes. This satisfies the stem's requirement for distributed, resilient deployment, allowing execution capacity to sit close to managed hosts across regions without a central hop.

Why this answer

Option A is correct because automation mesh is designed to span distributed environments, allowing execution nodes to be placed in different geographic regions and connected through hop nodes or peer relationships rather than requiring a single data center. Option D is correct because automation mesh uses a hierarchical topology in which nodes are organized as parent and child, with control and execution nodes communicating through defined parent/child links. Option B is incorrect because existing Ansible Tower nodes cannot simply be added unchanged; they must be upgraded/reconfigured to run receptor and mesh components.

Option C is incorrect because automation mesh does not require two separate ports for control and data plane traffic; it uses a single TCP port, typically 27199, for receptor traffic. Option E is incorrect because execution nodes do not need direct network access to the automation controller; they can communicate through intermediate hop nodes in the mesh.

Exam trap

The trap here is that candidates often assume automation mesh requires separate control and data ports (like in some SDN solutions) or that all nodes must reach the controller directly, but Red Hat's implementation uses a single port and a peer-to-peer routing model.

291
MCQmedium

A developer wants to create a new collection named 'myutils' under namespace 'myorg'. Which command initializes the collection structure?

A.ansible-galaxy collection scaffold myorg.myutils
B.ansible-galaxy collection create myorg.myutils
C.ansible-galaxy collection new myorg.myutils
D.ansible-galaxy collection init myorg.myutils
AnswerD

`ansible-galaxy collection init myorg.myutils` scaffolds the namespace/collection directory tree, generating `galaxy.yml`, `README.md`, `plugins/`, `roles/` and `docs/` under `myorg/myutils/`. The `init` subcommand is the only one that creates this skeleton, satisfying the stem's requirement to initialise the collection structure rather than build or install it.

Why this answer

The correct command to initialize a new Ansible collection structure is `ansible-galaxy collection init <namespace.collection>`. This creates the required directory layout, including `galaxy.yml`, `README.md`, and subdirectories like `roles/`, `playbooks/`, and `plugins/`. Option D matches this syntax exactly.

Exam trap

The trap here is that candidates confuse role scaffolding commands (`ansible-galaxy init` or `ansible-galaxy role init`) with collection initialization, and mistakenly apply verbs like `scaffold`, `create`, or `new` which are not valid for collections.

How to eliminate wrong answers

Option A is wrong because `ansible-galaxy collection scaffold` is not a valid subcommand; `scaffold` is used for roles, not collections. Option B is wrong because `ansible-galaxy collection create` is not a valid subcommand; the correct verb is `init`. Option C is wrong because `ansible-galaxy collection new` is not a valid subcommand; `new` is used for roles, not collections.

292
Multi-Selecteasy

Which TWO actions are required to use a private Automation Hub to share collections?

Select 2 answers
A.Configure the server in ansible.cfg under [galaxy] server_list.
B.Build a custom execution environment that includes the collections.
C.Run ansible-galaxy collection install --ignore-certs if using self-signed certs.
D.Use ansible-navigator with --pull-policy missing.
E.Create an API token and store it in ansible.cfg or environment variable.
AnswersA, E

Listing the private Automation Hub under `[galaxy] server_list` in `ansible.cfg` directs the `ansible-galaxy` client to resolve and download collections from that server rather than the public Galaxy endpoint, satisfying the stem's requirement to share collections through a private hub.

Why this answer

Option A is correct because to make the ansible-galaxy client talk to a private Automation Hub instead of the default galaxy.ansible.com, you must list that server under the [galaxy] server_list setting in ansible.cfg (or via the ANSIBLE_GALAXY_SERVER_LIST environment variable), which defines the server name and URL used for collection operations. Option E is correct because private Automation Hub requires authentication for publishing and often for downloading collections, so you must generate an API token in the Automation Hub UI and supply it via the token key under the server's section in ansible.cfg or through the corresponding environment variable (e.g., ANSIBLE_GALAXY_SERVER_<name>_TOKEN). Option B is not required because building a custom execution environment is an optional packaging/distribution approach, not a prerequisite for the client to share collections with a private hub.

Option C is not required because --ignore-certs is only a workaround for certificate validation failures with self-signed certificates and is not part of the standard configuration for using a private Automation Hub. Option D is not required because --pull-policy missing is an ansible-navigator execution-environment behavior and has nothing to do with configuring a private Automation Hub as a collection source.

Exam trap

The trap here is that candidates confuse optional steps (like building execution environments or ignoring certs) with required actions, or they overlook that both server configuration and API token authentication are mandatory for accessing a private Automation Hub.

293
MCQhard

During a collection development, a developer wants to include a Python dependency that is not available in the base image of the execution environment. Where should this dependency be declared?

A.In the execution-environment.yml under 'dependencies' -> 'python'
B.In the collection's requirements.yml under 'python'
C.In the collection's galaxy.yml under 'dependencies'
D.In the collection's meta/runtime.yml under 'python_dependencies'
AnswerA

Declaring the dependency under `dependencies` → `python` in `execution-environment.yml` instructs ansible-builder to install it into the execution environment image via pip during the build, satisfying the stem's constraint that the package is absent from the base image.

Why this answer

In Ansible execution environments, Python dependencies that are not part of the base image must be declared in the `execution-environment.yml` file under the `dependencies` key, specifically within the `python` subkey. This file is used by `ansible-builder` to build a custom container image that includes those additional Python packages. The base image already contains a standard set of Python libraries, but any extra ones needed by a collection must be explicitly listed here to be installed during the build process.

Exam trap

Red Hat often tests the distinction between files used for building execution environments (`execution-environment.yml`) versus files used for publishing or runtime metadata (`galaxy.yml`, `meta/runtime.yml`), causing candidates to confuse where Python dependencies should be declared.

How to eliminate wrong answers

Option B is wrong because `requirements.yml` is used for Ansible collections or roles, not for Python dependencies; it does not support a `python` key for pip packages. Option C is wrong because `galaxy.yml` is a metadata file for publishing collections to Ansible Galaxy, not for declaring runtime dependencies for execution environments. Option D is wrong because `meta/runtime.yml` defines Ansible runtime behavior like action groups or module deprecations, not Python package dependencies.

294
MCQeasy

A user wants to build an execution environment from a definition file. Which command is used?

A.ansible-playbook build -i ee.yml
B.ansible-builder build -f execution-environment.yml
C.ansible-execution-environment build -f ee.yml
D.ansible-galaxy build execution-environment.yml
AnswerB

The ansible-builder CLI is the supported tool for turning an execution-environment definition file into a container image. The build subcommand reads the YAML definition via -f, resolving collections and Python dependencies, then produces the image Ansible Automation Platform uses to run playbooks.

Why this answer

The `ansible-builder build` command is the correct tool for building an Ansible execution environment from a a definition file. The `-f` flag specifies the path to the `execution-environment.yml` file, which defines the base image, required collections, and system dependencies for the containerized environment.

Exam trap

The trap here is that candidates confuse `ansible-builder` with `ansible-galaxy` or `ansible-playbook`, mistakenly thinking that building an execution environment uses the same command as building a collection or running a playbook.

How to eliminate wrong answers

Option A is wrong because `ansible-playbook` is used to run playbooks, not to build execution environments; there is no `build` subcommand for `ansible-playbook`. Option C is wrong because `ansible-execution-environment` is not a valid Ansible command; the correct command is `ansible-builder`. Option D is wrong because `ansible-galaxy build` is used to build a collection from a `galaxy.yml` file, not an execution environment from an `execution-environment.yml` file.

295
MCQmedium

Refer to the exhibit. What is the most likely cause of the job being in 'pending' state?

A.The job is queued because the capacity limit of the automation controller is reached.
B.The credential is invalid and the system is attempting to validate it.
C.The job template is configured with a survey that requires approval.
D.The project needs to be updated before the job can run.
AnswerA

Reaching the automation controller's capacity limit caps concurrent job execution, so the task queues in 'pending' until a running job finishes and frees a slot. This matches the stem's constraint: the exhibit shows no execution errors, only a job awaiting available capacity rather than failing outright.

Why this answer

In Ansible Automation Platform, when a job is in 'pending' state, it typically indicates that the automation controller has queued the job because the maximum number of concurrent jobs (capacity limit) has been reached. The controller uses a job fork limit and instance group capacity to determine how many jobs can run simultaneously; once that limit is hit, additional jobs are placed in a pending queue until capacity frees up.

Exam trap

Red Hat often tests the distinction between 'pending' (capacity queue) and 'awaiting approval' (survey or workflow approval), so candidates mistakenly choose the survey option when they see a job not starting immediately.

How to eliminate wrong answers

Option B is wrong because an invalid credential would cause the job to fail immediately with an authentication error, not remain in a pending state; the system does not retry validation indefinitely. Option C is wrong because a survey requiring approval would place the job in an 'awaiting approval' state, not 'pending'; approval is a separate workflow step before the job is even queued. Option D is wrong because a project update is a prerequisite for launching a job template, but if the project is outdated, the job would either fail or prompt an update, not sit in pending; pending specifically relates to capacity, not project sync status.

296
Multi-Selecthard

Which THREE statements correctly describe the behavior of the 'serial' keyword in Ansible? (Choose exactly three.)

Select 3 answers
A.It can be set as a percentage of the total hosts.
B.It causes the playbook to run on a subset of hosts at a time.
C.It can be combined with max_fail_percentage to control failure thresholds.
D.It guarantees that only one task runs across all hosts at any time.
E.It applies globally to all plays in the playbook.
AnswersA, B, C

Ansible accepts serial as an integer or a percentage, so specifying 25% runs the play across a quarter of the matched hosts per batch. This satisfies the stem's requirement for a statement describing serial's percentage-based behaviour, distinct from fixed host counts.

Why this answer

Option A is correct because the serial keyword accepts a percentage value (e.g., serial: 25%) that Ansible interprets as a fraction of the total hosts in the play, batching them accordingly. Option B is correct because serial defines the number of hosts (or batch size) that Ansible targets per play iteration, so the play runs on a subset of hosts at a time rather than all at once. Option C is correct because serial is commonly paired with max_fail_percentage, which aborts the play if failures within a serial batch exceed the given threshold, enabling controlled rolling updates.

Option D is incorrect because serial controls host batching, not task concurrency; it does not guarantee only one task runs across all hosts at any time. Option E is incorrect because serial is set at the play level and applies only to that specific play, not globally to all plays in a playbook.

Exam trap

The trap here is that candidates often confuse 'serial' with a task-level concurrency control or assume it applies globally across all plays, when in fact it is a per-play batch size setting that controls how many hosts execute the entire play simultaneously.

297
MCQhard

A role's tasks/main.yml contains a task that uses `notify: restart service`. The handler is defined in handlers/main.yml. During a playbook run, the task reports 'changed' but the handler does not run until the end of the play. The administrator wants the handler to run immediately after the task, before any subsequent tasks. Which action should be taken?

A.Change the handler to use listen: restart service and set run_once: true.
B.Set force_handlers: true in the play and use serial: 1.
C.Move the handler definition into the same tasks/main.yml file and rename it.
D.Add a task using meta: flush_handlers immediately after the notifying task.
AnswerD

Handlers run at the end of each play by default, or when explicitly flushed. Inserting a meta: flush_handlers task right after the notifying task forces all pending handlers to execute at that point, before any later tasks. This fulfills the requirement to run the handler immediately after the task that notified it.

Why this answer

Handlers by default execute at the end of the play after all tasks complete. To run them earlier, a meta: flush_handlers task must be inserted at the desired point. Other options either change failure behavior, batching, or definition location, none of which alter the execution timing of handlers.

Exam trap

The trap here is thinking that handler options like run_once or force_handlers change when handlers execute, but only explicit flushing or play end triggers them.

298
MCQmedium

Your organization is migrating from manually maintained control nodes to using execution environments. You have created an execution environment that includes all necessary collections and Python dependencies. You want to ensure that developers use this execution environment when running playbooks. You have configured ansible-navigator on their workstations. However, some developers report that when they run a playbook, it uses the local installation of Ansible instead of the execution environment. What should you check first?

A.Confirm that the developers have installed ansible-builder locally.
B.Ensure that the developers are using the 'ansible-navigator run' command instead of 'ansible-playbook'.
C.Verify that the ansible-navigator configuration file points to the correct execution environment image.
D.Check that the execution environment container is running on the developers' machines.
AnswerB

ansible-navigator run executes playbooks inside the configured execution environment, whereas ansible-playbook uses the locally installed Ansible. Verifying the command used directly addresses the reported behaviour of falling back to local Ansible despite correct navigator configuration.

Why this answer

`ansible-navigator` is the CLI tool designed to run Ansible inside an execution environment. If developers run `ansible-playbook` directly, it uses the locally installed Ansible, bypassing the execution environment entirely. The question states that `ansible-navigator` is configured on their workstations, but the developers must use the `ansible-navigator run` subcommand to invoke playbooks within the containerized environment.

Exam trap

The trap here is that candidates often focus on configuration details (like the image path in the config file) or container status, missing the fundamental point that the command itself (`ansible-playbook` vs `ansible-navigator run`) determines whether the execution environment is used.

How to eliminate wrong answers

Option A is wrong because `ansible-builder` is used to build execution environment images, not to run playbooks; its absence does not affect whether a playbook runs locally or in an execution environment. Option C is wrong because while the configuration file pointing to the correct image is important, the primary issue is that developers are using the wrong command (`ansible-playbook`), which ignores the execution environment entirely regardless of the configuration. Option D is wrong because the execution environment container does not need to be running continuously; `ansible-navigator run` pulls and starts the container on demand, so checking if it is running is irrelevant to the reported problem.

299
Multi-Selectmedium

Which TWO statements about Ansible collections are correct?

Select 2 answers
A.Collections cannot be versioned.
B.Collections provide a way to package and distribute Ansible content.
C.Collections replace the need for inventory files.
D.Collections can only contain modules and roles.
E.Collections can be published to Ansible Galaxy or Automation Hub.
AnswersB, E

Collections bundle roles, modules, plugins and playbooks into a single distributable unit, replacing the older role-only packaging model. This packaging capability directly satisfies the stem's requirement that collections distribute Ansible content in a portable, versioned form.

Why this answer

Option B is correct because Ansible collections are the standard packaging format for distributing Ansible content, bundling modules, roles, plugins, playbooks, and documentation into a single installable unit that can be shared via namespaces. Option E is correct because collections can be published to and installed from public Ansible Galaxy or Red Hat Automation Hub (and private Automation Hub), typically using commands like 'ansible-galaxy collection install' with a namespace.collection name. Option A is incorrect because collections are versioned using semantic versioning (e.g., 1.2.0) in their galaxy.yml and requirements files.

Option C is incorrect because inventory files define managed hosts and remain necessary; collections do not replace them. Option D is incorrect because collections can contain many content types beyond modules and roles, including plugins, module utilities, and documentation.

Exam trap

Red Hat often tests the misconception that collections are limited to modules and roles, but the trap here is that collections can also include plugins, playbooks, and documentation, making option D a common distractor.

300
MCQeasy

A playbook needs to set a fact 'total_memory' by summing the 'memory_mb' values from a list of servers. Which filter should be used?

A.{{ servers | map(attribute='memory_mb') | sum }}
B.{{ servers | map('memory_mb') | sum }}
C.{{ servers | sum }}
D.{{ servers | sum(attribute='memory_mb') }}
AnswerA

The `map` filter extracts the `memory_mb` attribute from each server dictionary, producing a list of integers, which `sum` then totals into `total_memory`. This satisfies the stem's requirement to aggregate values across a list without a loop, using Jinja2 filters natively supported in Ansible playbooks.

Why this answer

It uses the `map` filter with the `attribute` parameter to extract the `memory_mb` value from each dictionary in the list, then pipes the resulting list of integers into the `sum` filter to compute the total. This is the standard Ansible idiom for summing a specific attribute across a list of dictionaries.

Exam trap

The trap here is that candidates confuse the `map` filter's `attribute` parameter with a direct filter name argument, leading them to choose option B, or they incorrectly assume `sum` can accept an `attribute` parameter like some other filters do.

How to eliminate wrong answers

Option B is wrong because `map('memory_mb')` attempts to call a filter named `memory_mb`, which does not exist; the correct syntax requires the `attribute` keyword to extract a dictionary key. Option C is wrong because `servers | sum` tries to sum the list objects themselves, which are dictionaries, not numbers, causing an error or incorrect result. Option D is wrong because the `sum` filter does not accept an `attribute` parameter; that parameter belongs to `map`, not `sum`.

Page 3

Page 4 of 6

Page 5

All pages