EX294 Implement advanced Ansible automation Practice Question
An automation engineer is using Ansible to manage a fleet of servers. They need to ensure that certain tasks run only on hosts that match specific criteria. Which two of the following are valid ways to limit task execution based on host facts? (Choose two.)
⚠ Common exam trap
The trap here is assuming that tags or run_once can be used for fact-based filtering. Tags are static, and run_once ignores facts, so they cannot select hosts based on facts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'group_by' module to create dynamic groups based on facts, then target those groups in subsequent plays.
The 'when' conditional and the 'group_by' module are both valid methods to limit task execution based on host facts. The 'when' clause evaluates facts per host, while 'group_by' dynamically creates groups that can be targeted in subsequent plays. Tags, delegate_to, and run_once do not provide fact-based filtering of hosts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the 'group_by' module to create dynamic groups based on facts, then target those groups in subsequent plays.
Why this is correct
The group_by module creates new inventory groups based on facts, such as os_family. You can then write plays that target these dynamic groups. This is a valid approach to limit task execution to hosts matching specific fact criteria, though it requires a separate play or playbook run.
- ✗
Use the 'tags' keyword to tag tasks with fact values, then run the playbook with --tags to filter.
Why it's wrong here
Tags are static labels assigned to tasks and are not evaluated against host facts. You cannot dynamically tag tasks with fact values at runtime. Using --tags filters by tag names, not by fact conditions. Therefore, this method does not limit execution based on facts.
- ✗
Use the 'delegate_to' directive with a fact-based expression to delegate tasks to matching hosts.
Why it's wrong here
delegate_to is used to run a task on a different host, not to conditionally limit execution based on facts. It does not evaluate conditions; it simply changes the target host for the task. It cannot be used to filter which hosts run the task based on their facts.
- ✓
Use the 'when' conditional with a fact variable, such as when: ansible_facts['os_family'] == 'RedHat'.
Why this is correct
The 'when' clause can reference any fact variable, including those gathered by the setup module. Checking ansible_facts['os_family'] allows tasks to run only on Red Hat family hosts. This is a common and valid method for conditional task execution based on host facts.
- ✗
Use the 'run_once' keyword with a fact-based condition to run the task only on the first matching host.
Why it's wrong here
run_once ensures a task runs only on the first host in the play, regardless of facts. It does not evaluate fact conditions to select a host. Combining it with a condition might skip the task entirely if the first host does not match, but it does not provide a reliable way to run on all matching hosts.
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.