Courseiva

EX294 Deploy Ansible Automation Platform Practice Question

An admin needs to restrict which users can launch specific job templates. Which AAP feature should be used?

⚠ Common exam trap

Candidates often confuse operational features (like execution environments or credentials) with access control mechanisms, assuming that restricting execution environments or credentials indirectly controls user access, when AAP explicitly uses RBAC for granular user permissions on job templates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-based access control (RBAC) on job templates.

Role-based access control (RBAC) on job templates is the correct feature because it allows an administrator to assign specific permissions (e.g., execute, read, or admin) to users or teams for individual job templates in Ansible Automation Platform (AAP). This directly restricts which users can launch specific job templates without affecting other resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Execution environments with custom modules.

    Why it's wrong here

    Execution environments define container images and dependencies for running playbooks; they carry no user or team permission model, so they cannot restrict who launches a template. They are tempting because they govern what runs, and are the right choice when jobs need isolated Python or collection versions.

  • ✗

    Machine credentials with different users.

    Why it's wrong here

    Machine credentials supply the SSH or privilege-escalation identity a job uses to reach managed hosts; they do not determine which human user may launch a template. They are tempting because credentials gate execution, but the correct control is RBAC roles assigned on the job template.

  • ✗

    Inventory groups with host restrictions.

    Why it's wrong here

    Inventory groups organise hosts and can scope credentials or variables, but they do not grant or deny a user the right to launch a job template. They are tempting because grouping feels like access control, yet launch permission is enforced through role-based access control on the template object itself.

  • ✓

    Role-based access control (RBAC) on job templates.

    Why this is correct

    RBAC on job templates grants or denies execute permission to named users or teams, directly satisfying the requirement to restrict who can launch specific templates. Unlike organisation-wide roles, template-level role assignments scope access per template, so only explicitly authorised principals can run it.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.