EX294 Manage automation security and operations Practice Question
A developer wants to encrypt a string in a playbook variable file. Which command should they use?
⚠ Common exam trap
Watch out — candidates often confuse encrypting a single string with encrypting an entire file, leading them to choose `ansible-vault create` or `ansible-vault edit` instead of the specific `encrypt_string` subcommand.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ansible-vault encrypt_string
`ansible-vault encrypt_string` is specifically designed to encrypt a single string value for use in a playbook variable file, without encrypting the entire file. This command outputs the encrypted string in a format that can be directly pasted into a YAML variable definition, preserving the rest of the file as plaintext.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ansible-vault rekey
Why it's wrong here
Rekey changes the encryption password on an already-encrypted file; it performs no encryption of plaintext. It is tempting because it manipulates vault files, and would be correct when rotating the vault password after a secret has been encrypted.
- ✗
ansible-vault create
Why it's wrong here
Create makes a new encrypted file from scratch, so it cannot encrypt a string inside an existing variable file. It is tempting because it produces vault-encrypted content, and would be correct when starting a brand-new encrypted variables file.
- ✗
ansible-vault edit
Why it's wrong here
Editing decrypts an existing vault file for modification; it cannot encrypt a plaintext string in place. It is tempting because edit is the routine command for changing vaulted content, and would be correct once the variable file is already encrypted and needs amending.
- ✓
ansible-vault encrypt_string
Why this is correct
The ansible-vault encrypt_string subcommand encrypts a single string value inline, producing ciphertext suitable for embedding directly in a variable file. This satisfies the requirement to encrypt one string rather than an entire file, which encrypt would handle.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.