You must be able to encrypt sensitive data with Ansible Vault, store credentials such as SSH keys in Automation Controller, and scope team permissions to specific job templates. The most important thing is applying least privilege: grant only the access needed and never expose secrets in plaintext.
Start practicing
Manage automation security and operations — choose a session length
Free · No account required
Domain overview
This domain covers securing Ansible automation and operating it at scale: protecting secrets with Ansible Vault, controlling access in Automation Controller, and building custom execution environments. Questions are scenario-based, asking you to choose correct practices or configuration approaches rather than recall syntax, so you must understand how vault, RBAC, credentials, and containerized execution fit together.
Exam objectives
Encrypting variables and files with ansible-vault and supplying vault passwords at runtime
Storing SSH private keys as Automation Controller credentials instead of plaintext in playbooks
Assigning Automation Controller roles and teams so users only launch permitted job templates
Building custom execution environments with ansible-builder and container tooling for jobs
Committing vault-encrypted files without managing the vault password securely, or hardcoding the password in playbooks and inventory instead of supplying it separately.
Granting broad Automation Controller roles such as System Administrator or Organization Admin when only job template launch access was required for the team.
Assuming the default execution environment contains every collection or Python dependency, then failing to build and register a custom execution environment.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An Ansible playbook uses 'become: yes' to install packages. The playbook works when run manually by the administrator but fails when run from automation controller with 'Missing sudo password'. The administrator has configured a machine credential with the SSH key and the 'Become password' field is blank. What is the most likely issue?
2A managed node is configured with an Ansible vault-encrypted variable file. When running a playbook that uses these variables, the user receives a 'decryption failed' error. Which two steps should the user take to resolve the issue?
3Drag and drop the steps to configure a container using Podman with a custom Dockerfile in the correct order.
4An automation team wants to securely store SSH private keys for use in playbooks. Which Ansible feature should they use?
5An organization uses Automation Controller with multiple teams. They want to ensure that team members can only launch job templates that are explicitly assigned to their team. Which configuration approach should be used?
6A developer wants to encrypt a string in a playbook variable file. Which command should they use?
7A Red Hat Ansible Automation Platform installation uses a custom execution environment. The playbook runs fail with 'execution environment not found'. The execution environment is stored in a private registry requiring authentication. What must be configured?
8Refer to the exhibit. An administrator deployed this configuration using the controller_configuration role. After deployment, user jdoe can administer Engineering organization but cannot launch a job template within it. What is the most likely reason?
9Which two actions are appropriate when configuring a custom execution environment for an automation controller job? (Choose two.)
10An organization needs to implement security best practices for Ansible automation. Which three measures should be taken? (Choose three.)
11An automation team wants to grant a group of operators the ability to launch job templates in automation controller but prevent them from modifying the job template configuration. They also need to troubleshoot failed jobs by viewing job output. Which predefined role should be assigned to the team for a specific job template?
12A company uses Ansible Automation Platform and wants to ensure that all playbook runs are logged for audit purposes. What is the simplest way to achieve centralized logging of job runs?
13An organization uses automation controller and has multiple teams. They want to create an inventory that automatically includes all hosts from a cloud provider that belong to the 'production' tag, and this inventory should be accessible only to the SRE team. What is the correct way to achieve this?
14After rotating the Ansible Vault password in the automation controller, several job templates that use vault credentials start failing with 'decryption failed'. The vault credential has been updated with the new password. What is the most likely cause of the failure?
15An administrator is migrating playbooks to use execution environments in automation controller. They want to ensure that all playbook runs use a custom execution environment that includes the necessary Python libraries and is signed to comply with security policy. What should the administrator do?
16A systems administrator is securing Ansible automation. Which two practices help protect sensitive data in playbooks? (Choose two.)
17Refer to the exhibit. A playbook fails with the given error. What is the most likely cause?
18Refer to the exhibit. What is the most likely cause of the job being in 'pending' state?
19Which TWO of the following are best practices for securing automation controller secrets and credentials?
20A junior administrator needs to rotate the password for a database user stored in an Ansible Vault-encrypted file (secrets.yml). The current password is unknown to the admin, but they have the vault password file (vault-pass.txt). The admin wants to edit the file securely without exposing the decrypted content in the terminal history or logs. Which command should they run?
21A playbook must read a vault-encrypted variable file named secrets.yml and also use a vault password stored in a file named vault_pass.txt. The playbook is executed with the command `ansible-playbook site.yml --vault-password-file vault_pass.txt`. The file secrets.yml was encrypted with the same password. During execution, the task that uses a variable from secrets.yml fails with an error indicating the variable is undefined. What is the most likely reason?
22An automation engineer stores a sudo password inside a project variable file that is committed to Git. The team requires that the cleartext value never appears in the repository and that playbooks still consume the variable transparently. Which approach meets this requirement?
23An automation controller administrator needs to allow a team of developers to run playbooks that use a vault-encrypted variable file. The vault password must not be stored in the playbook repository or exposed in job output. Which approach meets the requirement?
24A playbook that manages user accounts must run a task that passes a decrypted service account password to a command. Job output currently shows the password in the task result. Which change ensures the password is not displayed while keeping the task functional?
25An organization uses automation controller and must ensure that sensitive data such as passwords and API keys are not exposed in job output. Which TWO actions should the administrator take? (Choose two.)
26A playbook must write a sensitive token to a remote managed node's /etc/app/token.conf file. The security team requires that the token never appear in plaintext in the playbook or in the controller's job output. The token is stored in an Ansible Vault-encrypted variable file. Which task implementation best meets these requirements?
27An automation controller administrator needs to ensure that a vault password used by multiple job templates is rotated periodically without editing each job template. Which approach is most efficient and secure?
28An automation controller administrator must ensure that a job template handling credentials follows security best practices for both storage and execution. Which TWO actions should be taken in automation controller? (Choose two.)
29You are preparing an Ansible playbook that will run on a managed node. The playbook includes a task that uses the `ansible.builtin.user` module to create a user. The playbook is stored in a Git repository that multiple engineers can access. You need to ensure that the password for the new user is not stored in plain text in the repository. Which Ansible feature should you use to protect the password?
30A playbook must retrieve a secret from an external vault service at runtime instead of storing it in the repository. The team wants the value available as a variable named db_password. Which Ansible feature should be used?
31An automation team must ensure that sensitive variables used in playbooks are protected both at rest and during job execution in Ansible Automation Platform. Which TWO actions should be taken? (Choose two.)
32You are using Ansible Automation Platform to manage a large number of servers. You need to ensure that playbooks that run against production servers use a separate set of credentials than those used for development servers. The production credentials must be stored securely and audited. Which Ansible Automation Platform feature should you use to achieve this?
33A playbook uses the `copy` module to distribute a configuration file to managed nodes. The file contains a sensitive API key. You want to ensure the API key is not visible in the playbook source or in Ansible logs. Which approach should you use?
34You are reviewing an Ansible playbook that uses the `ansible.builtin.shell` module to run a command that includes a sensitive API key as an argument. You want to prevent the API key from being displayed in the job output. Which task-level directive should you add?
35An automation team uses Ansible Automation Platform to manage a large number of servers. They need to ensure that sensitive data such as passwords and API keys are not stored in plain text in playbooks or inventory files. They decide to use Ansible Vault to encrypt these secrets. Which of the following best describes how Ansible Vault integrates with playbook execution to protect secrets at runtime?
36A Red Hat Certified Engineer is configuring Ansible to run playbooks against managed nodes. The security policy requires that all communication between the control node and managed nodes is encrypted and authenticated. The engineer decides to use SSH keys for authentication. Which Ansible configuration parameter should be set to specify the private key file to use for SSH connections?
37An automation team uses Ansible Automation Platform to manage secrets. They have a requirement that certain tasks must not log sensitive output to the Ansible logs. Which Ansible task keyword should be used to prevent a task from logging its output?
38An organization uses Ansible Automation Platform to manage a large infrastructure. They need to implement security best practices for managing secrets and credentials. Which TWO of the following actions should they take to enhance security? (Choose two.)
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
You must be able to encrypt sensitive data with Ansible Vault, store credentials such as SSH keys in Automation Controller, and scope team permissions to specific job templates. The most important thing is applying least privilege: grant only the access needed and never expose secrets in plaintext.
The Courseiva EX294 question bank contains 38 questions in the Manage automation security and operations domain, covering the 12% of the exam attributed to this domain in the official Red Hat blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Manage automation security and operations domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included