EX294 Manage automation security and operations Practice Question
An administrator is migrating playbooks to use execution environments in automation controller. They want to ensure that all playbook runs use a custom execution environment that includes the necessary Python libraries and is signed to comply with security policy. What should the administrator do?
⚠ Common exam trap
Many exam-takers think they can install Python libraries dynamically via a playbook (Option C) or use a project-level definition (Option D), but the exam tests the understanding that execution environments are immutable container images built externally and referenced by registry path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Build the execution environment using ansible-builder and then push it to a private registry and reference it in the automation controller.
The administrator must build a custom execution environment using `ansible-builder`, which packages the required Python libraries and Ansible content into a container image. This image must then be pushed to a private registry (e.g., Quay.io or Red Hat Registry) and referenced in automation controller's execution environment configuration. Additionally, signing the image (e.g., via Podman or Skopeo) ensures compliance with security policies by verifying image integrity before execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Build the execution environment using ansible-builder and then push it to a private registry and reference it in the automation controller.
Why this is correct
Building with ansible-builder bundles the required Python libraries into a container image, satisfying the dependency constraint, while pushing to a private registry and referencing it in automation controller ensures every playbook run pulls that signed, policy-compliant execution environment rather than the default image.
- ✗
Push the custom execution environment to the default namespace and assign it to job templates.
Why it's wrong here
Pushing to the default namespace leaves the image unsigned and unverified, breaching the security policy's signing requirement. A signed custom execution environment in a controlled registry namespace is what satisfies both the library and signature requirements.
- ✗
Use the default execution environment and install Python libraries via the playbook.
Why it's wrong here
Installing libraries at playbook runtime modifies the container after it starts, so the signed image no longer reflects its contents and signature verification fails. A custom, signed execution environment is the correct artefact; runtime installation is what execution environments exist to replace.
- ✗
Define the execution environment in the project repository and use a pre-run hook.
Why it's wrong here
A pre-run hook executes inside the already-started container, so it cannot alter the signed image's Python libraries or satisfy signature verification. The signed custom execution environment must be built and referenced by the job template, not defined in the project repository.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.