Courseiva

CCNA Deploy Ansible Automation Platform Questions

33 questions · Deploy Ansible Automation Platform · All types, answers revealed

1
MCQeasy

An administrator is preparing to install Red Hat Ansible Automation Platform 2.5 using the containerized installer on a RHEL 9 host. The installer bundle has been extracted, and the administrator must provide the subscription manifest and other settings before running the setup playbook. Which file should the administrator edit to supply these installation parameters?

A.The group_vars/all.yml file created automatically in /etc/awx after the bundle is extracted.
B.The inventory file in the installer's setup directory, which holds host and platform configuration variables.
C.The ansible-navigator.yml file in the user's home directory, specifying execution environment options.
D.The /etc/ansible/ansible.cfg file on the target host, adding an [aap] section with the install variables.
AnswerB

The containerized installer uses an INI-style inventory file in the setup directory to define the target hosts and platform variables such as admin password, registry credentials, and the path to the Red Hat subscription manifest. Editing this file supplies the parameters the setup playbook consumes during installation.

Why this answer

The containerized installer is driven by an inventory file in its setup directory that holds both the target host definitions and the platform variables, including the subscription manifest location. Editing this file is the supported way to supply installation parameters before running the setup playbook.

Exam trap

The trap here is confusing the installer's inventory file with general Ansible configuration files such as ansible.cfg or ansible-navigator.yml, which do not carry platform install variables.

2
Multi-Selecteasy

Which TWO statements are true regarding the deployment of Ansible Automation Platform in a highly available configuration?

Select 2 answers
A.The automation hub requires an external PostgreSQL database to store collections and execution environments.
B.Execution nodes must have direct network access to the automation controller database.
C.The automation controller requires a PostgreSQL database that must be configured with replication for high availability.
D.The automation controller can use an embedded SQLite database for production deployments.
E.The automation mesh component is used to provide resilient, fault-tolerant execution across multiple nodes.
AnswersC, E

The automation controller persists its configuration, jobs and credentials in PostgreSQL, so a highly available deployment requires that database to be replicated across nodes; without database replication, a controller node failure would lose or block access to this shared state.

Why this answer

Option C is correct because in a highly available Ansible Automation Platform deployment, the automation controller (the control plane) relies on an external PostgreSQL database, and HA is achieved by configuring that PostgreSQL instance with replication (e.g., streaming replication or a supported HA topology) so the controller can fail over without losing job data. Option E is correct because the automation mesh (based on receptor) is the component that provides resilient, fault-tolerant execution by routing jobs across hop nodes and execution nodes, allowing execution to continue even if individual nodes become unavailable. Option A is incorrect because automation hub's PostgreSQL database is not strictly required to be external for HA in the way described; hub can be deployed with its own supported database configuration, and the statement overstates the requirement.

Option B is incorrect because execution nodes do not need direct network access to the automation controller's database; they communicate with the controller through the mesh/receptor network, not by connecting to PostgreSQL directly. Option D is incorrect because SQLite is not supported for production automation controller deployments; PostgreSQL is required.

Exam trap

The trap here is that candidates often confuse the storage backend for automation hub (thinking it requires an external database for content storage) or assume execution nodes need direct database access, when in reality the architecture separates database access to the controller and uses API-based communication for execution nodes.

3
MCQmedium

An administrator is deploying a redundant Ansible Automation Platform 2.4 cluster with two controller nodes and one database node. They want to ensure that the automation controller remains available if one controller node fails. Which configuration should they implement?

A.Deploy a single controller node with a hot standby that is manually activated during an outage.
B.Install the automation controller on both nodes and use a shared NFS mount for the project directory.
C.Configure the two controller nodes behind a load balancer that performs health checks on port 443.
D.Set up database replication between the two controller nodes and configure automatic failover.
AnswerC

In a redundant AAP cluster, controller nodes are placed behind a load balancer that distributes traffic and monitors node health. If one node fails, the load balancer routes traffic to the remaining healthy node, maintaining availability. This is the standard high-availability configuration for the automation controller component.

Why this answer

High availability for the automation controller in AAP is achieved by deploying multiple controller nodes behind a load balancer that performs health checks. This ensures that if one node becomes unavailable, traffic is automatically routed to the remaining healthy node, minimizing downtime. Other options do not provide automatic failover for the controller service.

Exam trap

The trap here is confusing database high availability with controller node high availability; they are separate components with different redundancy strategies.

4
MCQhard

An automation administrator is configuring an Ansible Automation Platform 2.4 controller to use an external PostgreSQL database. They have set `pg_host`, `pg_port`, `pg_database`, `pg_username`, and `pg_password` in the installer inventory. The installation fails with an error that the database user lacks the `CREATEDB` privilege. Which action should the administrator take?

A.Add `pg_sslmode='disable'` to the inventory to bypass SSL certificate validation.
B.Change `pg_host` to `localhost` to use a local socket connection instead of TCP.
C.Set `pg_username` to `postgres` and `pg_password` to the postgres superuser password.
D.Grant the `CREATEDB` privilege to the database user and re-run the installer.
AnswerD

The AAP installer requires the database user to have the `CREATEDB` privilege to create the necessary databases and schemas during installation. Without it, the installer cannot proceed. Granting this privilege to the specified user resolves the error and allows the installation to complete successfully. This is a documented requirement for external database configurations.

Why this answer

The installer requires the external database user to have the `CREATEDB` privilege to create the automation controller and hub databases. Granting this privilege is the correct fix. Other options either ignore the privilege requirement, use an insecure workaround, or modify unrelated connection parameters.

Exam trap

The trap here is thinking that any valid database user can be used, when the installer specifically requires elevated privileges like `CREATEDB` for initial setup.

5
MCQmedium

A Red Hat Certified Engineer is deploying Ansible Automation Platform 2.4 on a RHEL 9 server. They extract the installer tarball and edit the inventory file. They set `registry_username` and `registry_password` in the inventory, then run `./setup.sh`. The installation fails early with an error that the subscription-manager repositories are not enabled. Which action most directly resolves this failure?

A.Set `ansible_connection=local` in the installer inventory so the setup script uses the local RPM database.
B.Run the setup script with the `--skip-tags validation` flag to bypass the repository check.
C.Disable the firewall and SELinux on the server before rerunning the installer.
D.Ensure the RHEL system is registered with Red Hat Subscription Manager and the `ansible-automation-platform-2.4-for-rhel-9-x86_64-rpms` repository is enabled.
AnswerD

The AAP installer requires the system to be registered with RHSM and the correct AAP repository enabled so that required RPMs (e.g., ansible-core, receptor) can be installed. Without this repository, the setup script cannot resolve dependencies. Enabling the version-specific repository for RHEL 9 is the documented prerequisite before running the installer.

Why this answer

The AAP setup script depends on RHEL subscription repositories to install required packages. The system must be registered with RHSM and the appropriate AAP repository enabled. Without this, dependency resolution fails before configuration begins.

Enabling the correct version-specific repository is the documented prerequisite and directly resolves the reported error.

Exam trap

The trap here is assuming that providing registry credentials alone is sufficient for a disconnected or unregistered installation, when the installer also requires RHSM repositories to be enabled.

6
MCQeasy

An administrator is deploying Ansible Automation Platform 2.4 on a RHEL 9 server. They have downloaded the bundled installer tarball and extracted it. Which file must be edited to specify the PostgreSQL admin password, the automation controller admin password, and the receptor connection settings before running the setup script?

A.setup.sh
B.ansible.cfg
C.inventory
D./etc/tower/conf.d/credentials.py
AnswerC

The bundled installer uses an INI-style inventory file where variables such as admin_password, pg_password, and receptor parameters are defined under the [automationcontroller] and [all:vars] sections. Editing this file is the documented step before running setup.sh, making it the correct place to set these deployment-wide credentials and connection details.

Why this answer

The AAP bundled installer reads all deployment variables, including database and admin passwords plus receptor settings, from the inventory file. Editing that file before executing setup.sh is the supported method. Configuration files like ansible.cfg and legacy paths are not consulted for these values, and altering the installer script itself is unsupported.

Exam trap

The trap here is assuming Ansible runtime configuration files such as ansible.cfg supply installer credentials, when the bundled installer actually reads them from its inventory file.

7
MCQhard

A job template runs successfully on some hosts but fails on others with 'Permission denied' for the same task. The admin has verified that the credential is correct. What is the most likely cause?

A.The package repository is not accessible from those hosts.
B.The privilege escalation method (become method) differs among hosts.
C.The credential's username is incorrect for some hosts.
D.The SSH key is not accepted on some hosts.
AnswerB

Differing become methods across hosts break privilege escalation: sudo, su and doas require distinct configuration and password handling, so a task succeeding where sudo is configured fails elsewhere with 'Permission denied' despite valid credentials. Aligning the become method with each host's available escalation tooling resolves the inconsistency.

Why this answer

B is correct because the 'Permission denied' error on a task that runs successfully on some hosts but not others, despite a verified credential, typically indicates a privilege escalation issue. The become method (e.g., sudo, su, pbrun) may be configured differently or unsupported on the failing hosts, causing Ansible to fail when attempting to escalate privileges for the task. Since the credential is correct, the failure occurs during the become process, not authentication.

Exam trap

The trap here is that candidates often assume 'Permission denied' always means an SSH key or credential issue, overlooking that privilege escalation (become) is a separate step that can fail even when the initial SSH connection succeeds.

How to eliminate wrong answers

Option A is wrong because a package repository being inaccessible would cause a different error (e.g., 'Could not resolve host' or 'Failed to download metadata'), not 'Permission denied' for a task. Option C is wrong because the admin has verified the credential is correct, so the username is not incorrect; a wrong username would cause an authentication failure, not a permission error after authentication. Option D is wrong because an SSH key not being accepted would cause an SSH connection failure (e.g., 'Permission denied (publickey)') before any task runs, not a 'Permission denied' error on a specific task after connection is established.

8
Multi-Selectmedium

An organization is designing a high-availability Automation Platform deployment. Which TWO practices are essential for achieving high availability?

Select 2 answers
A.Use a single instance of PostgreSQL on the controller node.
B.Installation on a single powerful node.
C.Deploy multiple automation controllers behind a load balancer.
D.Store all secrets in the Automation Platform vault.
E.Use an external PostgreSQL database with replication.
AnswersC, E

Running multiple automation controllers behind a load balancer removes the single point of failure, distributing API and job traffic across nodes so one controller outage does not halt automation. This directly satisfies the high-availability design constraint.

Why this answer

Option C is correct because deploying multiple automation controllers behind a load balancer eliminates a single point of failure for the control plane, allowing traffic to be redistributed if one controller node becomes unavailable, which is fundamental to high availability. Option E is correct because using an external PostgreSQL database with replication ensures the shared data layer (job history, credentials metadata, inventories, etc.) remains available even if a database node fails, and externalizing it also decouples database lifecycle from controller nodes. Option A is incorrect because a single PostgreSQL instance on the controller node creates a single point of failure and couples the database to that node, undermining HA.

Option B is incorrect because consolidating everything on one powerful node still leaves a single point of failure regardless of performance. Option D is incorrect because storing secrets in the Automation Platform vault is a security best practice for credential management, not a high-availability mechanism.

Exam trap

The trap here is that candidates confuse 'high availability' with 'performance scaling' or 'security hardening', leading them to select a single powerful node (Option B) or vault storage (Option D) instead of recognizing that redundancy of both controllers and the database is required.

9
MCQeasy

An admin needs to restrict which users can launch specific job templates. Which AAP feature should be used?

A.Execution environments with custom modules.
B.Machine credentials with different users.
C.Inventory groups with host restrictions.
D.Role-based access control (RBAC) on job templates.
AnswerD

RBAC on job templates grants or denies execute permission to named users or teams, directly satisfying the requirement to restrict who can launch specific templates. Unlike organisation-wide roles, template-level role assignments scope access per template, so only explicitly authorised principals can run it.

Why this answer

Role-based access control (RBAC) on job templates is the correct feature because it allows an administrator to assign specific permissions (e.g., execute, read, or admin) to users or teams for individual job templates in Ansible Automation Platform (AAP). This directly restricts which users can launch specific job templates without affecting other resources.

Exam trap

The trap here is that candidates confuse operational features (like execution environments or credentials) with access control mechanisms, assuming that restricting execution environments or credentials indirectly controls user access, when AAP explicitly uses RBAC for granular user permissions on job templates.

How to eliminate wrong answers

Option A is wrong because execution environments are containerized runtime environments for Ansible playbooks, not a mechanism for user-level access control; custom modules extend functionality but do not restrict job template launches. Option B is wrong because machine credentials authenticate to target hosts (e.g., SSH keys or passwords) and do not control which users can launch job templates in AAP. Option C is wrong because inventory groups organize hosts for targeting playbooks, but they do not enforce user permissions on job templates; host restrictions limit which hosts are affected, not who can launch the job.

10
MCQmedium

A company is deploying Ansible Automation Platform (AAP) in a three-node cluster: one automation controller node, one private automation hub node, and one database node (PostgreSQL). The deployment uses an execution environment that pulls from the private automation hub. After a successful installation, all nodes are reachable and services are running. However, when launching a job template that uses the execution environment, the job fails with the error: 'Unable to pull execution environment image from automation-hub.example.com:5000/ee/my-ee:latest - request to registry failed with status 403 Forbidden'. The administrator confirms that the execution environment image exists in the private automation hub and that the automation controller node can reach the registry via curl. What is the most likely cause and solution?

A.The private automation hub is configured to allow unauthenticated access; change the hub configuration to disable authentication.
B.SELinux on the controller node is blocking container pulls; temporarily set SELinux to permissive.
C.Create a container registry credential in automation controller that uses the pull token from private automation hub, and associate it with the execution environment.
D.The execution environment definition in the controller is missing the 'pull' field; add 'pull: always' to the job template.
AnswerC

The 403 Forbidden comes from the registry rejecting an unauthenticated pull, not from network reachability. Automation controller needs a container registry credential holding the private automation hub pull token, associated with the execution environment, so it can authenticate.

Why this answer

The 403 Forbidden error indicates that the automation controller cannot authenticate to the private automation hub container registry. Even though the image exists and network connectivity works, the controller needs a container registry credential configured with the pull token from the private automation hub. This credential must be associated with the execution environment.

Option A is wrong because disabling authentication compromises security and is not the intended solution. Option B is wrong because SELinux would produce a different error (e.g., permission denied), not a 403. Option D is wrong because the 'pull' field does not affect authentication; the error is about authentication, not pull policy.

11
MCQmedium

An admin attempts to run this playbook as a job template in AAP. The job fails with 'ERROR! 'now' is not a valid attribute for a task'. What is the issue?

A.The template task is missing quotes around the file paths.
B.The playbook has an incorrect indentation in the tasks block.
C.The 'become' directive is placed incorrectly at the play level.
D.The 'now' attribute does not exist; it may be a typo for 'notify' or should be removed.
AnswerD

Ansible rejects unknown task keywords, so 'now' cannot be parsed as a valid task attribute. It is not a real module or directive; the playbook likely intended 'notify' or the line should be deleted entirely.

Why this answer

The error message 'ERROR! 'now' is not a valid attribute for a task' indicates that Ansible does not recognize 'now' as a valid task attribute. The 'now' keyword is not a standard Ansible directive; it is likely a typo for 'notify' (used with handlers) or should be removed entirely. Ansible validates task attributes against a strict schema, and any unknown attribute causes a parsing failure.

Exam trap

The trap here is that candidates may misread 'now' as a valid Jinja2 filter or confuse it with a module parameter, but Ansible strictly validates task attributes at parse time, not runtime.

How to eliminate wrong answers

Option A is wrong because missing quotes around file paths would cause a syntax error or a 'file not found' error, not an 'invalid attribute' error. Option B is wrong because incorrect indentation in the tasks block would produce a YAML parsing error (e.g., 'mapping values are not allowed here'), not an attribute validation error. Option C is wrong because placing 'become' at the play level is valid and would not generate an error about 'now'; it would either work or cause a privilege escalation error, not an attribute error.

12
Multi-Selectmedium

An administrator is configuring a new Red Hat Ansible Automation Platform 2.5 installation and must connect the automation controller to a private automation hub so that certified and validated collections can be pulled during project syncs. The administrator wants the controller to authenticate to the hub and resolve collections automatically. Which TWO actions should the administrator take to accomplish this? (Choose two.)

Select 2 answers
A.Set the organization's Galaxy credential to the created hub credential and add the hub to the list of enabled Galaxy servers.
B.Edit ansible.cfg on each execution node to add the private hub URL under the [galaxy_server] sections with a plaintext token.
C.Create a credential of type Ansible Galaxy/Automation Hub API Token in the controller and reference the hub URL and token.
D.Configure a webhook on the private automation hub that pushes collection metadata into the controller database on every change.
E.Publish the collections to the controller's local filesystem under /var/lib/awx/projects/collections and reference them with a relative path.
AnswersA, C

The controller resolves collections from the Galaxy servers configured for an organization. Assigning the hub credential to the organization and enabling the private hub as a Galaxy server ensures project syncs pull collections from the private hub using the stored token, completing the authenticated connection the administrator requires.

Why this answer

Connecting the controller to private automation hub requires a Galaxy/Automation Hub API Token credential holding the hub URL and token, plus assigning that credential to the organization and enabling the hub as a Galaxy server. Together these let project syncs authenticate and download certified or validated collections automatically.

Exam trap

The trap here is assuming that editing ansible.cfg on execution nodes or sideloading collections replaces the controller's own Galaxy server and credential configuration.

13
Drag & Dropmedium

Drag and drop the steps to configure a basic NFS server to export a directory in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To configure a basic NFS server to export a directory, the correct sequence is: install the NFS packages (e.g., nfs-utils), create the directory to be shared, edit /etc/exports to define the export, start and enable the NFS server service, and finally verify the export using 'showmount -e localhost'. This workflow ensures that all prerequisites are met before each step, avoiding errors such as missing directories or unapplied configuration.

14
MCQhard

An administrator is deploying a containerized Ansible Automation Platform 2.4 on a RHEL 9 host using the `ansible-container-installer`. After running the installation, the automation controller web UI is unreachable, and `podman ps` shows that the `automation-controller` container is in a restart loop. The administrator checks the container logs and sees repeated messages about failing to connect to the PostgreSQL database. The database container is running. Which action should the administrator take next?

A.Increase the memory limit for the automation controller container by editing the `container.yml` file and re-running the installer.
B.Restart the PostgreSQL container with `podman restart postgresql` and then restart the automation controller container.
C.Verify that the `postgresql` container's data directory has the correct SELinux context and that the `container_manage_cgroup` boolean is enabled.
D.Inspect the `automation-controller` container's environment variables to ensure the database hostname, port, username, and password match those configured for the PostgreSQL container.
AnswerD

In a containerized AAP deployment, the controller connects to the database using environment variables such as `CONTROLLER_PG_HOST`, `CONTROLLER_PG_PORT`, `CONTROLLER_PG_USER`, and `CONTROLLER_PG_PASSWORD`. If these do not match the actual database container's configuration, the controller will fail to connect and restart. Verifying and correcting these variables resolves the issue.

Why this answer

In a containerized AAP deployment, the automation controller and PostgreSQL run as separate containers. The controller uses environment variables to locate and authenticate to the database. When the controller container enters a restart loop with database connection errors, the most likely cause is a mismatch in these environment variables.

Verifying and aligning them with the database container's configuration restores connectivity and allows the controller to start successfully.

Exam trap

The trap here is focusing on container runtime or resource issues when the error message explicitly points to a database connection failure, which is typically a configuration mismatch.

15
MCQmedium

An administrator is deploying a containerized Ansible Automation Platform 2.4 on RHEL 9. After running the installer, the `automation-controller` containers fail to start, and the installer log reports that the `podman` service is not running. The administrator confirms that `podman` is installed. Which action should the administrator take to resolve the failure?

A.Enable and start the `podman.socket` service, then rerun the installer
B.Add the `awx` user to the `docker` group and restart the `automation-controller` service
C.Set `container_runtime=podman` in the inventory and rerun `setup.sh`
D.Install the `docker-ce` package and configure the installer to use Docker instead of Podman
AnswerA

Containerized AAP uses Podman to run its services, and the installer expects the Podman API socket to be available. Enabling and starting `podman.socket` provides that API endpoint. Rerunning the installer after the socket is active allows the container services to start, resolving the reported failure.

Why this answer

The containerized AAP installer relies on the Podman API, which is exposed by `podman.socket`. When that socket is inactive, container operations fail even though the Podman binary is present. Enabling and starting `podman.socket`, then rerunning the installer, restores the API endpoint and allows the AAP container services to start successfully.

Exam trap

The trap here is assuming that an installed Podman binary is sufficient, when the installer actually requires the Podman API socket service to be running.

16
MCQeasy

An administrator is installing Ansible Automation Platform 2.4 on a RHEL 9 server. They have extracted the installer tarball and are ready to run the setup script. Which command should they use to perform a standard installation using the default inventory?

A.`./setup.sh`
B.`./install.sh`
C.`ansible-playbook -i inventory install.yml`
D.`ansible-playbook setup.yml`
AnswerA

The `setup.sh` script is the documented entry point for installing Ansible Automation Platform. It reads the `inventory` file in the same directory and executes the installer playbooks with the appropriate environment. Running this script performs the standard installation using the default inventory file, which the administrator can edit beforehand.

Why this answer

The AAP installer is executed by running the `setup.sh` script from the extracted directory. This script reads the `inventory` file and runs the necessary playbooks. Using any other command, such as `ansible-playbook` with a guessed playbook name or a nonexistent `install.sh`, will not perform the installation correctly.

Exam trap

The trap here is assuming that because AAP is Ansible-based, you must run a playbook directly, when the supported method is the wrapper script `setup.sh`.

17
Matchingmedium

Match each Ansible module to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manage packages via YUM

Copy files to remote hosts

Manage system services

Deploy Jinja2 templates

Manage user accounts

Why these pairings

The yum module manages packages, service manages system services, and copy transfers files from local to remote. Common confusions include swapping definitions or using the wrong direction for file transfers.

18
MCQhard

An organization runs Red Hat Ansible Automation Platform 2.5 with a containerized automation controller. Administrators want job output and automation logs centralized so that a security team can search historical runs and correlate them with SIEM events. Which supported capability should the administrator configure to forward controller logs to an external logging endpoint?

A.Mount the controller container's /var/log/tower directory onto the host and ship those files with a log forwarder.
B.Enable the callback plugin in each project's ansible.cfg so every task posts its result to a remote HTTP endpoint.
C.Create a scheduled job template that queries the controller API for job events and writes them to a shared NFS export.
D.Configure the controller's external logging settings to send activity stream and job output to a syslog or aggregator endpoint.
AnswerD

Automation controller supports external logging, which forwards activity stream records and job events to an external aggregator such as Splunk, Elastic, or a syslog server. Enabling this with the appropriate host, port, and protocol settings centralizes logs so the security team can search and correlate them without querying the controller database directly.

Why this answer

Automation controller includes external logging configuration that forwards activity stream data and job events to syslog, Splunk, Elastic, or other aggregators. Enabling it centralizes logs for search and SIEM correlation without custom plugins, host mounts, or API polling jobs.

Exam trap

The trap here is assuming a callback plugin or host-mounted log directory replaces the controller's built-in external logging integration for audit and job events.

19
MCQhard

An administrator is deploying Ansible Automation Platform 2.4 with an external PostgreSQL database. The database administrator has created a database named `awx` and a user named `awx`, and has confirmed network connectivity from the AAP controller node to the database on port 5432. When the administrator runs the installer, the setup playbook fails during the database migration step with a permission error. Which configuration value is most likely missing or incorrect?

A.The AAP installer requires the database password to be stored in an Ansible Vault file referenced by `vault_password_file` in the inventory
B.The `postgresql.conf` file on the database server has `listen_addresses` set to `localhost` only
C.The `pg_hba.conf` on the database server does not permit the `awx` user to connect from the controller's IP address
D.The `awx` database was created with the `TEMPLATE template0` option instead of `TEMPLATE template1`
AnswerC

PostgreSQL uses `pg_hba.conf` to control which users may connect from which client addresses and with which authentication method. Even with a valid user and open port, a missing or restrictive host-based rule for the controller's address causes authentication or permission failures during migration. This is the classic cause when connectivity tests succeed but the installer's database operations fail.

Why this answer

When TCP connectivity to PostgreSQL is confirmed but the installer fails on database operations, the problem is almost always authorization. PostgreSQL's host-based authentication rules in `pg_hba.conf` determine whether the `awx` user may connect from the controller's address with the configured authentication method. Adding an appropriate host entry, then reloading PostgreSQL, resolves the migration failure.

Exam trap

The trap here is focusing on network reachability after it has already been proven, instead of checking PostgreSQL's host-based authentication rules that govern whether the user is allowed to connect.

20
MCQhard

An administrator deploys AAP 2.4 with an external PostgreSQL database. After the installation completes, the automation controller web UI is reachable, but jobs fail immediately with database connection errors. The administrator confirms the database host is reachable on port 5432 and the credentials in the inventory are correct. Which action should be taken to resolve the issue?

A.Change the database port in the inventory to 5433 and re-run the installer.
B.Open port 5432 in firewalld on the controller node.
C.Re-run setup.sh with the --force flag to regenerate the controller configuration.
D.Verify that the external database has been configured with the required extensions and that the pg_hba.conf allows connections from the controller node's IP address.
AnswerD

For an external database, PostgreSQL must have the necessary extensions (such as hstore and pg_trgm) and pg_hba.conf must permit the controller's IP with the correct authentication method. A reachable port alone does not guarantee authentication or extension availability, so these are the likely missing pieces.

Why this answer

When using an external PostgreSQL database with AAP, the database must be prepared with specific extensions and the pg_hba.conf must allow the controller host to authenticate. Port reachability and correct credentials in the inventory are necessary but not sufficient. The other options either target the wrong host, introduce an unrelated change, or re-run the installer without fixing the underlying database configuration.

Exam trap

The trap here is equating network reachability with database readiness, overlooking that extensions and pg_hba.conf rules are also required for an external PostgreSQL deployment.

21
Multi-Selectmedium

Which TWO statements are true about deploying Red Hat Ansible Automation Platform using the automation mesh?

Select 2 answers
A.Execution nodes can be located in different geographic regions.
B.Existing Ansible Tower nodes can be added to the mesh without modification.
C.Automation mesh requires two separate ports for control and data plane traffic.
D.The mesh topology is organized as a parent/child relationship between nodes.
E.All execution nodes must have direct network access to the automation controller.
AnswersA, D

Execution nodes in an automation mesh can span distinct geographic regions, since the mesh replaces the single-hop SSH model with peer-to-peer overlay routing between nodes. This satisfies the stem's requirement for distributed, resilient deployment, allowing execution capacity to sit close to managed hosts across regions without a central hop.

Why this answer

Option A is correct because automation mesh is designed to span distributed environments, allowing execution nodes to be placed in different geographic regions and connected through hop nodes or peer relationships rather than requiring a single data center. Option D is correct because automation mesh uses a hierarchical topology in which nodes are organized as parent and child, with control and execution nodes communicating through defined parent/child links. Option B is incorrect because existing Ansible Tower nodes cannot simply be added unchanged; they must be upgraded/reconfigured to run receptor and mesh components.

Option C is incorrect because automation mesh does not require two separate ports for control and data plane traffic; it uses a single TCP port, typically 27199, for receptor traffic. Option E is incorrect because execution nodes do not need direct network access to the automation controller; they can communicate through intermediate hop nodes in the mesh.

Exam trap

The trap here is that candidates often assume automation mesh requires separate control and data ports (like in some SDN solutions) or that all nodes must reach the controller directly, but Red Hat's implementation uses a single port and a peer-to-peer routing model.

22
MCQmedium

An automation architect is deploying Red Hat Ansible Automation Platform 2.4 on a RHEL 9 control node. The setup bundle has been extracted, and the admin runs `./setup.sh` from the installer directory. During the pre-flight checks, the installer reports that the PostgreSQL database is not reachable and aborts. The admin confirms that the database server is running and that the inventory file contains the correct hostname. Which action should the admin take to resolve the installation failure?

A.Edit the inventory file to set `pg_port=5432` and `pg_ssl=false` to force a plain-text connection to the database.
B.Disable the firewall on the automation controller node using `systemctl stop firewalld` and rerun `./setup.sh`.
C.Re-run the installer with the `--skip-preflight` flag to bypass the database check and complete the installation.
D.Verify that the `pg_hba.conf` file on the database server allows connections from the automation controller node and that the `postgresql` service is listening on the correct network interface.
AnswerD

The installer's pre-flight check validates database connectivity using the credentials and hostname in the inventory. If the database is running but not accepting remote connections, it is typically due to `pg_hba.conf` restrictions or the service binding only to localhost. Ensuring the database allows connections from the controller node and listens on the correct interface resolves the failure.

Why this answer

The installer's pre-flight check verifies that the automation controller can reach the PostgreSQL database using the inventory-defined host and credentials. When the database service is running but unreachable, the most common causes are restrictive `pg_hba.conf` entries or the service binding only to the loopback interface. Verifying these settings ensures the controller can establish the required connection.

Exam trap

The trap here is assuming that a running database service automatically accepts remote connections, when host-based authentication or interface binding may still block the controller.

23
MCQhard

An admin imports this inventory into AAP and assigns a machine credential that uses SSH key authentication. The job fails with 'Authentication failed'. What is the most likely cause?

A.The private key file path in the inventory does not exist on the controller.
B.The credential's SSH key is not being used because the inventory variable ansible_ssh_private_key_file conflicts.
C.The machine credential does not contain an SSH private key.
D.The 'ansible_become' variable is missing from the inventory.
AnswerC

SSH key authentication requires the machine credential to hold the private key matching the public key on the managed host. Without that private key stored in the credential, Ansible cannot authenticate, producing the 'Authentication failed' error.

Why this answer

In Red Hat Ansible Automation Platform (AAP), when a machine credential is assigned to a host, that credential's SSH key is used for authentication. If the credential does not contain an SSH private key, authentication will fail. Credentials take precedence over inventory variables such as ansible_ssh_private_key_file, so a conflict is not the likely cause.

Therefore, the most likely cause is that the machine credential is missing its SSH private key.

24
MCQeasy

A systems administrator is preparing to install Red Hat Ansible Automation Platform 2.4 on a RHEL 9 server. They have downloaded the installer tarball and extracted it. Which file must they edit to specify the target hosts and authentication credentials for the installation?

A.`group_vars/all.yml`
B.`ansible.cfg`
C.`inventory`
D.`setup.sh`
AnswerC

The AAP installer uses an inventory file, typically named `inventory`, located in the installer directory. This file defines the groups such as `[automationcontroller]`, `[automationhub]`, and `[database]`, and includes variables like `ansible_user`, `ansible_password`, and `ansible_become_password` for authentication. Editing this file is a required step before running `setup.sh`.

Why this answer

The AAP installer requires an inventory file where you list the target hosts under specific groups and provide authentication variables such as `ansible_user` and `ansible_password`. This file is typically named `inventory` and is located in the installer directory. Editing it is mandatory before running `setup.sh` to ensure the installer can connect to and configure the hosts.

Exam trap

The trap here is confusing the AAP installer inventory file with general Ansible configuration files like `ansible.cfg` or `group_vars`.

25
MCQmedium

An organization is deploying Automation Platform for the first time. The security team requires that all SSH private keys used for automation be stored securely with access controls. Which AAP feature should be used to meet this requirement?

A.Store the private key in plain text within the inventory file.
B.Use Ansible Vault to encrypt the private key file.
C.Set the SSH key as an environment variable on the controller.
D.Create a Machine credential type and upload the SSH private key.
AnswerD

A Machine credential stores the SSH private key encrypted within Automation Platform and enforces role-based access controls, so only authorised users and job templates can retrieve it. This satisfies the requirement that keys never sit in plain text on disk.

Why this answer

The Machine credential type in Ansible Automation Platform (AAP) is specifically designed to securely store SSH private keys. When you upload the private key via the AAP web UI or API, it is encrypted at rest in the AAP database and access is controlled through role-based access control (RBAC). This meets the security team's requirement for secure storage and access controls without exposing the key in plain text.

Exam trap

The trap here is that candidates may confuse Ansible Vault (a file-level encryption tool) with AAP's credential management system, not realizing that Vault does not provide the centralized access control and audit trail required for enterprise security compliance.

How to eliminate wrong answers

Option A is wrong because storing a private key in plain text within an inventory file violates basic security principles and exposes the key to anyone with file system access, which is not secure storage with access controls. Option B is wrong because Ansible Vault encrypts files at rest but does not integrate with AAP's native credential system; the key would still need to be decrypted at runtime and managed outside of AAP's RBAC, failing the access control requirement. Option C is wrong because setting the SSH key as an environment variable on the controller exposes it to any process or user that can read environment variables, and it lacks the granular access controls and audit logging that AAP credentials provide.

26
Matchingmedium

Match each Ansible inventory parameter to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Hostname or IP to connect to

SSH user for connection

SSH port number

Private key file path

Python interpreter path

Why these pairings

Common Ansible inventory parameters: ansible_host defines target host, ansible_port defines SSH port, ansible_user defines remote user, ansible_ssh_private_key_file defines SSH key. Be careful not to confuse them with ansible_connection or ansible_become.

27
MCQmedium

An automation engineer is deploying Red Hat Ansible Automation Platform 2.4 using the bundled installer on a RHEL 9 control node. The inventory file is configured with `[automationcontroller]` and `[automationhub]` groups. After running `./setup.sh`, the installation fails with the message 'Unable to resolve the DNS name for the automation hub host'. The engineer verifies that the hostname is correct and resolvable from the control node. What is the most likely cause of this failure?

A.The control node's firewall is blocking outbound DNS queries to the automation hub host.
B.The automation hub host is not listed in the `[automationhub]` group of the installer inventory.
C.The `[automationhub]` group is missing the `automationhub_admin_password` variable, causing the installer to fail before DNS resolution.
D.The target host's `/etc/hosts` file does not contain an entry mapping its own hostname to its IP address, and the installer uses the host's own hostname for internal service communication.
AnswerD

The AAP installer relies on the target host being able to resolve its own hostname, often via `/etc/hosts`. Even if the control node can resolve the target's DNS name, the target itself may fail to resolve its own hostname during service configuration. This causes the installer to report a DNS resolution error. Adding the hostname to `/etc/hosts` on the target resolves the issue.

Why this answer

The AAP installer requires that each target host can resolve its own hostname, typically via an entry in `/etc/hosts`. Even when the control node resolves the target's DNS name, the target itself may fail to resolve its own hostname during internal service configuration, producing a DNS resolution error. Adding the hostname to `/etc/hosts` on the target resolves the issue.

Exam trap

The trap here is assuming that DNS resolution from the control node is sufficient, while overlooking the target host's need to resolve its own hostname.

28
Multi-Selectmedium

Which THREE are valid user roles within an Automation Controller organization? (Choose three.)

Select 3 answers
A.Organization auditor
B.Organization admin
C.Organization team_member
D.Superuser
E.Organization member
AnswersA, B, E

Organization auditor is a built-in Automation Controller role granting read-only visibility across all objects within a single organization, including inventories, credentials, job templates and projects. It satisfies the stem's requirement for a valid organization-scoped user role, distinct from system auditor, which spans the entire controller instance rather than one organization.

Why this answer

In Automation Controller (Ansible Tower), an organization defines a set of users, teams, and resources, and it grants three built-in user roles: Organization admin, Organization member, and Organization auditor. Option B (Organization admin) is correct because this role has full administrative rights over the organization, including managing users, teams, projects, inventories, and credentials within it. Option E (Organization member) is correct because this role grants standard access to use the organization's resources, such as running job templates, without administrative privileges.

Option A (Organization auditor) is correct because this role provides read-only visibility into the organization's objects and activity for auditing purposes. Option C (Organization team_member) is not a valid organization-level role; team membership is a separate association, and roles like member/admin are assigned to teams rather than being an organization role itself. Option D (Superuser) is a system-wide role that sits above organizations and is not one of the organization-scoped user roles.

Exam trap

The trap here is that candidates may confuse 'Organization team_member' with a valid role, not realizing that team membership is distinct from organization-level roles, or they may incorrectly select 'Superuser' thinking it is an organization role when it is actually a global system role.

29
MCQeasy

An admin is configuring a project in Automation Platform to pull playbooks from a Git repository. Which source control type should be selected?

A.Local
B.Manual
C.SCM
D.Red Hat Insights
AnswerC

Selecting SCM as the source control type lets Automation Platform authenticate to the Git repository and retrieve playbooks directly, satisfying the requirement to pull playbooks from Git. Other source control types, such as manual or archive-based imports, do not establish the live repository connection the scenario demands.

Why this answer

(SCM) is correct because Ansible Automation Platform uses Source Control Management (SCM) to integrate with Git repositories. When configuring a project, selecting 'SCM' allows the platform to pull playbooks, roles, and inventories directly from a remote Git repository, enabling version control and automated sync.

Exam trap

The trap here is that candidates may confuse 'SCM' with a generic term and think 'Manual' or 'Local' are valid options, but only SCM enables Git integration for project synchronization.

How to eliminate wrong answers

Option A is wrong because 'Local' refers to a project that uses playbooks stored directly on the Automation Controller file system, not from a remote Git repository. Option B is wrong because 'Manual' is not a valid source control type in Automation Platform; projects require either Local or SCM. Option D is wrong because 'Red Hat Insights' is a separate analytics and remediation service, not a source control mechanism for pulling playbooks.

30
MCQmedium

A company is deploying Red Hat Ansible Automation Platform 2.3 in a hybrid cloud environment. The automation controller is installed on a RHEL 8 server in the on-premises data center. Execution nodes are distributed: four in the same data center, two in a remote branch office connected via VPN, and three in AWS EC2 instances. The VPN connection to the branch office is low-bandwidth and high-latency. The AWS nodes use a direct connect with stable bandwidth. During initial testing, playbooks running on the branch office execution nodes frequently timeout or hang, while on-premises and AWS nodes work fine. The automation mesh topology is configured with all nodes as direct children of the controller. The team wants to minimize latency and ensure reliable execution for the branch office nodes. Which course of action should the administrator take?

A.Deploy an additional automation mesh node in the branch office and make the branch office execution nodes children of that node.
B.Configure the controller to use the AWS execution nodes for all branch office jobs via a proxy.
C.Increase the `ansible_timeout` setting in the controller configuration to 120 seconds.
D.Reduce the forks value for branch office execution nodes to 1.
AnswerA

Introducing an intermediate hop node in the branch office lets execution nodes connect over the low-latency LAN rather than the high-latency VPN, satisfying the requirement to minimise latency and prevent timeouts. Direct children of the controller force every job hop across the constrained VPN link.

Why this answer

Deploying an additional automation mesh node in the branch office creates a local parent for the branch office execution nodes, reducing the number of high-latency, low-bandwidth VPN hops between the controller and those nodes. In the automation mesh, parent-child relationships allow execution nodes to connect through a closer intermediary, minimizing timeouts and improving reliability by keeping control-plane traffic local.

Exam trap

The trap here is that candidates may confuse tuning parameters (timeout, forks) with architectural fixes, failing to recognize that the mesh topology itself must be adapted to overcome network constraints.

How to eliminate wrong answers

Option B is wrong because using AWS execution nodes as a proxy for branch office jobs would still route traffic over the VPN, adding unnecessary latency and complexity without addressing the root cause. Option C is wrong because increasing `ansible_timeout` only masks the symptom of network delays; it does not reduce the underlying latency or packet loss causing the timeouts. Option D is wrong because reducing forks to 1 limits parallelism but does not solve connectivity issues; it may even increase execution time without preventing hangs from network instability.

31
MCQmedium

An admin configures an automation mesh environment. What is the primary purpose of mesh nodes in AAP?

A.To enable high availability for the web UI.
B.To act as a backup for the automation controller.
C.To provide a redundant database server.
D.To scale automation execution capacity.
AnswerD

Mesh nodes extend execution capacity by running jobs alongside control-plane hybrid nodes, distributing playbook workloads across additional compute. This directly satisfies the stem's scaling requirement: adding mesh nodes increases parallel job execution without altering the control plane, unlike hop nodes, which only relay traffic between isolated network segments.

Why this answer

Mesh nodes in Ansible Automation Platform (AAP) are designed to distribute automation execution workloads across multiple nodes, enabling horizontal scaling. They do not handle the web UI, controller logic, or database functions; instead, they execute playbooks and jobs, offloading work from the automation controller to increase overall capacity and performance.

Exam trap

The trap here is that candidates confuse mesh nodes with general high-availability or redundancy components, assuming they serve as backups for the controller or database, when in fact they are strictly for scaling execution capacity.

How to eliminate wrong answers

Option A is wrong because high availability for the web UI is provided by the automation controller nodes themselves, often through a load balancer, not by mesh nodes. Option B is wrong because mesh nodes are not backups for the automation controller; controller redundancy is achieved through a separate controller cluster with active/passive or active/active setups. Option C is wrong because database redundancy is handled by a separate database cluster (e.g., PostgreSQL streaming replication), not by mesh nodes, which have no database role.

32
MCQmedium

A team uses execution environments (EE) for job templates. The admin builds a custom EE using `ansible-builder` with a `execution-environment.yml` file that includes a `base_image: registry.redhat.io/ansible-automation-platform-21/ee-minimal-rhel8:latest` and a custom Python requirement. However, the controller reports that the EE is not found when launching a job. What is the most likely issue?

A.The built EE image was not pushed to the container registry specified in the controller's execution environment configuration.
B.The base image is pointing to an incorrect registry path.
C.The custom Python requirement needs to be added to `requirements.txt` in the project.
D.The execution environment does not include a `Containerfile` for the build process.
AnswerA

Ansible-builder produces the EE image locally, but the controller resolves EEs from a configured container registry. Unless the image is pushed there, the controller cannot pull it, producing the 'not found' error despite a successful build.

Why this answer

After building a custom execution environment with `ansible-builder`, the resulting container image must be pushed to a container registry that the Automation Controller is configured to access. The controller does not automatically pull images from the local build cache; it references the image by its registry path. If the image is not present in the specified registry, the controller will report that the EE is not found when launching a job.

Exam trap

The trap here is that candidates assume building the image locally is sufficient, but the controller requires the image to be accessible via a registry pull, not from the local build cache.

How to eliminate wrong answers

Option B is wrong because `registry.redhat.io/ansible-automation-platform-21/ee-minimal-rhel8:latest` is a valid Red Hat registry path for the minimal execution environment; the issue is not about an incorrect registry path but about the image not being available in the registry the controller queries. Option C is wrong because custom Python requirements are defined in the `execution-environment.yml` file under the `python` key, not in a project's `requirements.txt`; the controller does not read project files for EE dependencies. Option D is wrong because `ansible-builder` automatically generates a `Containerfile` (or `Dockerfile`) during the build process based on the `execution-environment.yml`; the absence of a pre-existing `Containerfile` is not the issue.

33
MCQeasy

An organization wants to deploy Ansible Automation Platform 2.x in a highly available configuration. Which component must be deployed in an active-active cluster to ensure controller failover?

A.PostgreSQL database
B.Automation controller
C.Private Automation Hub
D.Automation mesh
AnswerB

Automation controller nodes form an active-active cluster behind a load balancer, so any node can accept and execute jobs; if one fails, the remaining nodes continue running playbooks without manual intervention. This satisfies the stem's controller failover requirement, since the control plane itself must be redundant rather than relying on a single instance.

Why this answer

The automation controller is the component that provides the web UI, REST API, and job execution management in Ansible Automation Platform 2.x. For high availability, multiple controller nodes must be deployed in an active-active cluster behind a load balancer, ensuring that if one controller fails, another can immediately take over without service interruption.

Exam trap

The trap here is that candidates often confuse the automation mesh (which provides execution node redundancy) with the automation controller's active-active clustering, leading them to select mesh as the answer for controller failover.

How to eliminate wrong answers

Option A is wrong because PostgreSQL database is typically deployed as a separate highly available database cluster (e.g., using Patroni or streaming replication) and is not itself part of the active-active controller cluster; it supports the controller but does not provide controller failover. Option C is wrong because Private Automation Hub is a content distribution component for collections and execution environments, and it does not handle controller job scheduling or API requests; it can be made highly available independently but does not ensure controller failover. Option D is wrong because Automation mesh is a communication layer for distributing execution workloads across nodes and is not a controller component; it provides resilience for execution nodes but does not handle controller failover.

Ready to test yourself?

Try a timed practice session using only Deploy Ansible Automation Platform questions.