EX294 Deploy Ansible Automation Platform Practice Question
An automation administrator is configuring an Ansible Automation Platform 2.4 controller to use an external PostgreSQL database. They have set `pg_host`, `pg_port`, `pg_database`, `pg_username`, and `pg_password` in the installer inventory. The installation fails with an error that the database user lacks the `CREATEDB` privilege. Which action should the administrator take?
⚠ Common exam trap
The trap here is thinking that any valid database user can be used, when the installer specifically requires elevated privileges like `CREATEDB` for initial setup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the `CREATEDB` privilege to the database user and re-run the installer.
The installer requires the external database user to have the `CREATEDB` privilege to create the automation controller and hub databases. Granting this privilege is the correct fix. Other options either ignore the privilege requirement, use an insecure workaround, or modify unrelated connection parameters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add `pg_sslmode='disable'` to the inventory to bypass SSL certificate validation.
Why it's wrong here
SSL mode settings control encryption and certificate validation, not user privileges. Disabling SSL would not grant the `CREATEDB` privilege and could expose database traffic. The error message explicitly mentions a privilege issue, so adjusting SSL settings is irrelevant and potentially insecure.
- ✗
Change `pg_host` to `localhost` to use a local socket connection instead of TCP.
Why it's wrong here
The error is about missing privileges, not the connection method. Switching to a local socket would not grant the `CREATEDB` privilege to the user. The database user still needs the appropriate privileges regardless of how the connection is made. This change would not resolve the underlying privilege deficiency.
- ✗
Set `pg_username` to `postgres` and `pg_password` to the postgres superuser password.
Why it's wrong here
While using the `postgres` superuser would bypass the privilege issue, it is not recommended for security and operational reasons. The AAP installer is designed to use a dedicated database user with specific privileges, not the superuser. Using the superuser could lead to permission issues later and violates best practices for least privilege.
- ✓
Grant the `CREATEDB` privilege to the database user and re-run the installer.
Why this is correct
The AAP installer requires the database user to have the `CREATEDB` privilege to create the necessary databases and schemas during installation. Without it, the installer cannot proceed. Granting this privilege to the specified user resolves the error and allows the installation to complete successfully. This is a documented requirement for external database configurations.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.