EX294 Manage automation security and operations Practice Question
A playbook must read a vault-encrypted variable file named secrets.yml and also use a vault password stored in a file named vault_pass.txt. The playbook is executed with the command `ansible-playbook site.yml --vault-password-file vault_pass.txt`. The file secrets.yml was encrypted with the same password. During execution, the task that uses a variable from secrets.yml fails with an error indicating the variable is undefined. What is the most likely reason?
⚠ Common exam trap
The trap here is assuming that Ansible automatically loads vault-encrypted variable files from the playbook directory once a vault password is supplied.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vault-encrypted variable file must be included with vars_files in the playbook, not merely present in the same directory.
Variables from a vault-encrypted file are only available to a play if the file is explicitly loaded, commonly through vars_files or include_vars. Merely placing the encrypted file alongside the playbook and supplying the vault password does not make its variables available, so the task referencing them fails with an undefined variable error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vault password file must be passed with --vault-id instead of --vault-password-file.
Why it's wrong here
The --vault-password-file option is valid and specifies the file containing the vault password. Using --vault-id is for labeling multiple vaults, not required for a single password file. The failure is not due to the option name; the variable is undefined likely because the vaulted file's variables are not loaded.
- ✗
The vault password file must have permissions of 0600, otherwise Ansible ignores it.
Why it's wrong here
While restrictive permissions are a security best practice, Ansible does not silently ignore a vault password file solely due to its permissions. The command would typically fail with a decryption error if the password were incorrect or unreadable, not with an undefined variable error.
- ✓
The vault-encrypted variable file must be included with vars_files in the playbook, not merely present in the same directory.
Why this is correct
Ansible does not automatically load variable files from the playbook directory. To use variables from secrets.yml, the playbook must explicitly include it, typically via vars_files: - secrets.yml. Without that inclusion, the variables are never loaded, causing an undefined variable error even though decryption succeeds.
- ✗
The variable file must be decrypted to plaintext before it can be used in a playbook.
Why it's wrong here
Ansible can load vault-encrypted variable files directly when a vault password is provided. Decrypting to plaintext is unnecessary and defeats the purpose of vault encryption. The error is not because the file is encrypted; it is because the file is not referenced in the playbook.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.