Courseiva

EX294 · topic practice

Manage inventories and credentials practice questions

This domain covers Ansible inventory construction and credential handling for automation execution. On EX294 you build static and dynamic inventories, assign host and group variables, and configure credentials used by automation controller job templates. Questions test correct YAML structure for inventory files, plugin configuration, and credential-to-template association rather than memorized menu paths.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage inventories and credentials

What the exam tests

What to know about Manage inventories and credentials

Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.

Building static INI and YAML inventories with host groups, children, and group_vars directories

Configuring dynamic inventory plugins such as amazon.aws.aws_ec2 and community.general.proxmox with plugin YAML files

Defining group_vars and host_vars precedence for variables applied across inventory hosts

Associating machine, source control, and custom credential types with job templates in automation controller

Watch out for

Common Manage inventories and credentials exam traps

  • ▸Placing group_vars in the wrong directory level so variables are not picked up by the intended group or hosts
  • ▸Forgetting to enable a dynamic inventory plugin in ansible.cfg or omitting the plugin key in its configuration file
  • ▸Confusing credential types when a job template needs both machine and source control credentials attached separately

Practice set

Manage inventories and credentials questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Ansible explanation →

An administrator needs to store a secret API token in Ansible Automation Controller so that it can be used in job templates without exposing the token in plain text. Which type of credential should be used?

Question 2mediummulti select
Read the full Ansible explanation →

Which TWO of the following are valid methods to supply a credential password in Ansible Automation Controller?

The job template running against host db1 uses a machine credential with an SSH key. The key is correctly configured in Automation Controller. However, the job fails with the error shown. What is the most likely cause?

Exhibit

Refer to the exhibit.

Error message from a job run:
```
fatal: [db1]: UNREACHABLE! => {
    "changed": false,
    "msg": "Failed to connect to the host via ssh: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).",
    "unreachable": true
}
```
Question 4hardmultiple choice
Read the full Ansible explanation →

A company uses Ansible Automation Controller to manage a mix of Linux and Windows servers. Each server is in a separate inventory group. The Linux servers use SSH keys stored in machine credentials, and the Windows servers use username/password stored in machine credentials. Recently, a new security policy requires that all credentials must be rotated every 90 days. The automation team has 50 Linux servers and 20 Windows servers. They want to minimize manual effort and avoid exposing secrets in plain text during rotation. They currently have a Jenkins pipeline that can run scripts on the controller node. Which approach best meets the requirements?

Question 5hardmultiple choice
Read the full Ansible explanation →

A system administrator is managing Ansible Tower and wants to use an Azure Resource Manager credential to provision virtual machines. However, the credential fails authentication with the error '401 Unauthorized'. Which action should the administrator take to resolve the issue?

Question 6easymultiple choice
Read the full Ansible explanation →

An Ansible Tower administrator needs to allow a team of developers to run playbooks against specific inventory groups without allowing them to modify the inventory or credentials. Which approach best satisfies the requirement?

Question 7easymultiple choice
Read the full Ansible explanation →

An administrator wants to use a custom inventory script to dynamically generate hosts in Ansible Tower. Which of the following is a valid approach to manage credentials for accessing the script's API?

Question 8mediummulti select
Read the full Ansible explanation →

Which TWO of the following are valid methods to manage credentials in Ansible Tower?

Question 9mediumdrag order
Read the full Ansible explanation →

Drag and drop the steps to create and apply a simple Ansible playbook that installs httpd into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 10mediummultiple choice
Read the full Ansible explanation →

An Ansible Tower/AWX administrator wants to prevent users from viewing credential passwords in plain text. Which credential type should be used for SSH passwords?

Question 11hardmultiple choice
Read the full Ansible explanation →

A DevOps engineer is designing a dynamic inventory script for a cloud provider. The script must return host variables in a specific JSON format. According to Ansible best practices, which top-level keys should be present in the script output?

Question 12mediummultiple choice
Read the full Ansible explanation →

A team uses Ansible AWX and needs to run a job template that uses a custom credential of type 'OpenStack' to authenticate to an OpenStack cloud. Which field in the job template is used to specify this credential?

Question 13hardmultiple choice
Read the full Ansible explanation →

An Ansible playbook uses the `ansible_user` variable at the host level, but the SSH connection still uses root. Which configuration setting could override the playbook's user setting?

Question 14mediummultiple choice
Read the full Ansible explanation →

An Ansible inventory file uses the `gce.py` dynamic inventory script for Google Cloud. After running the script, the inventory contains hosts but no variables. What is the most likely cause?

Question 15hardmultiple choice
Read the full Ansible explanation →

An Ansible playbook uses a vault-encrypted variable `db_password` from a vars file. The playbook fails with 'Decryption failed' error. Which of the following could be the cause?

Question 16mediummulti select
Read the full Ansible explanation →

A team is configuring an inventory to manage Windows hosts via Ansible. Which TWO inventory variables must be defined for each host?

Question 17easymulti select
Read the full Ansible explanation →

An Ansible playbook uses the `fetch` module to retrieve files from managed hosts. Which TWO inventory variables are commonly used to construct unique destination paths for each host?

Question 18mediummultiple choice
Read the full Ansible explanation →

Refer to the exhibit. A playbook runs against the `web` group. What username will be used for host web2?

Exhibit

# inventory file
[web]
web1 ansible_host=192.168.1.10 ansible_user=admin
web2 ansible_host=192.168.1.11

[web:vars]
ansible_user=deploy
Question 19hardmultiple choice
Read the full Ansible explanation →

Refer to the exhibit. An Ansible playbook targeting server1 fails with a permissions error when connecting. The administrator notices the SSH private key is being used. Which change will likely fix the issue?

Network Topology
# ansible-navigator inventorylist"all": {"hosts": {"server1": {"ansible_host": "10.0.0.1","ansible_user": "centos","ansible_ssh_private_key_file": "/home/centos/.ssh/id_rsa"},"vars": {"ansible_ssh_common_args": "-o StrictHostKeyChecking=no"
Question 20easymultiple choice
Read the full Ansible explanation →

A company uses a static inventory file for Ansible Tower. They need to add a new host to an existing group. Which action should they take?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage inventories and credentials sessions

Start a Manage inventories and credentials only practice session

Every question in these sessions is drawn from the Manage inventories and credentials domain — nothing else.

Related practice questions

Related EX294 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the EX294 exam test about Manage inventories and credentials?
Create and validate inventories with ansible-inventory, set variables through group_vars and host_vars, and configure dynamic inventory plugins correctly. The most important thing is understanding variable precedence and where inventory data must live so playbooks resolve the right values.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage inventories and credentials questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage inventories and credentials domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other EX294 topics?
Use the topic links above to move to related areas, or go back to the EX294 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the EX294 exam covers. They are not copied from any real exam or dump site.