The conversation wasn't really about what is "best" or "smartest" Ansible is just another tool in the toolbox. I know organizations that love doing all their management through Ansible. I happen to love it.
Building Windows in Zero/Lite Touch is pretty tricky, even with Windows tools like the Deployment Toolkit. SMS/SCCM works well, if you're a bigger organization. Smaller orgs - not worth the build/maintenance time. These days, Windows Autopilot is pretty nifty if you're 100% native into MSFT Azure and Entra (just have P2 licensing for the greatest effect).
Updates are always a headache on Windows unless you start relying on 3rd party management tools (which carry their own, per-device, licensing fees).
In the end, as we well know, there is no solution that is "better" than another for every application.
But that's all apart from the OPs original question of CompTIA supporting ZeroTouch topics in their curriculum, which I don't think they do, apart from a simple mention.
/r