Courseiva

EX294 · domain

Manage inventories and credentials

This domain covers Ansible inventory construction and credential handling for automation execution. On EX294 you build static and dynamic inventories, assign host and group variables, and configure credentials used by automation controller job templates. Questions test correct YAML structure for inventory files, plugin configuration, and credential-to-template association rather than memorized menu paths.

52 questions13 easy23 medium16 hard

Focused practice

Practice Manage inventories and credentials questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Manage inventories and credentials

Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.

Building static INI and YAML inventories with host groups, children, and group_vars directories

Configuring dynamic inventory plugins such as amazon.aws.aws_ec2 and community.general.proxmox with plugin YAML files

Defining group_vars and host_vars precedence for variables applied across inventory hosts

Associating machine, source control, and custom credential types with job templates in automation controller

Watch out for

Common Manage inventories and credentials exam traps

  • ▸Placing group_vars in the wrong directory level so variables are not picked up by the intended group or hosts
  • ▸Forgetting to enable a dynamic inventory plugin in ansible.cfg or omitting the plugin key in its configuration file
  • ▸Confusing credential types when a job template needs both machine and source control credentials attached separately

Question index

All Manage inventories and credentials questions (52)

Click any question to see the full explanation, or start a practice session above.

1

An administrator is running `ansible-playbook -i inventories/prod site.yml` against the `prod` inventory, which contains a group `web` and a group `db`. The play is defined with `hosts: web:&db`. Which hosts will the play target?

Medium
2

You must store a database password that a playbook will use on managed nodes. Your security policy forbids clear-text secrets in the repository and requires that the secret remain usable with `ansible-playbook --vault-password-file /home/devops/.vault_pass`. Which two actions satisfy the policy? (Choose two.)

Medium
3

An administrator creates a group named `webservers` in an INI-style inventory and a group named `webservers` in a YAML inventory under the same inventory directory. Both groups define different hosts. What is the result when Ansible loads the inventory?

Easy
4

A company manages its infrastructure using Ansible Tower. There are two teams: Team Alpha manages web servers in the 'webservers' group, and Team Beta manages database servers in the 'dbservers' group. Both teams need to use the same SSH credential to connect to their respective servers. The credential is stored in Tower as 'shared_ssh_key'. Team Alpha reports that they can launch jobs against the 'webservers' group, but Team Beta gets an error when trying to launch jobs against the 'dbservers' group: 'You do not have permission to use this credential.' Both teams are members of the same organization. The inventory is a single inventory source with separate groups. The credential has been assigned to the organization. What is the most likely cause of Team Beta's issue, and what is the correct solution?

Hard
5

Which THREE of the following are best practices for managing credentials in Ansible Automation Controller?

Hard
6

An administrator needs to store sensitive credentials for a playbook that will be run from a control node. The credentials include an SSH password and a sudo password. The administrator wants to keep these encrypted at rest and avoid hardcoding them in the playbook. Which TWO methods are valid for providing these credentials securely? (Choose two.)

Medium
7

An organization uses multiple Satellite servers for inventory. They want to combine data from all satellites into one unified inventory in Ansible Tower. Which approach is best?

Hard
8

Which THREE of the following are valid ways to define host variables in an Ansible inventory? (Choose exactly three.)

Medium
9

Match each Linux file system path to its typical content.

Medium
10

Refer to the exhibit. A user runs a playbook that creates hosts and then attempts to use a constructed inventory plugin. However, the constructed inventory does not group hosts by OS distribution. What is the most likely cause?

Medium
11

You run 'ansible-playbook -i inventory site.yml' and notice that a host defined in the inventory file is not targeted by a play with 'hosts: all'. The inventory file contains a group named 'ungrouped' with several hosts and a group named 'all_servers' with the same hosts. Which command most directly reveals whether Ansible is parsing the intended inventory source and listing that host under the expected groups?

Hard
12

An administrator needs to connect to a set of servers that use different SSH users: 'admin' for the 'web' group and 'deploy' for the 'db' group. The inventory file contains these groups. The administrator wants to avoid specifying the user in the playbook and wants the correct user to be used automatically for each group. Which method should be used?

Medium
13

Ansible Tower is configured with a dynamic inventory source from VMware vCenter. The playbook needs to limit execution to hosts with a specific custom attribute. How should this be achieved?

Medium
14

Which THREE considerations are important when using dynamic inventories in Ansible Tower?

Hard
15

An Ansible Tower administrator needs to create a custom credential type that uses an SSH private key and a username. Which THREE components should be defined in the credential type's configuration?

Hard
16

A playbook must connect to hosts using a non-default SSH private key stored at /home/student/.ssh/prod_key and a non-default remote user 'deploy'. The inventory file should apply these settings to all hosts in the 'production' group without editing the playbook. Which inventory variable combination is correct?

Medium
17

An Ansible playbook uses the `ansible_password` variable to connect to a Windows host. The value is stored in an encrypted Ansible Vault file. Which credential type in Automation Controller would allow the vault password to be supplied at runtime?

Easy
18

An administrator maintains a project directory with an inventory file `inventory.ini` that contains a group `db_servers` with hosts `db1.example.com` and `db2.example.com`. The playbook `site.yml` must run only against these two hosts, but the inventory also contains other groups. The administrator wants to avoid modifying the inventory file and instead use a command-line option to limit execution to `db_servers`. Which command should be used?

Medium
19

The inventory above is used in a job template in Automation Controller. The job template also has a machine credential assigned that specifies username 'root' and an SSH key. When the job runs against host web1, which username will Ansible use to connect?

Medium
20

A systems administrator needs to use a different SSH private key for a group of hosts in an Ansible inventory. Which inventory variable should be set at the group level?

Easy
21

A team uses a single Ansible Tower inventory called 'Production' containing hosts for multiple environments (dev, stage, prod). They want to apply different variables to hosts based on environment. Which inventory structure meets this requirement with minimal administrative overhead?

Hard
22

Which THREE considerations are important when designing a credential strategy in Ansible Automation Platform? (Choose exactly three.)

Hard
23

A junior admin wants to remove a credential from Ansible Tower. Which role-based access control permission is required to delete a credential?

Easy
24

Refer to the exhibit. A playbook includes this vars file and runs `systemctl restart httpd`. The playbook fails because it cannot decrypt the vault. Which of the following is the most likely cause?

Easy
25

An administrator needs to encrypt a sensitive variable file 'secrets.yml' using Ansible Vault so that it can be safely stored in a Git repository. The file should remain encrypted at rest but be automatically decrypted during playbook runs when the vault password is supplied. Which command correctly creates the encrypted file?

Easy
26

An administrator uses an inventory file with a group 'web' and a host 'web1' that also belongs to group 'db'. The group_vars/web.yml file sets 'http_port: 80', and group_vars/db.yml sets 'http_port: 3306'. The playbook uses 'http_port' to configure a service. What will be the value of http_port for web1 when the playbook runs?

Hard
27

A sysadmin receives an error when running a job template: 'ERROR! the role 'common' was not found in the specified roles path'. The role exists in a source control repository referenced in the project. What is the most likely cause?

Medium
28

An inventory is sourced from an external dynamic inventory plugin. The plugin returns hosts with groups including 'webservers' and 'dbservers'. An administrator wants to add a custom variable to all hosts in the 'webservers' group without modifying the plugin script. How can this be achieved?

Medium
29

You provision a new RHEL 9 control node and create a project directory at /home/devops/ansible. While testing connectivity with `ansible all -m ping`, every host returns UNREACHABLE, yet `ssh` from the shell to those same hosts works without a password. The inventory file at /home/devops/ansible/inventory defines the group `web` with `web1 ansible_host=10.20.30.41`. Which action most directly resolves the failure?

Easy
30

Drag and drop the steps to configure a systemd service to start automatically at boot in the correct order.

Medium
31

An administrator wants to create a custom credential type to store a third-party API key. The API key must be passed to the playbook as an environment variable `MY_API_KEY`. What is the correct Injector configuration in the custom credential type definition?

Medium
32

A junior admin is troubleshooting why a job template fails with 'Permission denied' when connecting to a target host. The job template uses a machine credential that appears correct. What is the first thing to check?

Easy
33

An administrator is using ansible-playbook with an inventory file that defines a group 'webservers' and a group 'dbservers'. The administrator wants to run a playbook only against hosts in 'webservers' but exclude any host that is also in 'dbservers'. Which inventory pattern should be used with the --limit option?

Medium
34

An administrator is creating a new inventory file for a small environment. The inventory must define a group `app` containing hosts `app1` and `app2`, and a group `db` containing host `db1`. The administrator wants to use the INI format. Which inventory file content correctly defines these groups?

Easy
35

A team uses Ansible Automation Controller with multiple organizations. Each organization has its own set of machines that require different SSH keys. The administrator wants to ensure that users from one organization cannot use credentials from another organization. What is the best way to achieve this isolation?

Hard
36

An administrator manages a static inventory file with a group `web` defined as children of `production`. The inventory also defines a group variable `http_port=80` at the `all` group level and `http_port=8080` at the `web` group level. A playbook targets `hosts: web` and uses `{{ http_port }}` in a template. Which value will be used for hosts in the `web` group?

Hard
37

Match each storage concept to its description.

Medium
38

An administrator needs to provide a set of credentials to a job template that requires a machine credential for SSH and a source control credential for the project. What is the correct way to associate these credentials?

Easy
39

An administrator manages a mixed fleet of Linux servers and Windows servers using Ansible Automation Platform. The Linux hosts are accessed via SSH keys, while the Windows hosts require WinRM with username and password. The administrator wants to define connection credentials in an inventory file so that playbooks can target both groups without specifying credentials in the playbook. Which inventory variable should be used to set the username for WinRM connections?

Easy
40

Which TWO statements about machine credentials in Ansible Tower are correct? (Choose two.)

Medium
41

A junior administrator needs to create an encrypted Ansible Vault password file for use with ansible-playbook. The vault password must be stored in a file named vault_pass.txt in the current directory. Which command should the administrator run?

Easy
42

A playbook run against a Windows host fails at the connection stage with an authentication error, although the inventory specifies `ansible_user: Administrator` and the correct password. Which inventory variable must be set so that Ansible uses the password-based WinRM connection instead of trying Kerberos or certificate authentication?

Hard
43

Your inventory directory `inventory/prod` contains a static hosts file plus a group_vars subdirectory with webservers.yml. A dynamic inventory plugin in the same directory returns the group `webservers` with a host-level variable `http_port` set to 8080. The static group_vars/webservers.yml sets `http_port: 80`. When a play runs against the webservers group, which value does the managed host receive for http_port?

Hard
44

An automation engineer manages two data centers with Ansible Automation Platform 2.4. The production inventory file is located at /etc/ansible/prod_inventory.ini and the staging inventory at /etc/ansible/stage_inventory.ini. The engineer wants to run a playbook against both inventories in a single ansible-playbook command, but the host groups must remain separate so that group_vars/prod and group_vars/stage apply correctly. Which command should the engineer use?

Medium
45

An Ansible administrator wants to use an encrypted vault file to store sensitive variables. Which command creates a new vault file and prompts for a password?

Easy
46

A playbook must run only against hosts that belong to both the `webservers` group and the `production` group. Your inventory defines these as separate groups, and a host named web3 is a member of both. Which inventory pattern restricts the play's hosts to exactly that intersection?

Hard
47

Which TWO statements about inventory groups in Ansible Automation Platform are correct? (Choose exactly two.)

Medium
48

An administrator maintains a dynamic inventory script that outputs JSON. The script is placed at `/etc/ansible/inventory/aws_inventory.py` and is executable. The administrator runs `ansible-playbook -i /etc/ansible/inventory/aws_inventory.py site.yml` but receives an error: "Unable to parse /etc/ansible/inventory/aws_inventory.py as an inventory source". Which action is most likely to resolve the issue?

Hard
49

An administrator is using Ansible Vault to protect sensitive variables in an inventory project. The project has a vault-encrypted file 'secrets.yml' that contains the variable 'db_password'. The playbook needs to use this variable. Which TWO statements are correct about using vault-encrypted variables in this scenario? (Choose two.)

Hard
50

An administrator maintains a static inventory file at /home/student/inventory that defines a group 'webservers' and a group 'dbservers'. A host named 'web1.example.com' must belong to both groups. Which INI snippet correctly assigns web1.example.com to both groups without creating duplicate host entries?

Medium
51

Your team stores two inventories: a static file at inventories/prod and a dynamic inventory plugin configuration at inventories/aws_ec2.yml. The static file defines the group `db` with `db1 ansible_host=172.16.5.10`, while the plugin also returns a host named db1 with the address 172.16.5.99. You run `ansible-inventory -i inventories/prod -i inventories/aws_ec2.yml --host db1`. Which host variable value does Ansible report for ansible_host?

Medium
52

A Red Hat Certified Engineer is managing an Ansible inventory that includes a mix of Linux and network devices. The network devices are running Cisco IOS and require the network_cli connection plugin. The engineer needs to specify the username and password for these devices in the inventory. Which inventory variables should be used to provide the credentials for the network devices?

Medium

Frequently asked questions

What does the Manage inventories and credentials domain cover on the EX294 exam?
Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.
How many questions are in this domain?
This page lists all 52 Manage inventories and credentials questions in the EX294 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Manage inventories and credentials questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
redhat-rhce REDHAT-RHCE inventories credentials Practice Questions