mediumMultiple Choice
CAS-004 Ansible Vault Practice Question
An organization uses Ansible to automate server configuration for a hybrid cloud environment. The security team requires that sensitive data such as API keys and passwords are not exposed in the Ansible playbooks or logs. The Ansible control node is shared among several administrators. What is the best approach to protect these secrets?
⚠ Common exam trap
CAS-005 often tests the misconception that file permissions or environment variables are sufficient secret protection, when the requirement is encryption at rest and controlled decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Ansible Vault to encrypt the secret variables and restrict access to the vault password file.
Ansible Vault encrypts sensitive variables and files so secrets are never stored in plaintext in playbooks or logs. Restricting access to the vault password file ensures only authorized administrators on the shared control node can decrypt the secrets. This satisfies the requirement that secrets not be exposed in playbooks or logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store secrets in plaintext in a separate file and set restrictive file permissions.
Why it's wrong here
Plaintext files leave secrets readable to every administrator with access to the shared control node, and Ansible can echo them into logs. It is tempting because restrictive permissions appear to limit exposure, but file permissions do not encrypt content, whereas Ansible Vault encrypts the file itself.
- ✗
Remove all secrets from automation and require manual entry during each playbook run.
Why it's wrong here
Manual entry removes automation's repeatability and still exposes secrets on a shared control node's terminal and logs. It is tempting because nothing is stored persistently, but Ansible Vault encrypts secrets at rest and decrypts only in memory, satisfying the no-exposure requirement while keeping playbooks automated.
- ✓
Use Ansible Vault to encrypt the secret variables and restrict access to the vault password file.
Why this is correct
Ansible Vault encrypts variable files at rest with AES-256, so secrets never appear in plaintext playbooks, inventory or logs. Restricting the vault password file to authorised administrators on the shared control node prevents other users from decrypting them.
- ✗
Define secrets as environment variables on the control node and reference them in playbooks.
Why it's wrong here
Environment variables on a shared control node are visible to other administrators and can leak into process listings or verbose logs. It is tempting because referencing variables keeps secrets out of playbook text, but Ansible Vault encrypts the stored value and decrypts only during execution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CAS-005
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps team uses Ansible to automate server configuration. They need to ensure that sensitive variables like passwords are not exposed in playbook logs or version control. What is the recommended approach?
medium- ✓ A.Use Ansible Vault to encrypt sensitive variables
- B.Use environment variables only
- C.Store secrets in plain text within the playbook
- D.Encrypt the entire playbook file
Why A: Ansible Vault is the built-in mechanism for encrypting sensitive data such as passwords, API keys, and certificates within Ansible projects. It encrypts variables or files at rest using AES-256, and the vault password is provided at runtime (e.g., via --ask-vault-pass or a vault password file), ensuring secrets are never stored in plaintext in playbook logs or version control. This approach integrates seamlessly with Ansible's workflow without requiring external tools or compromising automation.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.