Courseiva
Automation →mediumMultiple Choice

350-401 Automation Practice Question

A network engineer is using Ansible to manage a group of Cisco IOS XE devices. The engineer wants to ensure that the playbook can securely connect to the devices without prompting for passwords and without storing passwords in plaintext in the playbook. Which method should be used to provide the credentials?

⚠ Common exam trap

The trap here is thinking that environment variables or interactive prompts are secure enough, when they either expose passwords or require manual intervention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the passwords in an encrypted file using Ansible Vault and reference them in the playbook.

Ansible Vault provides a secure way to encrypt sensitive data like passwords. By storing credentials in an encrypted file and referencing them in the playbook, the engineer can run playbooks without interactive prompts and without exposing passwords in plaintext. This is the standard best practice for securing credentials in Ansible automation, including for Cisco IOS XE devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the ansible_ssh_pass variable in the inventory file and encrypt the inventory with Ansible Vault.

    Why it's wrong here

    While encrypting the inventory with Ansible Vault is secure, using ansible_ssh_pass is not recommended for network devices because they typically use SSH with password authentication, but the variable is for SSH, not for the network_cli connection. For Cisco IOS XE, the correct variables are ansible_password and ansible_user, often used with connection: network_cli. This option is less precise and may not work as intended.

  • ✗

    Use the --ask-pass command-line option when running the playbook.

    Why it's wrong here

    The --ask-pass option prompts for the SSH password interactively, which violates the requirement of no prompting. It also does not store the password securely for repeated use. While it avoids plaintext storage, it is not suitable for automated, non-interactive runs. Therefore, it does not meet the engineer's needs.

  • ✓

    Store the passwords in an encrypted file using Ansible Vault and reference them in the playbook.

    Why this is correct

    Ansible Vault allows encrypting sensitive data such as passwords. The encrypted file can be decrypted at runtime with a vault password, which can be provided via a file or prompt. This keeps passwords out of plaintext in the playbook and enables secure, non-interactive automation. This is the recommended method for securing credentials in Ansible.

  • ✗

    Set the ANSIBLE_PASSWORD environment variable on the control node before running the playbook.

    Why it's wrong here

    Environment variables can be used, but they are not encrypted and can be exposed in process listings or logs. This method does not meet the requirement of not storing passwords in plaintext. Additionally, Ansible does not automatically use ANSIBLE_PASSWORD for network device authentication; specific variables like ansible_password must be set. This approach is insecure and unreliable.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.