Courseiva

EX294 Manage inventories and credentials Practice Question

An administrator needs to provide a set of credentials to a job template that requires a machine credential for SSH and a source control credential for the project. What is the correct way to associate these credentials?

⚠ Common exam trap

It's easy for candidates to think a single credential must contain all authentication data, but Ansible Tower explicitly separates credential types by function, and a job template can accept multiple credentials of different types simultaneously.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign both a machine credential and a source control credential to the job template

Ansible Tower/AWX allows multiple credentials of different types to be assigned to a single job template. A machine credential handles SSH authentication for target hosts, while a source control credential manages authentication for the project repository (e.g., Git). This separation follows Ansible's modular credential design, where each credential type serves a distinct purpose and can be independently managed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Define the source control token in the playbook using the 'set_fact' module

    Why it's wrong here

    set_fact runs during playbook execution, after the project has already been checked out, so it cannot supply the token needed to clone the repository. Defining variables in a playbook is tempting for reusable values, but source control authentication must occur before the playbook runs, via a source control credential on the job template.

  • ✗

    Create a single credential that includes both SSH key and source control token

    Why it's wrong here

    Automation Controller credential types are distinct: machine credentials hold SSH keys, source control credentials hold tokens, and a single credential cannot contain both. Combining them is tempting to reduce objects, but the job template must reference two separate credentials, each matching its required type.

  • ✗

    Store the source control token as an extra variable in the job template

    Why it's wrong here

    Extra variables are passed to the playbook at runtime and are never used by Automation Controller to authenticate to the Git repository, so the project cannot be fetched. Storing secrets as extra variables is tempting because it is quick, but source control credentials belong in a dedicated source control credential attached to the job template.

  • ✓

    Assign both a machine credential and a source control credential to the job template

    Why this is correct

    A job template accepts multiple credentials of different types simultaneously, so attaching both a machine credential for SSH and a source control credential for the project satisfies both authentication needs. Each credential type is matched to its corresponding function during job execution.

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.