Courseiva

EX294 Manage automation security and operations Practice Question

An Ansible playbook uses 'become: yes' to install packages. The playbook works when run manually by the administrator but fails when run from automation controller with 'Missing sudo password'. The administrator has configured a machine credential with the SSH key and the 'Become password' field is blank. What is the most likely issue?

⚠ Common exam trap

Red Hat often tests the distinction between SSH authentication (private key) and privilege escalation (become password) in Automation Controller, tempting candidates to focus on SSH key issues when the error clearly points to the missing become password.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The machine credential does not include the become password.

The playbook uses 'become: yes' to escalate privileges, which requires a become password when the remote user's sudo configuration demands password authentication. Since the machine credential's 'Become password' field is blank, Automation Controller cannot supply the password during the privilege escalation step, causing the 'Missing sudo password' error. The administrator's manual run succeeds because the SSH session can prompt interactively for the password, but Automation Controller's non-interactive execution requires the password to be pre-configured in the credential.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The machine credential does not include the become password.

    Why this is correct

    With become enabled, Ansible escalates via sudo, which needs the privilege password when NOPASSWD is not configured. The blank Become password field in the machine credential leaves sudo without credentials, producing the 'Missing sudo password' error.

  • ✗

    The become method is set to 'su' instead of 'sudo'.

    Why it's wrong here

    The error names a missing sudo password, which su would not produce; the become method is evidently sudo already. Switching to su is tempting when sudo is unavailable on a host, and would be correct where only the root password, not sudo rights, is granted.

  • ✗

    The remote user is not in the sudoers file.

    Why it's wrong here

    The playbook succeeds manually as the same remote user, so sudoers membership is already proven; the failure arises because the become password is absent from the credential. Adding the user to sudoers is tempting when privilege escalation is denied outright, which would produce a different error.

  • ✗

    The SSH private key is not loaded into the automation controller.

    Why it's wrong here

    SSH authentication succeeded, otherwise the error would report unreachable hosts or key rejection, not a missing sudo password. Loading the key is tempting when connections fail, and would be correct if the controller could not authenticate to the managed nodes at all.

About these practice questions

Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.