EX294 Practice Question: Credential precedence over inventory variables
Exhibit
Refer to the exhibit. ``` [webservers] web1 ansible_host=192.168.1.10 web2 ansible_host=192.168.1.11 [webservers:vars] ansible_user=admin ansible_ssh_private_key_file=/home/admin/.ssh/id_rsa ```
An admin imports this inventory into AAP and assigns a machine credential that uses SSH key authentication. The job fails with 'Authentication failed'. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The machine credential does not contain an SSH private key.
In Red Hat Ansible Automation Platform (AAP), when a machine credential is assigned to a host, that credential's SSH key is used for authentication. If the credential does not contain an SSH private key, authentication will fail. Credentials take precedence over inventory variables such as ansible_ssh_private_key_file, so a conflict is not the likely cause. Therefore, the most likely cause is that the machine credential is missing its SSH private key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The private key file path in the inventory does not exist on the controller.
Why it's wrong here
SSH key authentication in AAP uses the machine credential's stored private key, not a path declared in the inventory, so a missing inventory path cannot cause this failure. The inventory path field is tempting because inventories can carry host variables, and it would matter only if the connection plugin read a key from that variable.
- ✗
The credential's SSH key is not being used because the inventory variable ansible_ssh_private_key_file conflicts.
Why it's wrong here
An inventory variable does not override a machine credential's SSH key; AAP injects the credential's key at job runtime, so the conflict described cannot occur. The variable is intended for ad-hoc CLI runs where no credential exists, making it tempting when diagnosing key-path errors.
- ✓
The machine credential does not contain an SSH private key.
Why this is correct
SSH key authentication requires the machine credential to hold the private key matching the public key on the managed host. Without that private key stored in the credential, Ansible cannot authenticate, producing the 'Authentication failed' error.
- ✗
The 'ansible_become' variable is missing from the inventory.
Why it's wrong here
ansible_become governs privilege escalation after login, not SSH authentication, so its absence cannot produce 'Authentication failed'. It is tempting because become errors also abort jobs, but those surface as permission-denied during task execution, not connection-level authentication failure.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.