EX294 Practice Question: Create content collections and execution environments
Exhibit
{
"results": [
{
"namespace": "redhat",
"name": "insights",
"version": "1.0.0",
"signatures": [
{"signature": "abc123...", "signing_key_id": "key1"},
{"signature": "def456...", "signing_key_id": "key2"}
],
"download_url": "https://console.redhat.com/api/automation-hub/content/published/collections/redhat-insights-1.0.0.tar.gz"
}
]
}Refer to the exhibit. A user attempts to download the collection using the download URL but the signature verification fails. What is the most likely reason?
⚠ Common exam trap
Red Hat often tests the misconception that signature verification failures are always due to a corrupted or unsigned collection, when in reality the client-side public key management is a common oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's client does not have the corresponding public key.
B is correct because signature verification of a downloaded collection requires the client to have the corresponding public key that was used to sign the collection. If the user's client lacks this public key, the verification process will fail, even if the collection itself is properly signed and the URL is valid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The collection version does not match.
Why it's wrong here
A version mismatch would surface as a dependency or resolution error, not a signature verification failure; signatures are checked independently of version numbers. It tempts because mismatched versions commonly break installs, and would be correct if the error named a version conflict.
- ✓
The user's client does not have the corresponding public key.
Why this is correct
Signature verification requires the signer's public key imported into the local GPG keyring. Without that corresponding public key, ansible-galaxy cannot validate the detached signature, so verification fails even when the collection archive itself is intact.
- ✗
The collection is not properly signed.
Why it's wrong here
Signature verification failing does indicate the collection lacks a valid signature, but the stem asks the most likely reason given the exhibit, where the signing configuration is present. Unsigned collections are the answer when no signing key or signature file exists at all.
- ✗
The download URL is invalid.
Why it's wrong here
An invalid URL would produce a download or 404 failure before any signature check runs, so it cannot explain a verification error. It tempts because mistyped or expired URLs are a common cause of failed downloads, and would be the answer if the fetch itself errored.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.