EX294 Manage inventories and credentials Practice Question
Network Topology
The inventory above is used in a job template in Automation Controller. The job template also has a machine credential assigned that specifies username 'root' and an SSH key. When the job runs against host web1, which username will Ansible use to connect?
⚠ Common exam trap
Candidates often assume the credential's username is always used, forgetting that inventory host variables (like `ansible_user`) override credential settings, a common point of confusion in Ansible's variable precedence hierarchy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
admin (from inventory host variable)
Ansible uses a specific precedence order for determining the connection user. When a host variable (like `ansible_user: admin`) is defined in the inventory for host web1, it overrides the username set in the job template's machine credential. The credential's username ('root') acts only as a fallback if no `ansible_user` is defined at the host or group level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
admin (from inventory host variable)
Why this is correct
Inventory host variables take precedence over the machine credential's username when Ansible resolves connection parameters for a host. The web1 host variable ansible_user set to admin therefore overrides root, satisfying the precedence rule demonstrated in the inventory.
- ✗
The username set in the job template's 'extra variables'
Why it's wrong here
Extra variables do not set the connection username; Ansible resolves that from the credential or inventory, so this fails the scenario. It is tempting because extra variables do override many playbook variables, and they would be correct for passing arbitrary runtime values such as package versions into a job.
- ✗
The first defined username in the credential chain
Why it's wrong here
Ansible does not walk a credential chain to pick the first username; a single machine credential supplies the connection user, so this mechanism does not exist here. It is tempting because credential chaining sounds like layered fallback, and it would apply where multiple credential types are deliberately combined for one host.
- ✗
root (from credential)
Why it's wrong here
The machine credential's username root is what Ansible uses to connect to web1, so this option is actually correct and cannot be the intended wrong answer. It is tempting precisely because it matches the credential definition, and it would be the right choice in any scenario without an inventory-level override.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.