certslothcertsloth
EX294/Topic 02

Red Hat / Advanced

Connectivity, Privilege and Safe Execution

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Connection proves access; become proves authority; state proves success.

Must remember

Managed Linux nodes normally need reachable SSH, an authorized user and a suitable Python interpreter for most modules. SSH keys authenticate access; host-key verification establishes the server identity. Configure keys and ownership/modes deliberately. Do not solve an authentication problem by broadly disabling trust checks.

Privilege escalation uses become and related settings. The SSH connection user and become user can differ. A successful SSH login does not prove sudo authorization; a successful unprivileged fact gathering task does not prove a package install can run. Use the supplied credentials and required escalation method without exposing them in inventory or logs.

ansible.builtin.ping tests Ansible connectivity and Python/module execution; it is not ICMP ping. Distinguish unreachable hosts from task failures. Diagnose name resolution, network path, SSH authentication, interpreter availability and privilege in that order where appropriate.

Run playbooks through the specified ansible-playbook or ansible-navigator environment. Syntax checking validates structure, not business correctness. Check mode predicts changes for supported modules; skipped/unsupported tasks and registered results can limit its accuracy. Tasks explicitly disabling check mode may still execute. Diff mode can reveal sensitive file content, so scope it carefully.

Read the recap: ok, changed, failed and unreachable describe execution outcomes, not complete service validation. Re-run to inspect idempotence, verify service behavior and confirm persistence after reboot on a disposable practice system. A playbook intended for fresh machines must create its prerequisites rather than rely on manual setup left over from yesterday.

Choose under exam pressure

Requirement Choice and reason
SSH works but package tasks fail Check become/sudo and package/repository prerequisites.
Preview supported changes Check mode, understanding its limits.
Prove application availability An explicit functional check after configuration.

Traps

  • Ansible ping is not ICMP.
  • Check mode is not a universal guarantee that every task is simulated.

Active recall

1. remote_user versus become_user?

Connection identity versus effective elevated identity.

2. Unreachable versus failed?

Connection/setup access failure versus an executed task that failed.

3. Why can check mode mislead?

Some modules or data-dependent paths cannot fully simulate execution.

4. Why protect diff output?

It can display sensitive file contents.

5. Why test from a clean system?

To expose undocumented manual prerequisites and missing automation steps.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.