EX294 Deploy Ansible Automation Platform Practice Question
An organization runs Red Hat Ansible Automation Platform 2.5 with a containerized automation controller. Administrators want job output and automation logs centralized so that a security team can search historical runs and correlate them with SIEM events. Which supported capability should the administrator configure to forward controller logs to an external logging endpoint?
⚠ Common exam trap
The trap here is assuming a callback plugin or host-mounted log directory replaces the controller's built-in external logging integration for audit and job events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the controller's external logging settings to send activity stream and job output to a syslog or aggregator endpoint.
Automation controller includes external logging configuration that forwards activity stream data and job events to syslog, Splunk, Elastic, or other aggregators. Enabling it centralizes logs for search and SIEM correlation without custom plugins, host mounts, or API polling jobs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mount the controller container's /var/log/tower directory onto the host and ship those files with a log forwarder.
Why it's wrong here
Containerized deployments do not persist controller logs in a bind-mounted /var/log/tower path for host-side shipping. Logs live inside the container and are managed by the platform. Relying on a host mount is unsupported, may miss rotated data, and bypasses the built-in external logging integration that forwards events reliably.
- ✗
Enable the callback plugin in each project's ansible.cfg so every task posts its result to a remote HTTP endpoint.
Why it's wrong here
Callback plugins run inside the playbook execution and can post per-task data, but they do not centralize controller-level audit records such as logins and job launches, and they require modifying every project. This is a playbook-scoped workaround rather than the platform's supported external logging capability for the controller.
- ✗
Create a scheduled job template that queries the controller API for job events and writes them to a shared NFS export.
Why it's wrong here
Polling the API on a schedule introduces latency, duplicates data, and burdens the controller with heavy queries. It also does not capture activity stream events such as logins in real time. The platform provides native external logging configured in the controller settings, which is more efficient and complete than a custom polling job.
- ✓
Configure the controller's external logging settings to send activity stream and job output to a syslog or aggregator endpoint.
Why this is correct
Automation controller supports external logging, which forwards activity stream records and job events to an external aggregator such as Splunk, Elastic, or a syslog server. Enabling this with the appropriate host, port, and protocol settings centralizes logs so the security team can search and correlate them without querying the controller database directly.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.