Courseiva

EX294 Manage automation security and operations Practice Question

A managed node is configured with an Ansible vault-encrypted variable file. When running a playbook that uses these variables, the user receives a 'decryption failed' error. Which two steps should the user take to resolve the issue?

⚠ Common exam trap

Candidates often assume 'decryption failed' always means a wrong password, overlooking that Ansible vault IDs must match exactly when multiple vault passwords are in use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the vault ID matches the one used when encrypting the file.

Option D is correct because Ansible vault supports multiple vault IDs, and if the playbook or ansible-vault command specifies a vault ID that differs from the one used at encryption time, decryption will fail with a 'decryption failed' error; the vault ID must match exactly. Option E is correct because the most common cause of a vault decryption failure is supplying the wrong vault password, whether via --ask-vault-pass, --vault-password-file, or the ANSIBLE_VAULT_PASSWORD_FILE environment variable, so verifying the correct password resolves the error. Option A is not correct because file permissions of 600 affect access control, not the cryptographic decryption of vault contents. Option B is not correct because SSH private key access to the managed node is unrelated to decrypting a local vault-encrypted variable file. Option C is not correct because a vault password file should contain the password itself, not the path to the vault file, so that step is technically inaccurate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Verify the file permissions are set to 600.

    Why it's wrong here

    Vault decryption depends on the vault password or vault-id, not on file mode; 600 permissions affect readability, not the decryption key. Restricting permissions is tempting because Ansible documentation recommends 600 for vault files, but that guards secrecy rather than resolving a wrong password.

  • ✗

    Check that the SSH private key has access to the managed node.

    Why it's wrong here

    SSH keys authenticate the connection to the managed node; they play no part in decrypting vault content, which uses the vault password supplied via --ask-vault-pass or a password file. Checking SSH access is tempting because connection failures are common, but decryption happens locally before transport.

  • ✗

    Make sure the vault password file contains the path to the vault file.

    Why it's wrong here

    A vault password file holds the decryption password itself, not a path to the encrypted vault file; Ansible reads the vault file directly from the playbook's vars_files. Storing a path there causes authentication to fail. Password files are used when automating decryption in CI, where the password is supplied non-interactively.

  • ✓

    Ensure the vault ID matches the one used when encrypting the file.

    Why this is correct

    Vault matches decryption to the vault ID recorded in the file's header. If the playbook supplies a different ID, or none, decryption fails even with the right password, so aligning the vault ID used at encryption with the one supplied at runtime resolves it.

  • ✓

    Verify the correct vault password is being provided.

    Why this is correct

    Decryption requires the exact password that encrypted the file. If the wrong password is supplied, or none at all, the vault payload cannot be decrypted, producing the 'decryption failed' error. Verifying the correct password is provided restores successful decryption.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.