200-901 Infrastructure and Automation Practice Question
A company uses a centralized automation server that runs Ansible playbooks. What is the best security practice for storing SSH credentials?
⚠ Common exam trap
Cisco often tests the misconception that 'inventory files are safe if stored locally' or that 'hardcoding is acceptable for small teams,' but the exam expects candidates to recognize that any plain text storage of credentials violates security best practices, and Ansible Vault is the standard built-in solution for encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Ansible Vault
Ansible Vault is the recommended security practice for encrypting sensitive data like SSH credentials. It allows you to store encrypted variables and files within your playbooks or inventory, protecting secrets at rest while enabling decryption at runtime via a password or key file. This avoids exposing credentials in plain text, which is critical for centralized automation servers that may be accessed by multiple users or integrated into CI/CD pipelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store credentials in a public repository
Why it's wrong here
A public repository exposes SSH keys to anyone with read access, and version history preserves them even after deletion. Public repositories suit open-source code sharing, but credentials belong in Ansible Vault or an external secrets manager injected at run time.
- ✓
Use Ansible Vault
Why this is correct
Ansible Vault encrypts sensitive variables and files at rest using AES-256, so SSH credentials are never stored as plaintext on the centralised automation server. This satisfies the stem's requirement for secure credential storage within playbook workflows.
- ✗
Hardcode credentials in playbooks
Why it's wrong here
Hardcoded credentials sit in plaintext inside playbooks and propagate to every repository clone, backup and log. Embedding values directly is tempting for quick testing, yet production automation requires Ansible Vault or a secrets manager so keys are encrypted and rotated independently of the code.
- ✗
Use plain text inventory files
Why it's wrong here
Plain-text inventory files store connection passwords and keys unencrypted, readable by anyone with filesystem access. Inventory files are intended for host lists and grouping variables, not secrets; credentials belong in Ansible Vault or an external secrets manager referenced at run time.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.