Courseiva

200-901 Infrastructure and Automation Practice Question

A network engineer is preparing an Ansible playbook that will configure VLANs on a fleet of Cisco IOS XE switches. The playbook must authenticate to each device securely and must be able to reference the device-specific variables that the playbook expects. (Choose two.)

⚠ Common exam trap

The trap here is treating any working method of supplying credentials as acceptable, when only encrypted storage plus proper variable resolution meets the stated security and reference requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define host and group variables for each switch in the inventory so tasks can reference the expected variable names.

Secure authentication in Ansible is achieved by encrypting secrets with Ansible Vault and letting the playbook load them at runtime, while per-device values are supplied through inventory host_vars and group_vars. Together these satisfy both requirements: credentials stay protected, and the playbook can reference the variables it expects for each switch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hard-code the enable password directly inside each task's ios_config module arguments.

    Why it's wrong here

    Embedding the enable password in task arguments places the secret in plain text in the playbook and any logs or version-control history. It also duplicates the secret across tasks, making rotation error-prone. This violates the secure-authentication requirement even though the playbook might still run successfully.

  • ✓

    Define host and group variables for each switch in the inventory so tasks can reference the expected variable names.

    Why this is correct

    Ansible resolves variables from inventory host_vars and group_vars, making device-specific values available to tasks. Defining them there ensures the playbook references resolve correctly for each switch. This is the standard mechanism for supplying per-device data such as management addresses and platform-specific settings.

  • ✗

    Pass the credentials as extra variables on the ansible-playbook command line and rely on shell history being cleared.

    Why it's wrong here

    Command-line extra variables appear in process listings and shell history, exposing credentials to other users on the control node. Clearing history after the fact does not remove them from audit logs or the process table during execution. This does not meet the secure-authentication requirement for the playbook.

  • ✗

    Create a separate playbook for every switch and store the credentials only in that switch's playbook.

    Why it's wrong here

    Per-switch playbooks multiply maintenance work and still store credentials in files that may be committed to source control. They do not provide encryption or centralized management, and they offer no advantage over inventory variables. This approach fails the security goal and scales poorly across a large switch fleet.

  • ✓

    Store device credentials in an Ansible Vault-encrypted variable file and reference those variables in the playbook.

    Why this is correct

    Ansible Vault encrypts sensitive variable files so credentials are not stored in plain text in the repository. The playbook can load the encrypted file and use the variables during connection setup. This satisfies the secure-authentication requirement while keeping the playbook portable across the switch fleet.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.