An administrator is designing a rolling update playbook for a 20-node application cluster. The playbook must limit the blast radius of failures and allow the rollout to pause safely if too many hosts fail. Which two Ansible play-level keywords directly control how many hosts are updated at once and whether the play aborts based on failures? (Choose two.)
serial defines the number or percentage of hosts processed per batch during a rolling update. In this scenario it directly controls how many of the 20 nodes are updated at one time, limiting the blast radius and ensuring the play progresses in controlled groups rather than all at once.
Why this answer
serial controls how many hosts are processed in each rolling batch, directly limiting the blast radius. max_fail_percentage defines the failure threshold per batch that aborts the play, preventing the rollout from continuing when too many hosts fail. Together they provide the two controls the administrator needs for a safe rolling update.
Exam trap
The trap here is confusing parallelism controls like forks with rolling-update controls like serial and max_fail_percentage.