EX294 Deploy Ansible Automation Platform Practice Question
An admin needs to restrict which users can launch specific job templates. Which AAP feature should be used?
⚠ Common exam trap
Candidates often confuse operational features (like execution environments or credentials) with access control mechanisms, assuming that restricting execution environments or credentials indirectly controls user access, when AAP explicitly uses RBAC for granular user permissions on job templates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based access control (RBAC) on job templates.
Role-based access control (RBAC) on job templates is the correct feature because it allows an administrator to assign specific permissions (e.g., execute, read, or admin) to users or teams for individual job templates in Ansible Automation Platform (AAP). This directly restricts which users can launch specific job templates without affecting other resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Execution environments with custom modules.
Why it's wrong here
Execution environments define container images and dependencies for running playbooks; they carry no user or team permission model, so they cannot restrict who launches a template. They are tempting because they govern what runs, and are the right choice when jobs need isolated Python or collection versions.
- ✗
Machine credentials with different users.
Why it's wrong here
Machine credentials supply the SSH or privilege-escalation identity a job uses to reach managed hosts; they do not determine which human user may launch a template. They are tempting because credentials gate execution, but the correct control is RBAC roles assigned on the job template.
- ✗
Inventory groups with host restrictions.
Why it's wrong here
Inventory groups organise hosts and can scope credentials or variables, but they do not grant or deny a user the right to launch a job template. They are tempting because grouping feels like access control, yet launch permission is enforced through role-based access control on the template object itself.
- ✓
Role-based access control (RBAC) on job templates.
Why this is correct
RBAC on job templates grants or denies execute permission to named users or teams, directly satisfying the requirement to restrict who can launch specific templates. Unlike organisation-wide roles, template-level role assignments scope access per template, so only explicitly authorised principals can run it.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.