EX294 Manage task execution and roles Practice Question
You need to run an Ansible playbook every hour to update a dynamic inventory file from a CMDB API. The playbook is stored in /opt/ansible/update_inventory.yml. You want to schedule the execution using a cron job on the control node. The control node runs Red Hat Enterprise Linux 9. The playbook uses Ansible Vault to decrypt API credentials, and the vault password is stored in /etc/ansible/.vault_pass. Which cron entry will execute the playbook hourly?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
0 * * * * /usr/bin/ansible-playbook --vault-password-file /etc/ansible/.vault_pass /opt/ansible/update_inventory.yml
It specifies the correct cron schedule (0 * * * * for hourly), uses the correct command (ansible-playbook), and points to the correct vault password file (/etc/ansible/.vault_pass) as specified in the stem. Option A uses the wrong vault password file path (~/.vault_pass). Option B uses the wrong schedule (every minute). Option C uses the wrong command (ansible instead of ansible-playbook).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
0 * * * * /usr/bin/ansible-playbook --vault-password-file ~/.vault_pass /opt/ansible/update_inventory.yml
Why it's wrong here
The tilde expands to root's home directory under cron, not the intended path, so the vault password file at /etc/ansible/.vault_pass is never read and decryption fails. It is tempting because --vault-password-file is the correct flag for supplying a vault password; it would work if the file genuinely lived in the invoking user's home directory.
- ✗
* * * * * /usr/bin/ansible-playbook --vault-password-file /etc/ansible/.vault_pass /opt/ansible/update_inventory.yml
Why it's wrong here
Five asterisks run the playbook every minute, not hourly; the hour field must be fixed and the minute field set to a specific value. It is tempting because the command and vault-password-file flag are correct, and would be right if minute-level execution were intended.
- ✗
0 * * * * /usr/bin/ansible --vault-password-file /etc/ansible/.vault_pass /opt/ansible/update_inventory.yml
Why it's wrong here
ansible (ad-hoc) cannot execute a playbook file; it requires a module and host pattern, so the playbook never runs. It is tempting because ansible and ansible-playbook share vault flags and inventory options, and ad-hoc commands suit one-off tasks rather than scheduled playbook runs.
- ✓
0 * * * * /usr/bin/ansible-playbook --vault-password-file /etc/ansible/.vault_pass /opt/ansible/update_inventory.yml
Why this is correct
The cron field '0 * * * *' runs the job at minute zero of every hour, satisfying the hourly requirement. Supplying --vault-password-file lets ansible-playbook decrypt the API credentials non-interactively, which is essential because cron has no TTY for the vault prompt.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.