Courseiva
← Back to Red Hat Certified Engineer EX294 questions

Scenario-based practice

Hard Difficulty Questions

Practise Red Hat Certified Engineer EX294 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
EX294
exam code
Red Hat
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related EX294 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Read the full Ansible explanation →

A senior engineer needs to debug an Ansible playbook that uses lookups. Which TWO plugins can be used to retrieve data from a file on the control node? (Select exactly two.)

Question 2hardmultiple choice
Read the full Ansible explanation →

A large enterprise manages thousands of servers grouped by data center. They are designing a rolling update that must complete within a maintenance window. Which combination of Ansible strategies best minimizes total update time while maintaining safety?

Question 3hardmultiple choice
Full question →

An administrator has a requirements.yml file specifying roles from multiple sources: a public Galaxy server, a private Git repository, and a local path. They want to install all roles into the roles directory of the current project. Which command will achieve this?

Question 4hardmultiple choice
Read the full Ansible explanation →

An organization uses Ansible Tower (AWX) for rolling updates. They have a job template that runs a playbook with serial: 5. The inventory contains 50 hosts. The update fails after the first batch due to a syntax error in a playbook. After fixing the error, the administrator wants to resume updating from where it left off without updating already successful hosts. Which approach achieves this?

Question 5hardmultiple choice
Full question →

A DevOps engineer is responsible for coordinating a rolling update of a Red Hat OpenShift Container Platform 4.12 cluster with 10 worker nodes. The cluster hosts a stateful application that uses persistent volumes with ReadWriteOnce access mode. The update involves a minor version upgrade of the cluster from 4.12.0 to 4.12.5. The engineer uses the recommended `oc adm upgrade` command. During the update, after the first worker node is updated, the engineer notices that the node's status shows 'NotReady' and the cluster version operator reports a degraded status. A check of the node logs reveals 'kubelet: Failed to run kubelet: Could not get kubelet config from cluster: could not get config from cluster: context deadline exceeded'. Which action should the engineer take first?

Question 6hardmultiple choice
Read the full Ansible explanation →

You manage an Ansible Tower instance that has multiple inventories synced from different sources (static, dynamic cloud, and satellite). Recently, a job template that uses an inventory synced from Red Hat Satellite fails with 'No hosts matched' even though hosts exist in Satellite. The inventory sync job runs successfully and shows hosts populated in Tower. The job template uses a limit field set to '*' and there are no tags or other filters. The playbook is simple: 'hosts: all'. What is the most likely cause?

Question 7hardmultiple choice
Read the full Ansible explanation →

A company manages a large infrastructure of 10,000 servers using Ansible. The Ansible control node runs on a powerful machine with 32 cores and 64GB RAM. Recently, a playbook that processes server facts and generates a compliance report has become extremely slow, taking over 6 hours to complete. The playbook uses several `set_fact` tasks with complex jinja2 filters including `selectattr`, `map`, `json_query`, and `combine`. The inventory is stored in a dynamic inventory script that returns JSON. The team suspects that the filter operations are causing performance bottlenecks, especially when creating large data structures. A junior engineer suggests splitting the playbook into multiple plays and using `delegate_to` to distribute processing across managed nodes. Another suggests using the `ansible.builtin` module instead of filters. The senior architect recommends converting the heavy filter logic into a custom action plugin. What is the most effective approach to significantly reduce the execution time while maintaining functionality?

Question 8hardmultiple choice
Read the full Ansible explanation →

An Ansible playbook uses a rolling update strategy with serial: 1. After the first host is updated, the playbook stops and shows 'PLAY RECAP' with only one host. What is the most likely reason?

Question 9hardmultiple choice
Read the full Ansible explanation →

An Ansible automation is used to manage firewall rules on a set of Linux servers. The playbook defines a variable "allow_rules" as: allow_rules: - proto: tcp dport: 80 comment: HTTP - proto: tcp dport: 443 comment: HTTPS

The engineer needs to use the "iptables" module to create rules. The module expects "chain" to be specified, and the engineer wants to dynamically set the chain based on the port: ports 80 and 443 go to "INPUT" chain, while others go to "FORWARD". The engineer writes a loop: - name: Add iptables rules iptables: chain: "{{ item.dport | map('some_filter') }}" protocol: "{{ item.proto }}" destination_port: "{{ item.dport }}" comment: "{{ item.comment }}" loop: "{{ allow_rules }}"

But this fails because the chain field expects a string, not a list. The engineer realizes the map filter returns a list. Which of the following modifications correctly sets the chain based on port number?

Question 10hardmultiple choice
Read the full Ansible explanation →

Refer to the exhibit. An administrator runs an Ansible playbook and gets an unreachable error. The administrator has set ansible.cfg as shown. Which configuration change would most likely resolve the issue?

Exhibit

[root@controller ~]# cat ansible.cfg
[defaults]
inventory = /path/to/inventory
remote_user = ansible
ask_pass = false

[privilege_escalation]
become = true
become_method = sudo
become_user = root
become_ask_pass = true

[root@controller ~]# cat playbook.yml
---
- hosts: webservers
  tasks:
    - name: Install httpd
      yum:
        name: httpd
        state: present

[root@controller ~]# ansible-playbook -i inventory.ini playbook.yml
SSH password: 
SUDO password[defaults to SSH password]: 

PLAY [webservers] ********************************************************

TASK [Gathering Facts] ***************************************************
fatal: [server1]: UNREACHABLE! => {"changed": false, "msg": "Failed to connect to the host via ssh: Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password).", "unreachable": true}
Question 11hardmultiple choice
Read the full Ansible explanation →

Refer to the exhibit. A playbook fails with the error 'file not found: /var/www/app-v2.1.0.tar.gz' on the control node. What is the most likely cause?

Exhibit

---
- name: Deploy web app
  hosts: webservers
  become: yes
  vars:
    app_version: "2.1.0"
  tasks:
    - name: Install Apache
      yum:
        name: httpd
        state: latest
    - name: Deploy application
      copy:
        src: /var/www/app-v{{ app_version }}.tar.gz
        dest: /var/www/html/app.tar.gz
    - name: Extract archive
      unarchive:
        src: /var/www/html/app.tar.gz
        dest: /var/www/html/
        remote_src: yes
    - name: Start Apache
      service:
        name: httpd
        state: started
Question 12hardmultiple choice
Read the full Ansible explanation →

A managed node is not responding to Ansible automation. The administrator verifies that the node is reachable via SSH and that the SSH key is correctly deployed. However, 'ansible all -m ping' fails with 'UNREACHABLE'. The automation controller uses a custom execution environment. What is the most likely cause?

Question 13hardmultiple choice
Read the full Ansible explanation →

Refer to the exhibit. An administrator runs a playbook in check mode and receives the shown output. What should be done to fix the failure while maintaining idempotency?

Network Topology
[root@control ansible]# ansible-playbook playbook.ymlcheckdiff[root@control ansible]# cat playbook.yml- name: Deploy web apphosts: webserversroles:- common- apache- deployPLAY [Deploy web app] ********************************************************ok: [web1.example.com]changed: [web1.example.com]PLAY RECAP ********************************************************************web1.example.comok=3 changed=1 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0
Question 14hardmultiple choice
Read the full Ansible explanation →

An operations team is designing a rolling update for a stateful application that requires quorum (minimum 3 out of 5 nodes online). They plan to use Ansible's serial keyword. Which serial value ensures the update proceeds without breaking quorum while still being efficient?

Question 15hardmultiple choice
Read the full Ansible explanation →

You are managing a large infrastructure of 500 Linux servers. The servers are divided into groups: 'web', 'app', and 'db'. Each group has specific configuration requirements. You have developed a set of Ansible roles to manage these configurations. Recently, you noticed that when you run the playbook against all servers, the 'web' role is applied to 'app' servers due to a variable misconfiguration. The playbook uses include_role with a variable that determines which role to apply. The variable is defined in group_vars/all.yml as 'server_role: web'. However, each group should have its own role: 'web' for web servers, 'app' for app servers, 'db' for db servers. The playbook includes the role based on '{{ server_role }}'. What is the best course of action to fix this issue without modifying the playbook structure?

Question 16hardmultiple choice
Read the full Ansible explanation →

A developer wrote a custom filter plugin in a Python file `my_filters.py` and placed it in the directory `./filter_plugins/`. The playbook fails with 'ERROR! no filter named 'my_custom_filter''. The playbook is located in `/home/user/project/playbook.yml`. The `ansible.cfg` file in the same directory does not set `filter_plugins`. Which is the most likely cause?

Question 17hardmultiple choice
Full question →

The job template running against host db1 uses a machine credential with an SSH key. The key is correctly configured in Automation Controller. However, the job fails with the error shown. What is the most likely cause?

Exhibit

Refer to the exhibit.

Error message from a job run:
```
fatal: [db1]: UNREACHABLE! => {
    "changed": false,
    "msg": "Failed to connect to the host via ssh: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).",
    "unreachable": true
}
```
Question 18hardmultiple choice
Read the full Ansible explanation →

Refer to the exhibit. An administrator runs an Ansible playbook and receives the error shown. The playbook uses a variable 'vault_httpd_port' that should be stored in an encrypted vault file. Which step should the administrator take first to resolve the issue?

Exhibit

[root@controller ~]# ansible-playbook -i inventory.ini site.yml --ask-vault-pass
Vault password: 

PLAY [all] ***************************************************************

TASK [Gathering Facts] ***************************************************
ok: [server1]

TASK [common : Install httpd] ********************************************
fatal: [server1]: FAILED! => {"changed": false, "msg": "The task includes an option with an undefined variable. The error was: 'vault_httpd_port' is undefined"}

PLAY RECAP ****************************************************************
server1                     : ok=1    changed=0    unreachable=0    failed=1    skipped=0    rescued=0    ignored=0
Question 19hardmultiple choice
Full question →

The debug output shows 'changed' even when the firewall rule already existed. Which filter issue could cause this?

Exhibit

Refer to the exhibit.

- name: Configure firewall
  hosts: all
  tasks:
    - name: Allow HTTP
      ansible.posix.firewalld:
        service: http
        permanent: yes
        state: enabled
      register: fw_result

    - debug:
        msg: "{{ 'changed' if fw_result.changed else 'no change' }}"
Question 20hardmultiple choice
Read the full Ansible explanation →

An organization uses a private Git repository to store Ansible content collections. They want to automate the building of execution environments that include these collections. Which approach is recommended?

These EX294 practice questions are part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style EX294 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.