EX294 · domain
Manage inventories and credentials
This domain covers Ansible inventory construction and credential handling for automation execution. On EX294 you build static and dynamic inventories, assign host and group variables, and configure credentials used by automation controller job templates. Questions test correct YAML structure for inventory files, plugin configuration, and credential-to-template association rather than memorized menu paths.
Focused practice
Practice Manage inventories and credentials questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Manage inventories and credentials
Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.
Building static INI and YAML inventories with host groups, children, and group_vars directories
Configuring dynamic inventory plugins such as amazon.aws.aws_ec2 and community.general.proxmox with plugin YAML files
Defining group_vars and host_vars precedence for variables applied across inventory hosts
Associating machine, source control, and custom credential types with job templates in automation controller
Watch out for
Common Manage inventories and credentials exam traps
- ▸Placing group_vars in the wrong directory level so variables are not picked up by the intended group or hosts
- ▸Forgetting to enable a dynamic inventory plugin in ansible.cfg or omitting the plugin key in its configuration file
- ▸Confusing credential types when a job template needs both machine and source control credentials attached separately
Question index
All Manage inventories and credentials questions (52)
Click any question to see the full explanation, or start a practice session above.
An administrator is running `ansible-playbook -i inventories/prod site.yml` against the `prod` inventory, which contains a group `web` and a group `db`. The play is defined with `hosts: web:&db`. Which hosts will the play target?
Medium2You must store a database password that a playbook will use on managed nodes. Your security policy forbids clear-text secrets in the repository and requires that the secret remain usable with `ansible-playbook --vault-password-file /home/devops/.vault_pass`. Which two actions satisfy the policy? (Choose two.)
Medium3An administrator creates a group named `webservers` in an INI-style inventory and a group named `webservers` in a YAML inventory under the same inventory directory. Both groups define different hosts. What is the result when Ansible loads the inventory?
Easy4A company manages its infrastructure using Ansible Tower. There are two teams: Team Alpha manages web servers in the 'webservers' group, and Team Beta manages database servers in the 'dbservers' group. Both teams need to use the same SSH credential to connect to their respective servers. The credential is stored in Tower as 'shared_ssh_key'. Team Alpha reports that they can launch jobs against the 'webservers' group, but Team Beta gets an error when trying to launch jobs against the 'dbservers' group: 'You do not have permission to use this credential.' Both teams are members of the same organization. The inventory is a single inventory source with separate groups. The credential has been assigned to the organization. What is the most likely cause of Team Beta's issue, and what is the correct solution?
Hard5Which THREE of the following are best practices for managing credentials in Ansible Automation Controller?
Hard6An administrator needs to store sensitive credentials for a playbook that will be run from a control node. The credentials include an SSH password and a sudo password. The administrator wants to keep these encrypted at rest and avoid hardcoding them in the playbook. Which TWO methods are valid for providing these credentials securely? (Choose two.)
Medium7An organization uses multiple Satellite servers for inventory. They want to combine data from all satellites into one unified inventory in Ansible Tower. Which approach is best?
Hard8Which THREE of the following are valid ways to define host variables in an Ansible inventory? (Choose exactly three.)
Medium9Match each Linux file system path to its typical content.
Medium10Refer to the exhibit. A user runs a playbook that creates hosts and then attempts to use a constructed inventory plugin. However, the constructed inventory does not group hosts by OS distribution. What is the most likely cause?
Medium11You run 'ansible-playbook -i inventory site.yml' and notice that a host defined in the inventory file is not targeted by a play with 'hosts: all'. The inventory file contains a group named 'ungrouped' with several hosts and a group named 'all_servers' with the same hosts. Which command most directly reveals whether Ansible is parsing the intended inventory source and listing that host under the expected groups?
Hard12An administrator needs to connect to a set of servers that use different SSH users: 'admin' for the 'web' group and 'deploy' for the 'db' group. The inventory file contains these groups. The administrator wants to avoid specifying the user in the playbook and wants the correct user to be used automatically for each group. Which method should be used?
Medium13Ansible Tower is configured with a dynamic inventory source from VMware vCenter. The playbook needs to limit execution to hosts with a specific custom attribute. How should this be achieved?
Medium14Which THREE considerations are important when using dynamic inventories in Ansible Tower?
Hard15An Ansible Tower administrator needs to create a custom credential type that uses an SSH private key and a username. Which THREE components should be defined in the credential type's configuration?
Hard16A playbook must connect to hosts using a non-default SSH private key stored at /home/student/.ssh/prod_key and a non-default remote user 'deploy'. The inventory file should apply these settings to all hosts in the 'production' group without editing the playbook. Which inventory variable combination is correct?
Medium17An Ansible playbook uses the `ansible_password` variable to connect to a Windows host. The value is stored in an encrypted Ansible Vault file. Which credential type in Automation Controller would allow the vault password to be supplied at runtime?
Easy18An administrator maintains a project directory with an inventory file `inventory.ini` that contains a group `db_servers` with hosts `db1.example.com` and `db2.example.com`. The playbook `site.yml` must run only against these two hosts, but the inventory also contains other groups. The administrator wants to avoid modifying the inventory file and instead use a command-line option to limit execution to `db_servers`. Which command should be used?
Medium19The inventory above is used in a job template in Automation Controller. The job template also has a machine credential assigned that specifies username 'root' and an SSH key. When the job runs against host web1, which username will Ansible use to connect?
Medium20A systems administrator needs to use a different SSH private key for a group of hosts in an Ansible inventory. Which inventory variable should be set at the group level?
Easy21A team uses a single Ansible Tower inventory called 'Production' containing hosts for multiple environments (dev, stage, prod). They want to apply different variables to hosts based on environment. Which inventory structure meets this requirement with minimal administrative overhead?
Hard22Which THREE considerations are important when designing a credential strategy in Ansible Automation Platform? (Choose exactly three.)
Hard23A junior admin wants to remove a credential from Ansible Tower. Which role-based access control permission is required to delete a credential?
Easy24Refer to the exhibit. A playbook includes this vars file and runs `systemctl restart httpd`. The playbook fails because it cannot decrypt the vault. Which of the following is the most likely cause?
Easy25An administrator needs to encrypt a sensitive variable file 'secrets.yml' using Ansible Vault so that it can be safely stored in a Git repository. The file should remain encrypted at rest but be automatically decrypted during playbook runs when the vault password is supplied. Which command correctly creates the encrypted file?
Easy26An administrator uses an inventory file with a group 'web' and a host 'web1' that also belongs to group 'db'. The group_vars/web.yml file sets 'http_port: 80', and group_vars/db.yml sets 'http_port: 3306'. The playbook uses 'http_port' to configure a service. What will be the value of http_port for web1 when the playbook runs?
Hard27A sysadmin receives an error when running a job template: 'ERROR! the role 'common' was not found in the specified roles path'. The role exists in a source control repository referenced in the project. What is the most likely cause?
Medium28An inventory is sourced from an external dynamic inventory plugin. The plugin returns hosts with groups including 'webservers' and 'dbservers'. An administrator wants to add a custom variable to all hosts in the 'webservers' group without modifying the plugin script. How can this be achieved?
Medium29You provision a new RHEL 9 control node and create a project directory at /home/devops/ansible. While testing connectivity with `ansible all -m ping`, every host returns UNREACHABLE, yet `ssh` from the shell to those same hosts works without a password. The inventory file at /home/devops/ansible/inventory defines the group `web` with `web1 ansible_host=10.20.30.41`. Which action most directly resolves the failure?
Easy30Drag and drop the steps to configure a systemd service to start automatically at boot in the correct order.
Medium31An administrator wants to create a custom credential type to store a third-party API key. The API key must be passed to the playbook as an environment variable `MY_API_KEY`. What is the correct Injector configuration in the custom credential type definition?
Medium32A junior admin is troubleshooting why a job template fails with 'Permission denied' when connecting to a target host. The job template uses a machine credential that appears correct. What is the first thing to check?
Easy33An administrator is using ansible-playbook with an inventory file that defines a group 'webservers' and a group 'dbservers'. The administrator wants to run a playbook only against hosts in 'webservers' but exclude any host that is also in 'dbservers'. Which inventory pattern should be used with the --limit option?
Medium34An administrator is creating a new inventory file for a small environment. The inventory must define a group `app` containing hosts `app1` and `app2`, and a group `db` containing host `db1`. The administrator wants to use the INI format. Which inventory file content correctly defines these groups?
Easy35A team uses Ansible Automation Controller with multiple organizations. Each organization has its own set of machines that require different SSH keys. The administrator wants to ensure that users from one organization cannot use credentials from another organization. What is the best way to achieve this isolation?
Hard36An administrator manages a static inventory file with a group `web` defined as children of `production`. The inventory also defines a group variable `http_port=80` at the `all` group level and `http_port=8080` at the `web` group level. A playbook targets `hosts: web` and uses `{{ http_port }}` in a template. Which value will be used for hosts in the `web` group?
Hard37Match each storage concept to its description.
Medium38An administrator needs to provide a set of credentials to a job template that requires a machine credential for SSH and a source control credential for the project. What is the correct way to associate these credentials?
Easy39An administrator manages a mixed fleet of Linux servers and Windows servers using Ansible Automation Platform. The Linux hosts are accessed via SSH keys, while the Windows hosts require WinRM with username and password. The administrator wants to define connection credentials in an inventory file so that playbooks can target both groups without specifying credentials in the playbook. Which inventory variable should be used to set the username for WinRM connections?
Easy40Which TWO statements about machine credentials in Ansible Tower are correct? (Choose two.)
Medium41A junior administrator needs to create an encrypted Ansible Vault password file for use with ansible-playbook. The vault password must be stored in a file named vault_pass.txt in the current directory. Which command should the administrator run?
Easy42A playbook run against a Windows host fails at the connection stage with an authentication error, although the inventory specifies `ansible_user: Administrator` and the correct password. Which inventory variable must be set so that Ansible uses the password-based WinRM connection instead of trying Kerberos or certificate authentication?
Hard43Your inventory directory `inventory/prod` contains a static hosts file plus a group_vars subdirectory with webservers.yml. A dynamic inventory plugin in the same directory returns the group `webservers` with a host-level variable `http_port` set to 8080. The static group_vars/webservers.yml sets `http_port: 80`. When a play runs against the webservers group, which value does the managed host receive for http_port?
Hard44An automation engineer manages two data centers with Ansible Automation Platform 2.4. The production inventory file is located at /etc/ansible/prod_inventory.ini and the staging inventory at /etc/ansible/stage_inventory.ini. The engineer wants to run a playbook against both inventories in a single ansible-playbook command, but the host groups must remain separate so that group_vars/prod and group_vars/stage apply correctly. Which command should the engineer use?
Medium45An Ansible administrator wants to use an encrypted vault file to store sensitive variables. Which command creates a new vault file and prompts for a password?
Easy46A playbook must run only against hosts that belong to both the `webservers` group and the `production` group. Your inventory defines these as separate groups, and a host named web3 is a member of both. Which inventory pattern restricts the play's hosts to exactly that intersection?
Hard47Which TWO statements about inventory groups in Ansible Automation Platform are correct? (Choose exactly two.)
Medium48An administrator maintains a dynamic inventory script that outputs JSON. The script is placed at `/etc/ansible/inventory/aws_inventory.py` and is executable. The administrator runs `ansible-playbook -i /etc/ansible/inventory/aws_inventory.py site.yml` but receives an error: "Unable to parse /etc/ansible/inventory/aws_inventory.py as an inventory source". Which action is most likely to resolve the issue?
Hard49An administrator is using Ansible Vault to protect sensitive variables in an inventory project. The project has a vault-encrypted file 'secrets.yml' that contains the variable 'db_password'. The playbook needs to use this variable. Which TWO statements are correct about using vault-encrypted variables in this scenario? (Choose two.)
Hard50An administrator maintains a static inventory file at /home/student/inventory that defines a group 'webservers' and a group 'dbservers'. A host named 'web1.example.com' must belong to both groups. Which INI snippet correctly assigns web1.example.com to both groups without creating duplicate host entries?
Medium51Your team stores two inventories: a static file at inventories/prod and a dynamic inventory plugin configuration at inventories/aws_ec2.yml. The static file defines the group `db` with `db1 ansible_host=172.16.5.10`, while the plugin also returns a host named db1 with the address 172.16.5.99. You run `ansible-inventory -i inventories/prod -i inventories/aws_ec2.yml --host db1`. Which host variable value does Ansible report for ansible_host?
Medium52A Red Hat Certified Engineer is managing an Ansible inventory that includes a mix of Linux and network devices. The network devices are running Cisco IOS and require the network_cli connection plugin. The engineer needs to specify the username and password for these devices in the inventory. Which inventory variables should be used to provide the credentials for the network devices?
MediumOther domains
All EX294 exam domains
Frequently asked questions
- What does the Manage inventories and credentials domain cover on the EX294 exam?
- Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.
- How many questions are in this domain?
- This page lists all 52 Manage inventories and credentials questions in the EX294 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Manage inventories and credentials questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.