Courseiva

EX294 Deploy Ansible Automation Platform Practice Question

An administrator is configuring a new Red Hat Ansible Automation Platform 2.5 installation and must connect the automation controller to a private automation hub so that certified and validated collections can be pulled during project syncs. The administrator wants the controller to authenticate to the hub and resolve collections automatically. Which TWO actions should the administrator take to accomplish this? (Choose two.)

⚠ Common exam trap

The trap here is assuming that editing ansible.cfg on execution nodes or sideloading collections replaces the controller's own Galaxy server and credential configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the organization's Galaxy credential to the created hub credential and add the hub to the list of enabled Galaxy servers.

Connecting the controller to private automation hub requires a Galaxy/Automation Hub API Token credential holding the hub URL and token, plus assigning that credential to the organization and enabling the hub as a Galaxy server. Together these let project syncs authenticate and download certified or validated collections automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the organization's Galaxy credential to the created hub credential and add the hub to the list of enabled Galaxy servers.

    Why this is correct

    The controller resolves collections from the Galaxy servers configured for an organization. Assigning the hub credential to the organization and enabling the private hub as a Galaxy server ensures project syncs pull collections from the private hub using the stored token, completing the authenticated connection the administrator requires.

  • ✗

    Edit ansible.cfg on each execution node to add the private hub URL under the [galaxy_server] sections with a plaintext token.

    Why it's wrong here

    Execution nodes run jobs but do not perform project syncs that fetch collections. Placing tokens in ansible.cfg on each node exposes secrets and bypasses the controller's credential management. The controller handles collection resolution for projects, so configuring execution nodes this way neither connects the controller to the hub nor secures the token.

  • ✓

    Create a credential of type Ansible Galaxy/Automation Hub API Token in the controller and reference the hub URL and token.

    Why this is correct

    This credential type stores the automation hub server URL and an API token. Assigning it to an organization or project lets the controller authenticate to the hub and download collections during project syncs, which is exactly the mechanism that connects the controller to private automation hub content without embedding secrets in playbooks.

  • ✗

    Configure a webhook on the private automation hub that pushes collection metadata into the controller database on every change.

    Why it's wrong here

    Automation hub does not push metadata into the controller database through webhooks, and the controller does not accept such inbound writes. Collection resolution happens when the controller pulls from configured Galaxy servers during a project sync. This option describes a mechanism that does not exist in the platform, so it cannot satisfy the requirement.

  • ✗

    Publish the collections to the controller's local filesystem under /var/lib/awx/projects/collections and reference them with a relative path.

    Why it's wrong here

    Copying collections onto the controller filesystem does not use the private automation hub and defeats the purpose of centralized content management. Project syncs would not authenticate to the hub, version updates would not propagate, and the manual copy is unsupported. The requirement is to connect the controller to the hub, not to sideload content.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.