Courseiva

XK0-006 Automation, Orchestration, and Scripting Practice Question

A cloud engineer is using Ansible to manage configuration across multiple servers. The engineer needs to store variable data that is specific to each host and sensitive database passwords. Which two Ansible features should be used for these purposes? (Choose two.)

⚠ Common exam trap

The trap is selecting group_vars for host-specific data or forgetting that Ansible Vault is the only option for encrypting secrets; candidates must map 'per-host' to host_vars and 'sensitive' to Vault.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ansible Vault

Option E, host_vars, is correct because host-specific variable data is stored in host_vars files (e.g., host_vars/<hostname>.yml), which Ansible automatically loads for the matching inventory host, making it the proper place for per-host values. Option D, Ansible Vault, is correct because it encrypts sensitive data such as database passwords, allowing vault-encrypted variables or files to be decrypted at runtime with the vault password, keeping secrets protected at rest. Option A, group_vars, applies variables to whole inventory groups rather than individual hosts, so it does not satisfy the host-specific requirement. Option B, ansible_facts, holds automatically discovered system information gathered by setup, not user-defined sensitive credentials. Option C, roles, is a structural way to bundle tasks, handlers, and defaults for reuse, not a mechanism for storing host-specific or encrypted secret data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    group_vars

    Why it's wrong here

    group_vars stores variables shared by every host in an inventory group, so it cannot hold data unique to one host or encrypted passwords. It is tempting because it is a legitimate inventory variable location, and would be correct if the values applied to a whole group rather than a single host; host_vars and Ansible Vault are needed here.

  • ✗

    ansible_facts

    Why it's wrong here

    ansible_facts holds values Ansible discovers automatically from a managed host, such as IP addresses and OS details, so it cannot store engineer-defined per-host variables or secrets. It is tempting because facts are host-specific data, but they are gathered, not authored; host_vars and Ansible Vault meet this requirement.

  • ✗

    roles

    Why it's wrong here

    roles bundle tasks, handlers and default variables into a reusable structure, but they do not provide per-host variable storage or secret encryption. It is tempting because roles commonly contain vars directories, yet those defaults apply broadly; host_vars supplies host-specific values and Ansible Vault encrypts the passwords.

  • ✓

    Ansible Vault

    Why this is correct

    Ansible Vault encrypts sensitive variable files, such as the database passwords, using AES-256, so secrets remain unreadable at rest while still being decrypted at playbook runtime. This directly satisfies the stem's requirement to store sensitive credentials securely alongside host-specific data.

  • ✓

    host_vars

    Why this is correct

    Host_vars stores per-host variable data in separate files named after each managed node, automatically loaded during inventory parsing. This satisfies the requirement for host-specific values without polluting group_vars or playbooks. Sensitive passwords, however, need Ansible Vault encryption, so host_vars alone addresses only the per-host constraint, not secrecy.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.