Courseiva

EX294 · topic practice

Coordinate rolling updates practice questions

This domain covers orchestrating safe, staged updates across managed hosts using Ansible playbooks. It is tested through scenario questions on serial batching, failure thresholds, and quorum preservation for stateful services. You must reason about what happens mid-run when a host fails, and choose directives that limit blast radius while keeping services available.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Coordinate rolling updates

What the exam tests

What to know about Coordinate rolling updates

Be able to write a playbook that uses serial and max_fail_percentage to roll updates in controlled batches, and predict the exact outcome when a host fails mid-run. The most important thing is knowing that exceeding max_fail_percentage aborts the play for all remaining hosts.

Using the serial keyword to batch hosts, including values like 1, percentages, or counts

Applying max_fail_percentage to abort a play when a batch exceeds the failure threshold

Ordering tasks with handlers, pre_tasks, and post_tasks to drain and restore nodes

Managing stateful clusters so quorum (for example 3 of 5 nodes) stays online during updates

Why learners struggle

Why Coordinate rolling updates questions are commonly missed

NAT questions are missed when learners confuse the four address types (inside local, inside global, outside local, outside global) or misapply the interface direction. A translation rule can look correct but still fail if the ACL, interface, or direction is wrong.

  • ·Inside local vs inside global — inside local is the private source, inside global is the translated public address
  • ·PAT overloads — many sources share one public IP using unique port numbers
  • ·Interface direction — ip nat inside and ip nat outside must be on the correct interfaces
  • ·Static NAT vs dynamic NAT vs PAT — each serves a different use case
  • ·The NAT ACL identifies traffic to translate, not traffic to permit or deny
  • ·A missing translation can look like a routing problem if the interfaces are misconfigured

Watch out for

Common Coordinate rolling updates exam traps

  • ▸Confusing max_fail_percentage with serial: the threshold applies per batch, not across the whole host group.
  • ▸Assuming serial: 1 with max_fail_percentage: 0 continues after a failure; it aborts the entire play immediately.
  • ▸Forgetting that a failed host is removed from the play, so later batches and handlers may not run as expected.

Practice set

Coordinate rolling updates questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Ansible explanation →

A company uses Ansible to manage rolling updates of a web server fleet. During a deployment, the playbook fails on one host due to a transient network error, and the rest of the fleet is left in an inconsistent state. Which strategy would best minimize the risk of inconsistency in future rolling updates?

Question 2mediummultiple choice
Read the full Ansible explanation →

Refer to the exhibit. The playbook uses serial: 1 (one host at a time). The update failed on web3.example.com. Based on the output, what is the most likely reason the play did not abort the rollout and how should the playbook be modified to stop on failure?

Exhibit

Refer to the exhibit.

PLAY [Update web servers] ********************************************************

TASK [Gathering Facts] *********************************************************
ok: [web1.example.com]
ok: [web2.example.com]
ok: [web3.example.com]

TASK [Update Apache config] ****************************************************
changed: [web1.example.com] => {
    "changed": true,
    "msg": "Config updated"
}
changed: [web2.example.com] => {
    "changed": true,
    "msg": "Config updated"
}
failed: [web3.example.com] => {
    "changed": false,
    "msg": "Permission denied"
}

TASK [Restart Apache] **********************************************************
ok: [web1.example.com] => {
    "changed": true,
    "msg": "Service restarted"
}
ok: [web2.example.com] => {
    "changed": true,
    "msg": "Service restarted"
}
skipping: [web3.example.com]

PLAY RECAP *********************************************************************
web1.example.com : ok=3    changed=2    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0
web2.example.com : ok=3    changed=2    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0
web3.example.com : ok=1    changed=0    unreachable=0    failed=1    skipped=1    rescued=0    ignored=0
Question 3hardmultiple choice
Read the full Ansible explanation →

You are managing a rolling update of a 10-node web application cluster using Ansible. The application requires that at least 8 nodes remain available during the update to handle traffic. You have written a playbook that uses serial: 2 (updates 2 nodes at a time). During a test run, the playbook updates the first batch of 2 nodes successfully, but when it proceeds to the second batch, one of the nodes fails to restart the web service. However, the playbook continues and updates the remaining nodes. At the end, only 7 nodes are healthy, causing performance degradation. You need to ensure that if a batch fails to meet the minimum health requirements, the entire rollout is stopped and no further updates are applied. Which course of action should you take?

Question 4easymultiple choice
Read the full Ansible explanation →

A team runs the playbook shown in the exhibit. They notice that during the update, some requests are still being sent to servers that have been disabled. What is the most likely cause?

Exhibit

Refer to the exhibit.

```
- name: Rolling update with load balancer
  hosts: webservers
  serial: 2
  tasks:
    - name: Disable server in haproxy
      community.general.haproxy:
        state: disabled
        host: "{{ inventory_hostname }}"
        socket: /var/run/haproxy.sock
      delegate_to: lb01

    - name: Update web server
      yum:
        name: httpd
        state: latest

    - name: Enable server in haproxy
      community.general.haproxy:
        state: enabled
        host: "{{ inventory_hostname }}"
        socket: /var/run/haproxy.sock
      delegate_to: lb01
```

You are managing a Kubernetes cluster running a critical stateful application deployed as a StatefulSet with 3 replicas. The application uses persistent volumes with ReadWriteOnce access mode. You need to update the container image from version 1.0 to 1.1. The application's performance degrades if more than one replica is unavailable at any time. The StatefulSet is configured with the default RollingUpdate strategy (partition=0). You have a maintenance window of 30 minutes. The update must be completed within the window with minimal risk. Which of the following approaches should you take?

Match each Ansible playbook directive to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Specify target hosts or groups

Enable privilege escalation

Define variables

List of modules to execute

Special tasks run on notification

Question 7hardmultiple choice
Read the full Ansible explanation →

A large enterprise manages thousands of servers grouped by data center. They are designing a rolling update that must complete within a maintenance window. Which combination of Ansible strategies best minimizes total update time while maintaining safety?

Question 8hardmultiple choice
Read the full Ansible explanation →

An organization uses Ansible Tower (AWX) for rolling updates. They have a job template that runs a playbook with serial: 5. The inventory contains 50 hosts. The update fails after the first batch due to a syntax error in a playbook. After fixing the error, the administrator wants to resume updating from where it left off without updating already successful hosts. Which approach achieves this?

Question 9easymultiple choice
Read the full Ansible explanation →

What is the effect of setting 'serial: 5' in an Ansible playbook that targets a group of 20 hosts?

An administrator uses a rolling update strategy with serial: 3 and max_fail_percentage: 20. They have 10 hosts in the inventory. The first batch of 3 hosts: 2 succeed, 1 fails. What happens next?

Which TWO options are valid techniques for rolling out updates to a subset of hosts before updating the rest? (Choose exactly two.)

Question 12easymulti select
Read the full Ansible explanation →

Which TWO conditions cause an Ansible rolling update playbook to abort immediately? (Choose exactly two.)

Question 13easymultiple choice
Read the full Ansible explanation →

An Ansible playbook uses the 'deployment' resource with a 'rolling_update' strategy. Which module is typically used to manage this in a Kubernetes/OpenShift environment?

An OpenShift deployment is stuck in a degraded state after a rolling update. Which command helps diagnose the root cause by showing status conditions?

Question 15easymulti select
Read the full Ansible explanation →

Which THREE of the following are valid 'serial' values for an Ansible rolling update playbook?

Which THREE commands can verify the status of a rolling update on an OpenShift deployment?

Question 17hardmulti select
Read the full Ansible explanation →

Which TWO Ansible playbook parameters directly control the number of host failures allowed before aborting a rolling update?

The deployment has 4 replicas. During a rolling update, what is the maximum number of pods that can be unavailable at any single time?

Exhibit

Refer to the exhibit.
$ oc describe deploymentconfig/myapp
Strategy: RollingParams:
  UpdatePeriod: 1s
  IntervalSeconds: 6s
  MaxSurge: 25% (1 pod)
  MaxUnavailable: 25% (1 pod)
  TimeoutSeconds: 600
Replicas: 4

There are 5 hosts in the webservers group. All updates succeed on the first batch of 2 hosts. On the second batch, one host fails. What is the result?

Exhibit

Refer to the exhibit.
- name: Rolling update
  hosts: webservers
  serial: 2
  max_fail_percentage: 0
  tasks:
    - name: update app
      yum:
        name: httpd
        state: latest
      notify: restart httpd

You are managing a critical web application deployed on OpenShift with 12 replicas. The application must maintain at least 10 replicas available during updates to meet an SLA. You initiate a rolling update using the default strategy, but the rollout is progressing slowly because only 2 new pods are created at a time, causing a prolonged update duration. You need to speed up the rollout without violating the SLA (10 available replicas). The current Deployment configuration has maxSurge: 25% (3 pods) and maxUnavailable: 25% (3 pods). You have permission to update the DeploymentConfig during the active rollout. Which action should you take?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Coordinate rolling updates sessions

Start a Coordinate rolling updates only practice session

Every question in these sessions is drawn from the Coordinate rolling updates domain — nothing else.

Related practice questions

Related EX294 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the EX294 exam test about Coordinate rolling updates?
Be able to write a playbook that uses serial and max_fail_percentage to roll updates in controlled batches, and predict the exact outcome when a host fails mid-run. The most important thing is knowing that exceeding max_fail_percentage aborts the play for all remaining hosts.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Coordinate rolling updates questions in a focused session?
Yes — the session launcher on this page draws every question from the Coordinate rolling updates domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other EX294 topics?
Use the topic links above to move to related areas, or go back to the EX294 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the EX294 exam covers. They are not copied from any real exam or dump site.