Courseiva

CCNA Manage inventories and credentials Questions

52 questions · Manage inventories and credentials · All types, answers revealed

1
MCQmedium

An administrator is running `ansible-playbook -i inventories/prod site.yml` against the `prod` inventory, which contains a group `web` and a group `db`. The play is defined with `hosts: web:&db`. Which hosts will the play target?

A.All hosts that are in both the `web` group and the `db` group
B.All hosts in the inventory except those in the `web` and `db` groups
C.Only the first host listed in the `web` group that also appears in `db`
D.All hosts that are in the `web` group or in the `db` group
AnswerA

In an Ansible host pattern, the `&` separator means intersection (logical AND). Writing `web:&db` selects only hosts that appear in the `web` group and also in the `db` group. This is the correct behavior: the pattern applies both group filters and targets the overlap, which is exactly what the play declares.

Why this answer

The `:&` syntax in a host pattern performs set intersection, so the play runs only against hosts that are members of both the `web` and `db` groups. The `:` alone would create a union, and a leading `!` would exclude. Because the play uses `web:&db`, the correct target set is the overlap of the two groups.

Exam trap

The trap here is confusing the colon union operator with the ampersand intersection operator, which leads to selecting every host in either group instead of the shared members.

2
Multi-Selectmedium

You must store a database password that a playbook will use on managed nodes. Your security policy forbids clear-text secrets in the repository and requires that the secret remain usable with `ansible-playbook --vault-password-file /home/devops/.vault_pass`. Which two actions satisfy the policy? (Choose two.)

Select 2 answers
A.Reference the password with `lookup('env', 'DB_PASSWORD')` so it is read from the environment at run time.
B.Create the secret with `ansible-vault encrypt_string --vault-password-file /home/devops/.vault_pass --name db_password` and paste the resulting block into the vars file.
C.Commit the password in a vars file and add the file path to a .gitignore entry in the repository root.
D.Store the password in a YAML file, run `ansible-vault encrypt db_vars.yml`, and reference it from the playbook with `vars_files`.
E.Define the password as an extra variable with `-e db_password=...` in the playbook invocation.
AnswersB, D

encrypt_string produces an inline encrypted variable that can be embedded directly in a YAML vars file while leaving the rest of the file readable in version control. Because it is encrypted with the same vault password, the playbook decrypts it transparently when run with the matching --vault-password-file, satisfying both the no-clear-text rule and the operational requirement.

Why this answer

Both accepted approaches produce artifacts encrypted with the same vault password that the required --vault-password-file supplies. Inline encryption with encrypt_string hides a single value inside an otherwise readable vars file, while encrypting an entire vars file protects a group of secrets referenced through vars_files. Each keeps clear-text secrets out of the repository while remaining fully usable at run time.

Exam trap

The trap here is treating .gitignore or environment-variable lookups as secret protection, when both leave the value readable in clear text.

3
MCQeasy

An administrator creates a group named `webservers` in an INI-style inventory and a group named `webservers` in a YAML inventory under the same inventory directory. Both groups define different hosts. What is the result when Ansible loads the inventory?

A.Ansible raises a duplicate group error and refuses to load either inventory
B.Only the YAML definition is used because YAML takes precedence over INI
C.The two group definitions are merged, and the group contains the union of hosts from both files
D.The group from the first parsed file wins and the second group definition is ignored
AnswerC

When multiple inventory sources define the same group name, Ansible merges them and the group contains all hosts from every definition. Group membership is additive across sources, so the `webservers` group ends up with the combined host list. This is the expected behavior when an inventory directory contains both INI and YAML files.

Why this answer

Ansible merges group membership across all loaded inventory sources. When the same group name appears in an INI file and a YAML file, the group ends up containing the union of hosts from both definitions. There is no duplicate error and no format-based precedence for group membership.

Exam trap

The trap here is assuming that duplicate group names across inventory files cause an error or that one file format overrides another, when membership is actually merged.

4
MCQhard

A company manages its infrastructure using Ansible Tower. There are two teams: Team Alpha manages web servers in the 'webservers' group, and Team Beta manages database servers in the 'dbservers' group. Both teams need to use the same SSH credential to connect to their respective servers. The credential is stored in Tower as 'shared_ssh_key'. Team Alpha reports that they can launch jobs against the 'webservers' group, but Team Beta gets an error when trying to launch jobs against the 'dbservers' group: 'You do not have permission to use this credential.' Both teams are members of the same organization. The inventory is a single inventory source with separate groups. The credential has been assigned to the organization. What is the most likely cause of Team Beta's issue, and what is the correct solution?

A.Grant Team Beta the 'Use' role on the credential 'shared_ssh_key'.
B.Create a new credential with the same SSH key and assign it to Team Beta.
C.Assign the credential to the dbservers group in the inventory.
D.Move the credential from the organization to the project level.
AnswerA

Tower roles are scoped per object, not inherited from organisation membership. Team Alpha holds a Use role on the credential; Team Beta does not, so job launch is refused. Granting Team Beta the Use role on 'shared_ssh_key' satisfies the credential-permission constraint.

Why this answer

In Ansible Tower, credentials are assigned to an organization, but users or teams must be explicitly granted the 'Use' role on a credential to be able to use it in a job template. Team Alpha can use the credential because they likely have the 'Use' role, while Team Beta does not. Granting Team Beta the 'Use' role on 'shared_ssh_key' resolves the permission error.

Exam trap

The trap here is that candidates assume assigning a credential to an organization automatically grants all members the right to use it, but Tower requires explicit 'Use' role assignment for each team or user.

How to eliminate wrong answers

Option B is wrong because creating a duplicate credential violates the principle of least privilege and adds unnecessary management overhead; the existing credential can be shared by granting the 'Use' role. Option C is wrong because credentials are not assigned to inventory groups in Tower; they are assigned to organizations, projects, or job templates, and the error is about credential permissions, not inventory group assignments. Option D is wrong because moving the credential to the project level does not change the fact that Team Beta lacks the 'Use' role; the credential would still require explicit role assignment for the team to use it.

5
Multi-Selecthard

Which THREE of the following are best practices for managing credentials in Ansible Automation Controller?

Select 3 answers
A.Avoid using external secret management systems; keep all secrets in Automation Controller
B.Share the same credential across multiple organizations for simplicity
C.Restrict credential 'Use' permissions to specific users or teams
D.Use custom credential types to store secrets for third-party APIs
E.Use Vault credentials to store and encrypt sensitive variables in playbooks
AnswersC, D, E

This ensures only authorized users can use the credential.

Why this answer

Ansible Automation Controller's Role-Based Access Control (RBAC) allows administrators to assign granular 'Use' permissions to specific users or teams, ensuring that only authorized entities can leverage a credential for job runs. This prevents unauthorized access to sensitive secrets and aligns with the principle of least privilege, which is a core security best practice in automation environments.

Exam trap

The trap here is that candidates may think storing all secrets inside Automation Controller is safer than using an external vault, but Red Hat specifically recommends integrating with external secret managers for centralized control and rotation, making Option A a common misconception.

6
Multi-Selectmedium

An administrator needs to store sensitive credentials for a playbook that will be run from a control node. The credentials include an SSH password and a sudo password. The administrator wants to keep these encrypted at rest and avoid hardcoding them in the playbook. Which TWO methods are valid for providing these credentials securely? (Choose two.)

Select 2 answers
A.Define the passwords as extra variables using the -e option on the command line, like -e "ansible_password=secret".
B.Set the passwords as environment variables on the control node and reference them with lookup('env', 'SSH_PASSWORD') in the playbook.
C.Use the ansible.builtin.debug module to print the passwords from a vault-encrypted file, then manually copy them into the playbook.
D.Store the passwords in the inventory file as host variables, and encrypt the inventory file with ansible-vault.
E.Use ansible-vault to encrypt a vars file containing the passwords, and include it with vars_files in the playbook.
AnswersD, E

Inventory files can contain host variables, including ansible_password and ansible_become_password. Encrypting the entire inventory file with ansible-vault protects the credentials at rest. Ansible can decrypt the inventory at runtime if the vault password is provided. This method is valid and keeps sensitive data encrypted, meeting the requirement.

Why this answer

Ansible Vault is the primary tool for encrypting sensitive data at rest. Encrypting a vars file and including it with vars_files, or encrypting an inventory file that contains host variables, both securely provide passwords to playbooks. The vault password can be supplied separately.

Command-line extra vars, debug printing, and environment variables either expose secrets or fail to encrypt them at rest, so they are not valid secure methods.

Exam trap

The trap here is thinking that any method that supplies the password value is acceptable, ignoring the need for encryption at rest and avoidance of exposure in logs or process lists.

7
MCQhard

An organization uses multiple Satellite servers for inventory. They want to combine data from all satellites into one unified inventory in Ansible Tower. Which approach is best?

A.Use a custom script to fetch and merge data from all Satellites into a single inventory source.
B.Create a smart inventory that includes all satellites.
C.Use a single Satellite server that aggregates data from all other Satellites.
D.Create one inventory with multiple inventory sources, each pointing to a different Satellite.
AnswerD

A single inventory with multiple sources lets Tower merge hosts from every Satellite into one unified view, satisfying the requirement to combine all satellites' data. Each source syncs independently, and Tower deduplicates hosts sharing a name, so overlapping entries collapse rather than duplicate.

Why this answer

Ansible Tower allows you to create a single inventory with multiple inventory sources, each configured to sync from a different Satellite server. This approach consolidates all host data into one unified inventory without custom scripting or requiring a central aggregator, leveraging Tower's native multi-source inventory capabilities.

Exam trap

The trap here is that candidates may confuse 'smart inventory' with the ability to aggregate external sources, but smart inventories only filter existing inventory data and cannot import from multiple external sources directly.

How to eliminate wrong answers

Option A is wrong because using a custom script to fetch and merge data introduces unnecessary complexity, maintenance overhead, and bypasses Tower's built-in inventory source management, which is designed for this exact use case. Option B is wrong because a smart inventory filters hosts based on existing inventory data and cannot directly import data from multiple external sources like Satellite servers; it requires a pre-populated inventory. Option C is wrong because requiring a single Satellite server to aggregate data from others adds an extra layer of infrastructure and defeats the purpose of using multiple independent Satellite servers, which Tower can directly query.

8
Multi-Selectmedium

Which THREE of the following are valid ways to define host variables in an Ansible inventory? (Choose exactly three.)

Select 3 answers
A.In the 'extra_vars' field of the job template.
B.Inline in the inventory file, e.g., 'myhost ansible_host=192.168.1.1 http_port=8080'.
C.In a credential's 'Input Configuration' as a secret variable.
D.In a 'group_vars/<groupname>' file, if the host belongs to that group.
E.In a 'host_vars/<hostname>' file within the project.
AnswersB, D, E

Variables can be assigned directly in the inventory file.

Why this answer

Ansible allows inline host variable definitions directly in the inventory file using key=value pairs after the hostname. This is a standard syntax where variables like 'http_port=8080' are assigned to the host 'myhost' and become available as Ansible facts during playbook execution. The 'ansible_host' special variable is also defined this way to override the connection address.

Exam trap

The trap here is that candidates confuse runtime variable injection methods (like extra_vars or credentials) with static inventory variable definitions, leading them to select options that are valid for passing variables but not for defining host variables in an inventory.

9
Matchingmedium

Match each Linux file system path to its typical content.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Configuration files

Variable data (logs, databases)

User system resources (binaries, libraries)

Temporary files

Process and kernel information

Why these pairings

In Red Hat Enterprise Linux, standard directories follow the Filesystem Hierarchy Standard (FHS). /etc holds configuration files, /home stores user home directories, and /boot contains boot loader files and kernel images. Common confusions include mixing /var (variable data like logs) with /tmp (temporary files) and associating log files incorrectly with /tmp.

10
MCQmedium

Refer to the exhibit. A user runs a playbook that creates hosts and then attempts to use a constructed inventory plugin. However, the constructed inventory does not group hosts by OS distribution. What is the most likely cause?

A.The constructed plugin cannot be used with the add_host module.
B.The 'strict: false' setting ignores missing variables, causing the group to be empty.
C.The constructed inventory runs before add_host tasks, so the hosts are not yet created.
D.The variable ansible_distribution is not defined because gather_facts is set to no.
AnswerC

Constructed inventory plugins parse existing inventory sources at the start of a play; hosts added mid-play via add_host exist only in memory and are never written back. Because the inventory is built before those tasks execute, the OS distribution groups cannot be populated.

Why this answer

The constructed inventory plugin processes inventory sources and applies Jinja2 conditions to group hosts based on variables. However, when used in a playbook alongside the `add_host` module, the constructed inventory is evaluated at the start of the play, before any tasks (including `add_host`) run. Therefore, hosts added dynamically via `add_host` do not exist when the constructed plugin attempts to group them, causing the groups to be empty.

Option C correctly identifies this ordering issue.

Exam trap

Red Hat often tests the misconception that inventory plugins and dynamic host creation (`add_host`) operate in the same phase, when in fact the constructed plugin runs during inventory loading (pre-task) while `add_host` runs during task execution, creating a timing mismatch that candidates overlook.

How to eliminate wrong answers

Option A is wrong because the constructed plugin can absolutely be used with hosts created by `add_host` — the issue is not compatibility but execution order. Option B is wrong because `strict: false` does not cause groups to be empty; it merely suppresses errors when a variable is undefined, but if the hosts themselves are not yet present, no grouping can occur regardless of strict mode. Option D is wrong because even if `gather_facts` is set to `no`, the constructed plugin can still use other variables or static facts; the core problem remains that the hosts are not yet added to the inventory at the time the plugin runs.

11
MCQhard

You run 'ansible-playbook -i inventory site.yml' and notice that a host defined in the inventory file is not targeted by a play with 'hosts: all'. The inventory file contains a group named 'ungrouped' with several hosts and a group named 'all_servers' with the same hosts. Which command most directly reveals whether Ansible is parsing the intended inventory source and listing that host under the expected groups?

A.ansible-config dump --only-changed
B.ansible-inventory -i inventory --list
C.ansible all -i inventory -m ping
D.ansible-doc -t inventory -l
AnswerB

The ansible-inventory --list command parses the specified inventory and outputs a JSON representation of all groups and hosts, showing exactly which groups each host belongs to. It confirms whether the host is present and under which group names, making it the most direct diagnostic for inventory parsing issues.

Why this answer

The ansible-inventory --list command is designed to parse an inventory source and emit the resulting groups, hosts, and variables as JSON. It is the definitive tool for confirming how Ansible interprets an inventory file, including group membership and host listing.

Exam trap

The trap here is reaching for connectivity tests or configuration dumps when the issue is inventory parsing, whereas ansible-inventory directly exposes the parsed inventory structure.

12
MCQmedium

An administrator needs to connect to a set of servers that use different SSH users: 'admin' for the 'web' group and 'deploy' for the 'db' group. The inventory file contains these groups. The administrator wants to avoid specifying the user in the playbook and wants the correct user to be used automatically for each group. Which method should be used?

A.Set the remote_user directive in the playbook and use a variable that changes per group.
B.Define ansible_user in host_vars for each host individually, using the correct user for that host's group.
C.Use the --user command-line option with a comma-separated list of users for each group.
D.Set ansible_user in the [web:vars] and [db:vars] sections of the inventory file.
AnswerD

Inventory files support group variables via [group:vars] sections. Setting ansible_user in [web:vars] and [db:vars] assigns the correct SSH user to all hosts in each group automatically. This is a clean, inventory-based solution that requires no playbook changes and ensures the right user is used per group.

Why this answer

Setting ansible_user in [group:vars] sections of the inventory file assigns the correct SSH user to all hosts in each group. This is a standard inventory feature that automatically applies group-specific connection variables. It requires no playbook modifications and ensures the right user is used for web and db hosts without manual per-host configuration.

Exam trap

The trap here is assuming that command-line options like --user can specify different users per group, when they apply globally to the entire playbook run.

13
MCQmedium

Ansible Tower is configured with a dynamic inventory source from VMware vCenter. The playbook needs to limit execution to hosts with a specific custom attribute. How should this be achieved?

A.Modify the VMware inventory script to filter hosts.
B.Use a smart inventory filter.
C.Add the required hosts manually.
D.Create a new inventory source with a filter.
AnswerB

Smart inventory filters let you define host criteria using facts and attributes, so the playbook runs only against vCenter hosts matching the custom attribute. A static group would not track the dynamic inventory source's changing membership.

Why this answer

Smart inventories in Ansible Tower allow you to apply a filter (using Jinja2-style syntax) against an existing inventory source, such as a dynamic VMware vCenter source, to limit execution to hosts matching specific criteria like a custom attribute. This approach avoids modifying the source script or creating duplicate inventory sources, preserving the dynamic nature of the inventory while enabling targeted host selection.

Exam trap

The trap here is that candidates may think they need to modify the inventory source or script to filter hosts, not realizing that Tower's smart inventories provide a built-in, non-destructive way to apply filters on top of any existing inventory source.

How to eliminate wrong answers

Option A is wrong because modifying the VMware inventory script is not a supported or scalable method in Tower; it would break the dynamic inventory source and require manual maintenance. Option C is wrong because manually adding hosts defeats the purpose of using a dynamic inventory from vCenter and introduces management overhead. Option D is wrong because creating a new inventory source with a filter is unnecessary; smart inventories provide the filtering capability without duplicating the source, and filters are applied at the smart inventory level, not at the source level.

14
Multi-Selecthard

Which THREE considerations are important when using dynamic inventories in Ansible Tower?

Select 3 answers
A.Dynamic inventory groups can be nested under static groups.
B.Each inventory source can be assigned to multiple inventories.
C.The inventory source must have a defined credential for authentication to the cloud provider.
D.Custom inventory scripts must be placed in the Tower home directory.
E.Inventory sources can update automatically on a schedule.
AnswersA, C, E

Group hierarchies can mix static and dynamic groups.

Why this answer

Ansible Tower allows dynamic inventory groups to be nested under static groups, enabling a hybrid inventory structure where cloud-sourced hosts can be organized within manually defined static groups for more flexible automation targeting. This is supported by the Tower inventory model, which merges static and dynamic sources into a unified group hierarchy.

Exam trap

The trap here is that candidates may confuse the one-to-many relationship of inventory sources to inventories (Option B) with the actual one-to-one constraint, or assume custom scripts must reside in a specific directory (Option D) when Tower actually supports flexible script paths via projects or absolute paths.

15
Multi-Selecthard

An Ansible Tower administrator needs to create a custom credential type that uses an SSH private key and a username. Which THREE components should be defined in the credential type's configuration?

Select 3 answers
A."fields": [{"id": "ssh_key_data", "type": "string", "label": "SSH Private Key", "multiline": true, "secret": true}]
B."fields": [{"id": "password", "type": "string", "label": "Password"}]
C."fields": [{"id": "key_type", "type": "string", "label": "Key Type"}]
D."fields": [{"id": "username", "type": "string", "label": "Username"}]
E."injectors": {"extra_vars": {"ansible_user": "{{ username }}", "ansible_ssh_private_key_file": "{{ ssh_key_data }}"}}
AnswersA, D, E

Input field for SSH private key content.

Why this answer

The SSH private key must be defined as a field with `"type": "string"`, `"multiline": true` (since SSH keys are multi-line), and `"secret": true` (to encrypt the value in the database). This matches the standard Ansible Tower custom credential type schema for storing sensitive key material.

Exam trap

The trap here is that candidates often add unnecessary fields like 'password' or 'key type' because they confuse SSH key-based authentication with password-based authentication, or they think the key format must be explicitly specified.

16
MCQmedium

A playbook must connect to hosts using a non-default SSH private key stored at /home/student/.ssh/prod_key and a non-default remote user 'deploy'. The inventory file should apply these settings to all hosts in the 'production' group without editing the playbook. Which inventory variable combination is correct?

A.[production:vars] private_key_file=/home/student/.ssh/prod_key remote_user=deploy
B.[production:vars] ansible_ssh_private_key_file=/home/student/.ssh/prod_key ansible_user=deploy
C.[production:vars] ssh_private_key_file=/home/student/.ssh/prod_key user=deploy
D.[production:vars] ansible_ssh_key=/home/student/.ssh/prod_key ansible_remote_user=deploy
AnswerB

The ansible_ssh_private_key_file variable tells Ansible which private key to use for SSH authentication, and ansible_user sets the remote login name. Defining both under a [production:vars] section applies them to every host in the production group, exactly matching the requirement without playbook changes.

Why this answer

Ansible uses connection variables prefixed with ansible_ to override SSH behavior. ansible_ssh_private_key_file specifies the key, and ansible_user sets the remote user. Placing them in a group vars section applies them to all hosts in that group, satisfying the scenario without modifying the playbook.

Exam trap

The trap here is using plausible but incorrect variable names such as private_key_file or ansible_remote_user instead of the actual Ansible connection variables.

17
MCQeasy

An Ansible playbook uses the `ansible_password` variable to connect to a Windows host. The value is stored in an encrypted Ansible Vault file. Which credential type in Automation Controller would allow the vault password to be supplied at runtime?

A.Cloud credential
B.Machine credential
C.Vault credential
D.Network credential
AnswerC

A Vault credential stores the Ansible Vault password separately from machine credentials, letting Automation Controller decrypt vault-encrypted variables such as ansible_password at runtime. It satisfies the requirement to supply the vault password without embedding it in the playbook.

Why this answer

Automation Controller's Vault credential type is specifically designed to provide the vault password needed to decrypt Ansible Vault-encrypted variables like `ansible_password`. When a job runs, the controller uses this credential to unlock the vault file, allowing the playbook to access the encrypted value at runtime without exposing the plaintext password.

Exam trap

The trap here is that candidates confuse the credential type used to authenticate to the target host (Machine credential) with the credential type needed to decrypt the vault file containing the host's password, leading them to select Option B instead of C.

How to eliminate wrong answers

Option A is wrong because Cloud credentials are used to authenticate against cloud providers (e.g., AWS, Azure, GCP) and have no mechanism to supply a vault password for decrypting Ansible Vault files. Option B is wrong because Machine credentials provide SSH keys or username/password for connecting to target hosts, not the vault password needed to decrypt encrypted variables stored in vault files. Option D is wrong because Network credentials are used for network device authentication (e.g., via SSH or API tokens) and do not support supplying vault passwords for Ansible Vault decryption.

18
MCQmedium

An administrator maintains a project directory with an inventory file `inventory.ini` that contains a group `db_servers` with hosts `db1.example.com` and `db2.example.com`. The playbook `site.yml` must run only against these two hosts, but the inventory also contains other groups. The administrator wants to avoid modifying the inventory file and instead use a command-line option to limit execution to `db_servers`. Which command should be used?

A.ansible-playbook -i inventory.ini site.yml --limit db_servers
B.ansible-playbook -i inventory.ini site.yml --start-at-task db_servers
C.ansible-playbook -i inventory.ini site.yml -e "target=db_servers"
D.ansible-playbook -i inventory.ini site.yml --tags db_servers
AnswerA

The --limit option restricts execution to the specified subset of hosts. Using the group name db_servers correctly targets only hosts in that group. This is the intended mechanism to override the play's host pattern without editing the inventory. The command assumes the playbook's hosts directive matches a broader pattern, but --limit applies on top. It is the correct approach for the scenario.

Why this answer

The --limit option is the correct way to restrict a playbook run to a subset of hosts defined in the inventory, such as a group. It overrides the play's host pattern without modifying the inventory or playbook. The other options either pass variables, control task execution, or filter tags, none of which select hosts.

Thus, only --limit db_servers targets the intended group.

Exam trap

The trap here is confusing host-limiting options with task-limiting or variable-passing options, assuming that any extra flag can restrict execution to a group.

19
MCQmedium

The inventory above is used in a job template in Automation Controller. The job template also has a machine credential assigned that specifies username 'root' and an SSH key. When the job runs against host web1, which username will Ansible use to connect?

A.admin (from inventory host variable)
B.The username set in the job template's 'extra variables'
C.The first defined username in the credential chain
D.root (from credential)
AnswerA

Inventory host variables take precedence over the machine credential's username when Ansible resolves connection parameters for a host. The web1 host variable ansible_user set to admin therefore overrides root, satisfying the precedence rule demonstrated in the inventory.

Why this answer

Ansible uses a specific precedence order for determining the connection user. When a host variable (like `ansible_user: admin`) is defined in the inventory for host web1, it overrides the username set in the job template's machine credential. The credential's username ('root') acts only as a fallback if no `ansible_user` is defined at the host or group level.

Exam trap

The trap here is that candidates assume the credential's username is always used, forgetting that inventory host variables (like `ansible_user`) override credential settings, a common point of confusion in Ansible's variable precedence hierarchy.

How to eliminate wrong answers

Option B is wrong because extra variables in the job template do not directly set the connection username; they are used for playbook variables, not for the SSH user unless explicitly referenced via `ansible_user` in the extra vars. Option C is wrong because there is no 'credential chain' that selects the first username; Ansible uses a deterministic precedence: host vars > group vars > credential username > default (current user). Option D is wrong because the credential's username ('root') is overridden by the host variable `ansible_user: admin` defined in the inventory for web1.

20
MCQeasy

A systems administrator needs to use a different SSH private key for a group of hosts in an Ansible inventory. Which inventory variable should be set at the group level?

A.ansible_ssh_key
B.ansible_ssh_private_key_file
C.ansible_ssh_key_file
D.ansible_private_key
AnswerB

ansible_ssh_private_key_file is the inventory variable that specifies the SSH private key used for authentication. Setting it at group level applies that key to every host in the group, satisfying the requirement to use a different key for those hosts.

Why this answer

`ansible_ssh_private_key_file` is the Ansible inventory variable that specifies the path to the SSH private key file for a host or group. When set at the group level, it applies to all hosts in that group, allowing the administrator to use a different key for authentication without modifying individual host definitions.

Exam trap

The trap here is that candidates confuse the variable name with similar-sounding but invalid options like `ansible_ssh_key` or `ansible_private_key`, forgetting that Ansible requires the exact `ansible_ssh_private_key_file` syntax to specify a private key file path.

How to eliminate wrong answers

Option A is wrong because `ansible_ssh_key` is not a valid Ansible variable; the correct variable name includes `private_key_file` to indicate the file path. Option C is wrong because `ansible_ssh_key_file` is not a recognized variable; Ansible uses `ansible_ssh_private_key_file` to avoid ambiguity with public keys. Option D is wrong because `ansible_private_key` omits the `ssh` connection plugin prefix and the `file` suffix, making it an invalid variable that Ansible will ignore.

21
MCQhard

A team uses a single Ansible Tower inventory called 'Production' containing hosts for multiple environments (dev, stage, prod). They want to apply different variables to hosts based on environment. Which inventory structure meets this requirement with minimal administrative overhead?

A.Create groups within the inventory for each environment (e.g., 'dev', 'stage', 'prod') and assign variables at the group level.
B.Assign variables directly to each host using the 'Host Variables' field in the inventory.
C.Add tags to each host and use the tags to filter variables in the job template.
D.Create separate inventories for each environment and link them to the same project.
AnswerA

Grouping hosts by environment inside the single Production inventory and assigning variables at group level applies environment-specific values automatically, satisfying the minimal administrative overhead constraint. No duplicate inventories or per-host variable files are needed, and group variables inherit cleanly.

Why this answer

Ansible Tower (now Red Hat Ansible Automation Platform) supports group-based variable inheritance within a single inventory. By creating groups for each environment (dev, stage, prod) and assigning variables at the group level, you can apply environment-specific variables to all hosts in that group with minimal administrative overhead. This leverages Tower's built-in group variable mechanism without requiring per-host edits or multiple inventory objects.

Exam trap

The trap here is that candidates often confuse tags (which are for job template filtering and RBAC) with group variables (which are for host-level data), leading them to select option C despite tags having no role in variable assignment.

How to eliminate wrong answers

Option B is wrong because assigning variables directly to each host via the 'Host Variables' field creates significant administrative overhead when managing many hosts, as each host must be individually configured, and it does not scale well for environment-wide changes. Option C is wrong because tags in Ansible Tower are used for job template filtering and access control, not for variable assignment; variables cannot be conditionally applied based on tags within an inventory. Option D is wrong because creating separate inventories for each environment increases administrative overhead by requiring multiple inventory objects to be maintained and linked to the same project, and it does not leverage the single-inventory structure specified in the question.

22
Multi-Selecthard

Which THREE considerations are important when designing a credential strategy in Ansible Automation Platform? (Choose exactly three.)

Select 3 answers
A.All credentials must be stored within the AAP database for security
B.Playbooks should contain hardcoded credentials for simplicity
C.Credentials should be assigned to job templates rather than embedded in playbooks
D.Custom credential types allow integration with external secrets management systems
E.Credential access can be restricted using RBAC on organizations, teams, and users
AnswersC, D, E

Best practice is to manage credentials via AAP and assign them to templates.

Why this answer

Ansible Automation Platform (AAP) best practices dictate that credentials should be assigned to job templates, not embedded in playbooks. This decouples sensitive authentication data from automation logic, allowing credentials to be managed, rotated, and audited centrally through the AAP controller without exposing them in version-controlled playbook files.

Exam trap

The trap here is that candidates often assume all credentials must be stored inside the AAP database for security, but the platform is designed to delegate secret storage to external vaults, and the question tests awareness of that flexibility.

23
MCQeasy

A junior admin wants to remove a credential from Ansible Tower. Which role-based access control permission is required to delete a credential?

A.Read
B.Use
C.Execute
D.Admin
AnswerD

Deleting a credential is an administrative operation, so the Admin role is required; lesser roles such as Auditor or Execute only grant read or job-run rights. This satisfies the stem's requirement for the permission that authorises credential deletion.

Why this answer

In Ansible Tower, the Admin role is the only role that grants full management permissions, including the ability to delete credentials. Lower-level roles like Read, Use, and Execute only allow viewing or using credentials, not modifying or deleting them. This aligns with Tower's RBAC hierarchy where Admin is required for destructive actions on any resource.

Exam trap

The trap here is that candidates often confuse the 'Use' role with full management permissions, but 'Use' only allows credential consumption in job templates, not deletion or modification.

How to eliminate wrong answers

Option A is wrong because the Read role only allows viewing credentials, not deleting them. Option B is wrong because the Use role permits using a credential in a job template but does not grant deletion rights. Option C is wrong because the Execute role applies to job templates and projects, not to credential management, and does not include delete permissions.

24
MCQeasy

Refer to the exhibit. A playbook includes this vars file and runs `systemctl restart httpd`. The playbook fails because it cannot decrypt the vault. Which of the following is the most likely cause?

A.The vault ID is missing.
B.The variable db_password is not used in the playbook.
C.The vault password is not provided.
D.The vault file is corrupted.
AnswerC

Ansible Vault decrypts encrypted variables only when the vault password is supplied via --ask-vault-pass, a vault password file, or vault_password_file in ansible.cfg. Without it, decryption fails and the playbook aborts before systemctl restart httpd executes.

Why this answer

The error 'cannot decrypt the vault' indicates that Ansible is unable to decrypt the vault-encrypted variable file. This occurs when the vault password is not provided via `--ask-vault-pass`, `--vault-password-file`, or the `ANSIBLE_VAULT_PASSWORD_FILE` environment variable. Without the correct password, Ansible cannot decrypt the vault, causing the playbook to fail.

Exam trap

Red Hat often tests the distinction between vault ID (which is optional) and vault password (which is mandatory), leading candidates to incorrectly select 'vault ID is missing' when the actual issue is the missing password.

How to eliminate wrong answers

Option A is wrong because a vault ID is optional; Ansible can decrypt vaults without an ID if the password matches, and the error message does not indicate a missing ID. Option B is wrong because whether `db_password` is used in the playbook is irrelevant to the decryption failure; the vault file is loaded regardless of variable usage. Option D is wrong because a corrupted vault file would typically produce a different error (e.g., 'Vault format error' or 'HMAC mismatch'), not a generic 'cannot decrypt' message.

25
MCQeasy

An administrator needs to encrypt a sensitive variable file 'secrets.yml' using Ansible Vault so that it can be safely stored in a Git repository. The file should remain encrypted at rest but be automatically decrypted during playbook runs when the vault password is supplied. Which command correctly creates the encrypted file?

A.ansible-vault rekey secrets.yml --new-vault-password-file newpass.txt
B.ansible-vault create secrets.yml --encrypt-vault-id default
C.ansible-vault encrypt_string secrets.yml --name secrets
D.ansible-vault encrypt secrets.yml --vault-password-file vault_pass.txt
AnswerD

The ansible-vault encrypt command encrypts an existing file in place, and --vault-password-file specifies the file containing the vault password. This produces an encrypted secrets.yml that Ansible can decrypt at runtime when the same password file is provided, meeting the requirement for secure storage and automatic decryption.

Why this answer

The ansible-vault encrypt command is the correct tool to encrypt an existing plaintext file. Using --vault-password-file provides the password non-interactively, enabling automation. The resulting file remains encrypted at rest and is decrypted automatically during playbook runs when the same vault password is supplied.

Exam trap

The trap here is confusing ansible-vault encrypt with create or encrypt_string, which serve different purposes, or using rekey on a plaintext file.

26
MCQhard

An administrator uses an inventory file with a group 'web' and a host 'web1' that also belongs to group 'db'. The group_vars/web.yml file sets 'http_port: 80', and group_vars/db.yml sets 'http_port: 3306'. The playbook uses 'http_port' to configure a service. What will be the value of http_port for web1 when the playbook runs?

A.3306, because the 'db' group is alphabetically before 'web'.
B.The playbook will fail with an error because http_port is defined in two groups.
C.80, because group_vars/web.yml takes precedence over group_vars/db.yml for hosts in both groups.
D.80, because the 'web' group appears first in the inventory file.
AnswerC

Ansible merges group variables for a host by processing groups in alphabetical order, with later groups overriding earlier ones. Since 'web' comes after 'db' alphabetically, variables from group_vars/web.yml override those from group_vars/db.yml. Therefore, http_port is 80 for web1. This is the correct precedence rule for group variables at the same level.

Why this answer

When a host belongs to multiple groups, Ansible merges group variables by processing groups in alphabetical order. Later groups override earlier ones. 'db' precedes 'web' alphabetically, so variables from group_vars/web.yml override those from group_vars/db.yml. Thus http_port becomes 80.

Inventory file order and duplicate definitions do not cause errors; precedence rules apply.

Exam trap

The trap here is thinking that inventory file order or a failure occurs when a variable is defined in multiple groups, when actually alphabetical group order determines the final value.

27
MCQmedium

A sysadmin receives an error when running a job template: 'ERROR! the role 'common' was not found in the specified roles path'. The role exists in a source control repository referenced in the project. What is the most likely cause?

A.The inventory does not include the target hosts
B.The project's source control sync failed, so the roles directory is empty
C.The job template is configured with an incorrect schedule
D.The credential used does not have access to the source control repository
AnswerB

A failed project sync leaves the local checkout without the roles directory, so Ansible's configured roles path contains no `common` role and the lookup fails. The stem states the role exists only in source control, making a stale or empty working copy the direct cause of the not-found error.

Why this answer

The error indicates that Ansible cannot find the 'common' role in the specified roles path. Since the role exists in the source control repository referenced by the project, the most likely cause is that the project's source control sync failed, leaving the roles directory empty or incomplete. Without a successful sync, the role files are not present on the Ansible control node, causing the job template execution to fail.

Exam trap

The trap here is that candidates may confuse a credential failure (Option D) with a sync failure, but the error message specifically points to a missing role file, not an authentication issue, and the sync failure is the direct cause of the missing role.

How to eliminate wrong answers

Option A is wrong because the inventory not including target hosts would cause a different error, such as 'No hosts matched' or a failure to connect, not a missing role error. Option C is wrong because an incorrect schedule would prevent the job from running at the intended time but would not cause a missing role error during execution. Option D is wrong because if the credential lacked access to the source control repository, the project sync would fail with an authentication or authorization error, not a missing role error after a successful sync.

28
MCQmedium

An inventory is sourced from an external dynamic inventory plugin. The plugin returns hosts with groups including 'webservers' and 'dbservers'. An administrator wants to add a custom variable to all hosts in the 'webservers' group without modifying the plugin script. How can this be achieved?

A.Modify the dynamic inventory plugin script to add the variable
B.Add the variable to the host_vars file for each host
C.Create a group_vars file named 'webservers' in the project directory and define the variable
D.Use the 'add_host' module in a playbook to set the variable
AnswerC

Group_vars files are loaded automatically by Ansible from the project directory and override or supplement plugin-supplied group data, so defining 'webservers' there injects the custom variable into every host in that group without touching the dynamic inventory script.

Why this answer

Ansible's group_vars mechanism allows you to define variables for all hosts in a group by creating a YAML file named after the group (e.g., 'webservers') in the group_vars directory. This approach does not require modifying the dynamic inventory plugin script, which is external and should remain untouched. The variable will be automatically applied to all hosts in the 'webservers' group during playbook execution.

Exam trap

The trap here is that candidates may think modifying the plugin script (Option A) is acceptable, but the EX294 exam emphasizes immutability of external sources and using Ansible's built-in variable precedence and group_vars instead.

How to eliminate wrong answers

Option A is wrong because modifying the dynamic inventory plugin script violates the requirement to not modify the plugin, and it is not a best practice—external plugins should be treated as immutable. Option B is wrong because adding the variable to host_vars files for each host would be repetitive and inefficient, and it does not leverage group-level inheritance; it also requires knowing all hostnames in advance. Option D is wrong because the 'add_host' module is used to dynamically add hosts to the in-memory inventory during playbook runtime, not to set persistent variables for existing group members; it would not apply the variable to all hosts in the 'webservers' group automatically.

29
MCQeasy

You provision a new RHEL 9 control node and create a project directory at /home/devops/ansible. While testing connectivity with `ansible all -m ping`, every host returns UNREACHABLE, yet `ssh` from the shell to those same hosts works without a password. The inventory file at /home/devops/ansible/inventory defines the group `web` with `web1 ansible_host=10.20.30.41`. Which action most directly resolves the failure?

A.Add `ansible_connection=local` to the inventory host entry.
B.Add `ansible_python_interpreter=/usr/bin/python3` to the inventory host entry.
C.Install the `sshpass` package on the control node.
D.Add `ansible_user=devops` to the inventory host entry or run the ad-hoc command with `-u devops`.
AnswerD

Ansible defaults to the local username for the remote SSH user unless told otherwise. If the local account differs from the remote account that owns the authorized key, the ping module cannot authenticate and the host is reported UNREACHABLE. Supplying the correct remote user through a host variable or the -u flag restores connectivity, and the inventory already resolves the address correctly.

Why this answer

Because manual SSH succeeds but Ansible cannot connect, the difference lies in the identity Ansible uses. Ansible defaults to the local account name for remote logins, so when that name differs from the account holding the authorized key, the connection is refused and hosts are marked UNREACHABLE. Defining the correct remote user in inventory or on the command line restores key-based access without altering the transport.

Exam trap

The trap here is assuming that working manual SSH guarantees Ansible uses the same username, when Ansible actually defaults to the local account name.

30
Drag & Dropmedium

Drag and drop the steps to configure a systemd service to start automatically at boot in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for configuring a systemd service to start at boot is: first create the unit file, then reload systemd to load the new unit, next enable the service to create the necessary symlinks for automatic start, then start the service immediately, and finally verify its status. Common mistakes include omitting the reload step, enabling after starting, or performing the reload too late.

31
MCQmedium

An administrator wants to create a custom credential type to store a third-party API key. The API key must be passed to the playbook as an environment variable `MY_API_KEY`. What is the correct Injector configuration in the custom credential type definition?

A.file: {MY_API_KEY: "{{ api_key }}"}
B.env: {"MY_API_KEY": api_key}
C.extra_vars: {MY_API_KEY: "{{ api_key }}"}
D.env: {MY_API_KEY: "{{ api_key }}"}
AnswerD

The env dictionary maps credential inputs to environment variables.

Why this answer

The Injector configuration for a custom credential type in Ansible Automation Platform uses the `env` key to map credential inputs to environment variables. The syntax `env: {"MY_API_KEY": "{{ api_key }}"}` correctly references the input field `api_key` using Jinja2 templating and assigns it to the environment variable `MY_API_KEY`, which the playbook can then access via `ansible_env.MY_API_KEY`.

Exam trap

The trap here is that candidates often confuse `env` with `extra_vars` or forget the Jinja2 templating syntax, leading them to pick Option B (missing braces) or Option C (incorrect injector type).

How to eliminate wrong answers

Option A is wrong because `file` is not a valid Injector key; it is used for file-based credential types (e.g., SSH keys) but not for environment variables. Option B is wrong because it omits the required Jinja2 braces around the variable reference (`api_key` instead of `{{ api_key }}`), which would cause the literal string 'api_key' to be passed rather than the credential input value. Option C is wrong because `extra_vars` is used to inject variables into the playbook's variable space, not as environment variables; it would set `MY_API_KEY` as an Ansible variable, not an environment variable.

32
MCQeasy

A junior admin is troubleshooting why a job template fails with 'Permission denied' when connecting to a target host. The job template uses a machine credential that appears correct. What is the first thing to check?

A.Verify the inventory contains the correct host IP
B.Check the credential's username and private key / password
C.Check the vault credential used in the job template
D.Check the project sync status
AnswerB

A 'Permission denied' error during connection typically stems from an invalid credential, so verifying the username and private key or password is the first check. The credential may appear correct while containing a mismatched key or wrong user.

Why this answer

The error 'Permission denied' during SSH connection to a target host indicates an authentication failure. Since the machine credential appears correct, the most immediate cause is that the username or private key/password stored in the credential is incorrect or mismatched. This is the first thing to check because the credential directly controls authentication to the target host.

Exam trap

The trap here is that candidates often confuse 'Permission denied' with a network or inventory issue, leading them to check the inventory or project sync instead of the credential's authentication details.

How to eliminate wrong answers

Option A is wrong because verifying the inventory host IP addresses connectivity issues (e.g., wrong host or unreachable), not authentication failures; 'Permission denied' is an SSH-level error, not a network reachability error. Option C is wrong because vault credentials are used to decrypt sensitive data within Ansible, not for SSH authentication to target hosts; they do not affect the 'Permission denied' error. Option D is wrong because project sync status relates to retrieving playbook content from a source control repository, not to SSH authentication; a failed sync would cause a different error (e.g., 'project not found'), not 'Permission denied'.

33
MCQmedium

An administrator is using ansible-playbook with an inventory file that defines a group 'webservers' and a group 'dbservers'. The administrator wants to run a playbook only against hosts in 'webservers' but exclude any host that is also in 'dbservers'. Which inventory pattern should be used with the --limit option?

A.webservers:&dbservers
B.webservers:dbservers
C.webservers:!dbservers
D.webservers,!dbservers
AnswerC

The pattern 'webservers:!dbservers' selects all hosts in webservers and then excludes any host that is in dbservers. This is the correct syntax for set operations in Ansible inventory patterns. The colon separates the intersection and exclusion, and the exclamation mark denotes exclusion. This pattern will limit execution to the desired hosts.

Why this answer

Ansible inventory patterns support set operations using colons and special characters. To select hosts in one group and exclude those in another, the pattern 'group1:!group2' is used. The exclamation mark indicates exclusion, and the colon separates the two patterns.

This allows precise targeting of hosts for playbook execution.

Exam trap

The trap here is using a comma instead of a colon to separate the group and the exclusion pattern, which is invalid syntax and will not work as intended.

34
MCQeasy

An administrator is creating a new inventory file for a small environment. The inventory must define a group `app` containing hosts `app1` and `app2`, and a group `db` containing host `db1`. The administrator wants to use the INI format. Which inventory file content correctly defines these groups?

A.app: app1, app2 db: db1
B.[app] app1, app2 [db] db1
C.[app] app1 app2 [db] db1
D.group app host app1 host app2 group db host db1
AnswerC

This content correctly uses INI section headers to define groups. The group `app` contains app1 and app2, and the group `db` contains db1. There are no syntax errors, and the format matches Ansible's INI inventory requirements. This is the valid and straightforward way to define static groups in an INI inventory file.

Why this answer

Ansible INI inventory files use square-bracketed group names followed by one host per line. The correct content defines the `app` group with app1 and app2 on separate lines, and the `db` group with db1. The other options use invalid syntax such as key-value pairs, non-standard keywords, or comma-separated hosts, which Ansible would not parse as intended.

Exam trap

The trap here is assuming that comma-separated hosts or YAML-like structures are valid in INI inventory files, when each host must be on its own line.

35
MCQhard

A team uses Ansible Automation Controller with multiple organizations. Each organization has its own set of machines that require different SSH keys. The administrator wants to ensure that users from one organization cannot use credentials from another organization. What is the best way to achieve this isolation?

A.Create credentials within each organization and assign organization-level access
B.Store credentials in separate projects and restrict project access
C.Set 'Use' permission on credentials only for specific users
D.Place users in different teams and restrict credential access by team
AnswerA

Credentials scoped to an organisation are only visible to members of that organisation, so users cannot select or reference another organisation's SSH keys. This satisfies the stem's isolation constraint, since Ansible Automation Controller enforces credential ownership boundaries at the organisation level rather than through playbook logic or host grouping.

Why this answer

In Ansible Automation Controller, credentials are scoped to organizations. By creating credentials within each organization and assigning organization-level access, the administrator ensures that credentials are only visible and usable by members of that organization. This leverages the built-in role-based access control (RBAC) that isolates resources by organization, preventing cross-organization credential access.

Exam trap

The trap here is that candidates often confuse team-based access control with organization-level isolation, assuming that restricting credentials to a team within an organization provides cross-organization security, but teams do not span organizations and cannot prevent access from users in other organizations.

How to eliminate wrong answers

Option B is wrong because projects in Ansible Automation Controller are used to store playbooks and source code, not credentials; credentials are stored separately in the Credentials resource and are not scoped by project. Option C is wrong because setting 'Use' permission on credentials for specific users does not prevent users from other organizations from accessing those credentials if they are not properly scoped to an organization; organization-level isolation is required. Option D is wrong because teams are subgroups within an organization and do not provide cross-organization isolation; users from different organizations could still be placed in the same team, and team-based restrictions do not enforce organizational boundaries.

36
MCQhard

An administrator manages a static inventory file with a group `web` defined as children of `production`. The inventory also defines a group variable `http_port=80` at the `all` group level and `http_port=8080` at the `web` group level. A playbook targets `hosts: web` and uses `{{ http_port }}` in a template. Which value will be used for hosts in the `web` group?

A.80, because variables defined at the `all` group take precedence over child groups.
B.80, because the play targets `web` but the variable is defined at `all` and that is the default.
C.8080, because variables defined at the `web` group override those at the `all` group.
D.8080, because the last definition in the inventory file wins regardless of group hierarchy.
AnswerC

In Ansible, group variable precedence increases with group depth. The `web` group is a child of `production`, which is a child of `all`. Variables defined at a more specific (deeper) group level override those at broader levels. Thus, http_port=8080 at the `web` group level takes precedence over http_port=80 at the `all` level for hosts in `web`. This is the correct value.

Why this answer

Ansible group variable precedence follows group depth: variables in child groups override those in parent groups. Since `web` is a child of `production` and `all` is the root, the `web` group variable http_port=8080 takes precedence over the `all` group variable http_port=80 for hosts in `web`. This ensures more specific settings are used.

The other options misstate the precedence rules.

Exam trap

The trap here is assuming that the broadest group (all) or file order dictates variable precedence, when actually child groups override parent groups.

37
Matchingmedium

Match each storage concept to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Logical Volume Manager for flexible storage

Redundant array of independent disks

Default Linux filesystem (journaling)

High-performance 64-bit filesystem

Virtual memory on disk

Why these pairings

The correct matches are: LVM for flexible disk management with VGs and LVs, RAID for combining disks for redundancy/performance, Stratis for pool-based snapshots and thin provisioning, and VDO for block-level deduplication/compression. Common confusions include swapping LVM with VDO and RAID with Stratis.

38
MCQeasy

An administrator needs to provide a set of credentials to a job template that requires a machine credential for SSH and a source control credential for the project. What is the correct way to associate these credentials?

A.Define the source control token in the playbook using the 'set_fact' module
B.Create a single credential that includes both SSH key and source control token
C.Store the source control token as an extra variable in the job template
D.Assign both a machine credential and a source control credential to the job template
AnswerD

A job template accepts multiple credentials of different types simultaneously, so attaching both a machine credential for SSH and a source control credential for the project satisfies both authentication needs. Each credential type is matched to its corresponding function during job execution.

Why this answer

Ansible Tower/AWX allows multiple credentials of different types to be assigned to a single job template. A machine credential handles SSH authentication for target hosts, while a source control credential manages authentication for the project repository (e.g., Git). This separation follows Ansible's modular credential design, where each credential type serves a distinct purpose and can be independently managed.

Exam trap

The trap here is that candidates think a single credential must contain all authentication data, but Ansible Tower explicitly separates credential types by function, and a job template can accept multiple credentials of different types simultaneously.

How to eliminate wrong answers

Option A is wrong because the 'set_fact' module sets variables at runtime within a playbook, not credentials; source control tokens must be stored securely in a credential type, not hardcoded in playbooks. Option B is wrong because Ansible Tower does not support a single credential that combines SSH and source control tokens; credentials are typed (machine, source control, vault, etc.) and cannot be merged. Option C is wrong because extra variables are not designed for sensitive credentials; they are visible in job runs and logs, whereas source control tokens should be stored in a dedicated credential type with encryption.

39
MCQeasy

An administrator manages a mixed fleet of Linux servers and Windows servers using Ansible Automation Platform. The Linux hosts are accessed via SSH keys, while the Windows hosts require WinRM with username and password. The administrator wants to define connection credentials in an inventory file so that playbooks can target both groups without specifying credentials in the playbook. Which inventory variable should be used to set the username for WinRM connections?

A.ansible_ssh_user
B.ansible_user
C.ansible_connection_user
D.ansible_winrm_user
AnswerB

ansible_user is the correct inventory variable to specify the username for a connection. For Windows hosts using WinRM, Ansible uses ansible_user to set the remote username, and ansible_password for the password. This allows the administrator to define credentials at the inventory level, such as in group_vars/windows.yml, without embedding them in playbooks.

Why this answer

The ansible_user inventory variable sets the remote username for all connection types, including WinRM. For Windows hosts, ansible_user and ansible_password are used with the winrm connection plugin. Defining these in group_vars ensures credentials are applied consistently without modifying playbooks.

Exam trap

The trap here is assuming that a WinRM-specific variable like ansible_winrm_user is required, when Ansible uses the generic ansible_user for all connection types.

40
Multi-Selectmedium

Which TWO statements about machine credentials in Ansible Tower are correct? (Choose two.)

Select 2 answers
A.Machine credentials can specify a 'become_method' for privilege escalation.
B.Machine credentials can use an SSH private key for authentication.
C.The SSH private key file automatically includes privilege escalation settings.
D.The username field is optional when using an SSH key.
E.SSH key credentials require a password field to be filled in.
AnswersA, B

Machine credentials in Ansible Tower store connection details for managed hosts, including privilege escalation settings. Specifying become_method lets the credential define how privilege escalation is performed, such as sudo or su, when running playbooks against those hosts.

Why this answer

Option A is correct because Ansible Tower machine credentials include a 'become_method' setting (e.g., sudo, su, pbrun, pfexec) that defines how privilege escalation is performed on the managed host. Option B is correct because machine credentials support SSH private key authentication, allowing Tower to connect to managed nodes without a password by supplying the key material. Option C is wrong because privilege escalation settings are configured as separate fields on the credential, not embedded in the SSH private key file itself.

Option D is wrong because the username field is required for machine credentials, even when an SSH key is used, so Tower knows which remote user to authenticate as. Option E is wrong because SSH key credentials do not require a password field; the password can be left blank when using key-based authentication.

Exam trap

The trap here is that candidates often assume the SSH private key file inherently includes privilege escalation settings, or that the username is optional when using SSH keys, but Ansible Tower strictly requires a username and treats privilege escalation as a separate configuration field.

41
MCQeasy

A junior administrator needs to create an encrypted Ansible Vault password file for use with ansible-playbook. The vault password must be stored in a file named vault_pass.txt in the current directory. Which command should the administrator run?

A.ansible-vault create vault_pass.txt
B.echo 'mysecretpassword' > vault_pass.txt
C.ansible-vault encrypt --vault-password-file vault_pass.txt
D.ansible-vault encrypt_string --vault-password-file vault_pass.txt
AnswerB

A vault password file is simply a plaintext file containing the password on the first line. Using echo to write the password to vault_pass.txt creates the required file. The file should be secured with appropriate permissions. This is the standard method to create a vault password file for non-interactive use with --vault-password-file.

Why this answer

A vault password file is a plaintext file that contains the vault password on its first line. It is created using standard file redirection or an editor, not with ansible-vault commands. This file is then referenced with --vault-password-file during playbook runs to decrypt vault-encrypted content non-interactively.

Exam trap

The trap here is confusing the creation of a vault password file with the creation of an encrypted file using ansible-vault, when the password file itself is plaintext and created with normal shell commands.

42
MCQhard

A playbook run against a Windows host fails at the connection stage with an authentication error, although the inventory specifies `ansible_user: Administrator` and the correct password. Which inventory variable must be set so that Ansible uses the password-based WinRM connection instead of trying Kerberos or certificate authentication?

A.ansible_winrm_transport: ntlm
B.ansible_become: true
C.ansible_ssh_pass: <password>
D.ansible_connection: winrm
AnswerA

On Windows, the `ansible_winrm_transport` inventory variable selects the authentication protocol used by the WinRM connection plugin. Setting it to `ntlm` forces basic NTLM authentication with the supplied user and password, avoiding Kerberos or certificate attempts. This directly addresses the authentication failure when a password is provided and the environment does not have Kerberos configured.

Why this answer

For Windows targets, authentication over WinRM is governed by `ansible_winrm_transport`. With a username and password and no Kerberos infrastructure, setting it to `ntlm` forces NTLM authentication and resolves the connection failure. Connection type, SSH password, and become settings do not select the WinRM authentication protocol.

Exam trap

The trap here is assuming that `ansible_connection: winrm` alone determines how Windows authentication happens, when the authentication protocol is actually chosen by a separate transport variable.

43
MCQhard

Your inventory directory `inventory/prod` contains a static hosts file plus a group_vars subdirectory with webservers.yml. A dynamic inventory plugin in the same directory returns the group `webservers` with a host-level variable `http_port` set to 8080. The static group_vars/webservers.yml sets `http_port: 80`. When a play runs against the webservers group, which value does the managed host receive for http_port?

A.80, because the static inventory directory is processed after the dynamic plugin.
B.80, because group_vars files always override variables supplied by inventory plugins.
C.8080, because a host-level variable from the plugin outranks a group-level variable from group_vars.
D.The play fails with a conflicting variable definition error.
AnswerC

Ansible's variable precedence places host variables above group variables, regardless of whether the host value comes from a dynamic plugin or a static file. Because http_port is returned as a host variable by the plugin, it takes priority over the group-level definition in group_vars/webservers.yml, so the host receives 8080 when the play runs.

Why this answer

Variable precedence in Ansible is hierarchical rather than source-based: host variables outrank group variables, and more specific group levels outrank broader ones. Because the dynamic plugin attaches http_port to the individual host, that value sits above the group-level definition in group_vars. The managed host therefore receives 8080 even though the static group file specifies 80.

Exam trap

The trap here is assuming static group_vars always beats dynamic plugin data, when precedence depends on whether the value is host-level or group-level.

44
MCQmedium

An automation engineer manages two data centers with Ansible Automation Platform 2.4. The production inventory file is located at /etc/ansible/prod_inventory.ini and the staging inventory at /etc/ansible/stage_inventory.ini. The engineer wants to run a playbook against both inventories in a single ansible-playbook command, but the host groups must remain separate so that group_vars/prod and group_vars/stage apply correctly. Which command should the engineer use?

A.ansible-playbook --inventory=/etc/ansible/prod_inventory.ini --inventory=/etc/ansible/stage_inventory.ini site.yml
B.ansible-playbook -i /etc/ansible/prod_inventory.ini,/etc/ansible/stage_inventory.ini site.yml
C.ansible-playbook -i /etc/ansible/prod_inventory.ini /etc/ansible/stage_inventory.ini site.yml
D.ansible-playbook -i /etc/ansible/prod_inventory.ini -i /etc/ansible/stage_inventory.ini site.yml
AnswerD

Multiple -i flags are supported by ansible-playbook; each inventory source is parsed independently and merged into a single inventory. Groups with the same name are combined, but distinct groups like prod and stage remain separate, so group_vars directories are applied correctly. This command meets the requirement without altering the inventory files.

Why this answer

Ansible supports multiple inventory sources by repeating the -i option. Each source is parsed separately and merged, preserving distinct group names so that group_vars directories are applied based on group membership. Using a single -i with a comma-separated list or additional positional arguments does not achieve the same result and will cause errors.

Exam trap

The trap here is assuming that a comma-separated list of files can be passed to a single -i option, when in fact -i must be repeated for each inventory source.

45
MCQeasy

An Ansible administrator wants to use an encrypted vault file to store sensitive variables. Which command creates a new vault file and prompts for a password?

A.ansible-vault edit secrets.yml
B.ansible-vault create secrets.yml
C.ansible-vault view secrets.yml
D.ansible-vault encrypt secrets.yml
AnswerB

ansible-vault create secrets.yml generates a new encrypted file and prompts for the vault password, then opens the editor for content entry. The create subcommand is specifically designed for new vault files, unlike encrypt, which converts an existing plaintext file.

Why this answer

`ansible-vault create secrets.yml` creates a new encrypted vault file and immediately prompts the user to set a password, which is then used to encrypt the file. This command is specifically designed for initial creation of vault files, unlike `edit` which requires an existing file, `view` which only displays content, or `encrypt` which encrypts an existing plaintext file.

Exam trap

The trap here is that candidates confuse `ansible-vault create` with `ansible-vault encrypt`, mistakenly thinking both create new files, but `encrypt` requires an existing plaintext file while `create` generates a new encrypted file from scratch.

How to eliminate wrong answers

Option A is wrong because `ansible-vault edit` opens an existing vault file for editing, not creating a new one; it requires the file to already exist and be encrypted. Option C is wrong because `ansible-vault view` displays the decrypted content of an existing vault file without prompting for a new password or creating a file. Option D is wrong because `ansible-vault encrypt` encrypts an existing plaintext file into a vault file, but does not create a new file from scratch; it expects the file to already exist in plaintext.

46
MCQhard

A playbook must run only against hosts that belong to both the `webservers` group and the `production` group. Your inventory defines these as separate groups, and a host named web3 is a member of both. Which inventory pattern restricts the play's hosts to exactly that intersection?

A.hosts: webservers:production
B.hosts: webservers[production]
C.hosts: webservers:&production
D.hosts: webservers:!production
AnswerC

The ampersand prefix introduces an intersection constraint, so the pattern selects only hosts that are members of webservers and also members of production. Because web3 belongs to both groups, it is included, while hosts in just one group are excluded. This is the documented syntax for intersecting group membership in a play's hosts line.

Why this answer

Ansible group patterns use colon-prefixed operators: a leading ampersand means intersection, a leading exclamation mark means exclusion, and a bare colon means union. Placing an ampersand before the second group limits the selection to hosts that are members of both groups, which matches the requirement that only hosts in webservers and production be targeted by the play.

Exam trap

The trap here is reading the colon as an intersection when it actually forms a union, and confusing the ampersand intersection operator with exclusion.

47
Multi-Selectmedium

Which TWO statements about inventory groups in Ansible Automation Platform are correct? (Choose exactly two.)

Select 2 answers
A.A host can belong to multiple groups
B.Inventory groups can be used in smart inventories as filter criteria
C.Host variables are the only way to define variables for a host
D.Groups cannot be members of other groups
E.Dynamic inventory sources cannot produce groups
AnswersA, B

A host can be a member of multiple groups, e.g., 'webservers' and 'production'.

Why this answer

Ansible's inventory system allows a host to belong to multiple groups simultaneously. This is a fundamental feature of Ansible's inventory model, enabling flexible host organization and variable inheritance from all parent groups.

Exam trap

The trap here is that candidates often assume groups cannot be nested or that dynamic inventories cannot produce groups, but Ansible explicitly supports both features, and the exam tests understanding of these flexible inventory capabilities.

48
MCQhard

An administrator maintains a dynamic inventory script that outputs JSON. The script is placed at `/etc/ansible/inventory/aws_inventory.py` and is executable. The administrator runs `ansible-playbook -i /etc/ansible/inventory/aws_inventory.py site.yml` but receives an error: "Unable to parse /etc/ansible/inventory/aws_inventory.py as an inventory source". Which action is most likely to resolve the issue?

A.Ensure the script outputs a JSON object with a top-level key `_meta` containing `hostvars`, and that the script supports the `--list` argument.
B.Change the script's file extension to .json so Ansible recognizes it as a JSON inventory.
C.Make the script non-executable and pass it as a static inventory file.
D.Add the script path to the `inventory` setting in ansible.cfg and remove the -i option from the command.
AnswerA

Ansible dynamic inventory scripts must accept the --list argument and output JSON with groups and hosts. The _meta key is optional but recommended to provide hostvars efficiently. If the script does not support --list or outputs invalid JSON, Ansible cannot parse it. This is the most common cause of the parse error. Ensuring the script meets these requirements resolves the issue.

Why this answer

Dynamic inventory scripts must be executable and support the --list argument, returning valid JSON with groups and hosts. The _meta key with hostvars is recommended to avoid separate --host calls. The parse error typically occurs when the script fails to output valid JSON or does not handle --list.

The other options either misrepresent how Ansible detects dynamic inventories or take actions that would not fix the script's output.

Exam trap

The trap here is assuming that file extension or configuration location determines dynamic inventory parsing, when the critical factor is the script's executable behavior and JSON output for --list.

49
Multi-Selecthard

An administrator is using Ansible Vault to protect sensitive variables in an inventory project. The project has a vault-encrypted file 'secrets.yml' that contains the variable 'db_password'. The playbook needs to use this variable. Which TWO statements are correct about using vault-encrypted variables in this scenario? (Choose two.)

Select 2 answers
A.The variable db_password must be defined in a separate unencrypted file that references the encrypted one.
B.The vault password can be provided at runtime using the --ask-vault-pass option when running ansible-playbook.
C.The vault-encrypted file must be listed in the ansible.cfg file under the [defaults] section as vault_identity_list.
D.Vault-encrypted variables can only be used in playbooks, not in inventory variables.
E.A vault password file can be specified using the --vault-password-file option, and it can be a script that outputs the password.
AnswersB, E

The --ask-vault-pass option prompts for the vault password interactively when running ansible-playbook. This allows decryption of vault-encrypted files without storing the password in plain text. It is a secure and common method for providing the vault password during playbook execution, especially in interactive or ad-hoc runs.

Why this answer

Providing the vault password interactively with --ask-vault-pass or via a vault password file with --vault-password-file are both valid methods to decrypt vault-encrypted files. The password file can be a script that outputs the password, which is useful for automation. Vault-encrypted files can be used for any variables, including inventory variables, and do not require an unencrypted reference file.

Exam trap

The trap here is believing that vault-encrypted variables require special configuration like vault_identity_list or an unencrypted reference file, when they can be decrypted directly with a password provided at runtime.

50
MCQmedium

An administrator maintains a static inventory file at /home/student/inventory that defines a group 'webservers' and a group 'dbservers'. A host named 'web1.example.com' must belong to both groups. Which INI snippet correctly assigns web1.example.com to both groups without creating duplicate host entries?

A.[webservers] web1.example.com [dbservers] web1.example.com ansible_group=webservers
B.[webservers] web1.example.com [dbservers] web1.example.com
C.[webservers] web1.example.com [dbservers] web1.example.com:children
D.[webservers] web1.example.com [dbservers:children] webservers
AnswerB

This INI structure places web1.example.com under two distinct group headers. Ansible merges the host into both groups while maintaining a single host record, so group_vars for webservers and dbservers both apply. This is the standard, supported way to express overlapping group membership in a static inventory.

Why this answer

Placing the same hostname under two separate group headers is the correct way to give a host membership in multiple groups in an INI inventory. Ansible then treats the host as a single managed node that inherits variables from both groups, with group variable precedence rules resolving conflicts.

Exam trap

The trap here is assuming a host can belong to only one group or that a special variable is needed to add it to another group, when simply listing it under a second group header is sufficient.

51
MCQmedium

Your team stores two inventories: a static file at inventories/prod and a dynamic inventory plugin configuration at inventories/aws_ec2.yml. The static file defines the group `db` with `db1 ansible_host=172.16.5.10`, while the plugin also returns a host named db1 with the address 172.16.5.99. You run `ansible-inventory -i inventories/prod -i inventories/aws_ec2.yml --host db1`. Which host variable value does Ansible report for ansible_host?

A.172.16.5.99, because the last inventory source processed takes precedence for the same host.
B.Both values are retained, and Ansible fails with a duplicate host variable error.
C.Neither value; Ansible reports the host as undefined because duplicate host names are skipped.
D.172.16.5.10, because the first inventory source listed on the command line takes precedence.
AnswerA

When inventories are merged, Ansible combines hosts and groups, and for a host defined in more than one source the variable values from the later source override earlier ones. Here the dynamic plugin is processed after the static file, so its ansible_host value of 172.16.5.99 prevails. You can verify this with ansible-inventory before running production playbooks.

Why this answer

Merging multiple inventories unifies hosts and groups rather than rejecting duplicates. For a host present in several sources, variables from the source processed later override those from earlier sources. Since the dynamic plugin is processed after the static file, its ansible_host value is the one that survives, so the host resolves to the plugin-provided address.

Exam trap

The trap here is assuming command-line order of -i flags decides precedence, when merging actually favors the last-processed source.

52
MCQmedium

A Red Hat Certified Engineer is managing an Ansible inventory that includes a mix of Linux and network devices. The network devices are running Cisco IOS and require the network_cli connection plugin. The engineer needs to specify the username and password for these devices in the inventory. Which inventory variables should be used to provide the credentials for the network devices?

A.ansible_winrm_user and ansible_winrm_password
B.ansible_user and ansible_password
C.ansible_ssh_user and ansible_ssh_pass
D.ansible_network_user and ansible_network_password
AnswerB

For network devices using the network_cli connection plugin, Ansible uses the standard ansible_user and ansible_password variables to authenticate. These can be set in the inventory file, group_vars, or host_vars. This allows the engineer to define credentials for the network devices without modifying the playbook.

Why this answer

The network_cli connection plugin relies on ansible_user and ansible_password for authentication. These variables are set in the inventory or group_vars and are used by the plugin to establish connections to network devices, ensuring proper credential management.

Exam trap

The trap here is assuming that network devices require special variables like ansible_network_user, when in fact they use the standard ansible_user and ansible_password.

Ready to test yourself?

Try a timed practice session using only Manage inventories and credentials questions.