EX294 Manage automation security and operations Practice Question
A junior administrator needs to rotate the password for a database user stored in an Ansible Vault-encrypted file (secrets.yml). The current password is unknown to the admin, but they have the vault password file (vault-pass.txt). The admin wants to edit the file securely without exposing the decrypted content in the terminal history or logs. Which command should they run?
⚠ Common exam trap
Test-takers frequently confuse `edit` with `decrypt` (thinking they need to decrypt first, then edit, then re-encrypt), or they may think `rekey` is for changing the content, when in fact it only changes the vault encryption password.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ansible-vault edit --vault-password-file vault-pass.txt secrets.yml
`ansible-vault edit` decrypts the file to a temporary file, opens it in the default editor (e.g., vi), and upon saving, re-encrypts it transparently. This prevents the decrypted content from ever being written to the terminal history or logs, as the editing happens in a secure temporary location that is cleaned up after the editor closes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ansible-vault edit --vault-password-file vault-pass.txt secrets.yml
Why this is correct
ansible-vault edit decrypts into a temporary file and opens the editor, so plaintext never enters shell history or terminal output; supplying --vault-password-file avoids an interactive prompt. This satisfies the requirement to edit securely without exposing decrypted content.
- ✗
ansible-vault decrypt --vault-password-file vault-pass.txt secrets.yml
Why it's wrong here
Decrypting writes the plaintext back to secrets.yml, leaving the credentials exposed on disk until re-encrypted, and it does not open an editor for rotation. It is tempting because decrypt is used when plaintext must be processed by external tooling before re-encryption.
- ✗
ansible-vault rekey --vault-password-file vault-pass.txt secrets.yml
Why it's wrong here
Rekey changes the vault encryption password, not the database user's password stored inside the file. It is tempting because rekey operates on vault-encrypted files, but it requires knowing the current vault password and leaves the database credential unchanged; editing the file is what rotates that credential.
- ✗
ansible-vault view --vault-password-file vault-pass.txt secrets.yml
Why it's wrong here
Viewing only prints the decrypted file to stdout; it cannot alter the stored password, so rotation never occurs. It is tempting because view safely inspects vault contents without writing plaintext to disk, which suits auditing or verifying existing secrets rather than editing them.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.