EX294 Implement advanced Ansible automation Practice Question
A company uses Ansible Vault to encrypt sensitive data in playbooks. They have multiple environments (dev, test, prod) and use a separate vault password file for each environment. The passwords are stored in files named 'vault-pass-dev', 'vault-pass-test', and 'vault-pass-prod'. To run a playbook against the test environment, they use the command 'ansible-playbook site.yml -i test -e @test-vars.yml --vault-id test@vault-pass-test'. This runs successfully from the command line. However, when they define the same vault-id in an Ansible Tower credential and attempt to run the job, the job fails with 'ERROR! Decryption failed (no vault secrets would be found that could decrypt the vault encrypted file)' for a vault-encrypted variable file that was encrypted with a different vault ID (e.g., 'dev'). The team expects that Tower would use the provided vault credential to decrypt all vault-encrypted files. Which change should be made to ensure correct decryption in Tower?
⚠ Common exam trap
EX294 often tests the misconception that a single vault credential can decrypt all vault-encrypted files regardless of vault ID, leading candidates to overlook the need for multiple credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add multiple vault credentials to the job template, one for each vault ID used in the project.
In Ansible Tower, each vault credential is associated with a single vault ID and password. To decrypt files encrypted with different vault IDs, you must attach multiple vault credentials to the job template, each corresponding to a vault ID used in the project. This allows Tower to try each credential until decryption succeeds. The command-line success with a single vault-id works because only files encrypted with that ID are decrypted; files with other IDs would fail unless multiple --vault-id options are provided.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add multiple vault credentials to the job template, one for each vault ID used in the project.
Why this is correct
Tower matches each vault credential to a single vault ID, so a test credential cannot decrypt dev-encrypted files. Adding one credential per vault ID lets Tower supply every required secret, satisfying the multi-environment decryption constraint that the CLI handled via repeated --vault-id flags.
- ✗
Enter all vault passwords separated by commas in the 'VAULT PASSWORD' field of a single credential.
Why it's wrong here
A Tower credential holds one password per vault-id; comma-separating them is not parsed as multiple secrets, so only the first is tried and decryption of the dev-encrypted file fails. Multiple vault passwords require separate credentials attached to the job template, each with its own vault-id.
- ✗
Re-encrypt all files with the same vault ID (e.g., 'default') to simplify the setup.
Why it's wrong here
Re-encrypting with a single vault ID discards the per-environment separation the team deliberately built, and does not address Tower's need for multiple vault-id credentials. Distinct vault IDs exist precisely so dev, test and prod secrets stay isolated; one shared ID would be the choice only if environments were merged.
- ✗
Change the vault password file to contain the password for the vault ID that was used to encrypt the file.
Why it's wrong here
Tower matches each vault ID to its credential, so a credential labelled test cannot decrypt files encrypted under dev; the file must be re-encrypted with the test vault ID or a matching credential supplied. This option is tempting because supplying the correct password feels sufficient, but the vault ID label must also align.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.