Courseiva

EX294 Manage automation security and operations Practice Question

A playbook must retrieve a secret from an external vault service at runtime instead of storing it in the repository. The team wants the value available as a variable named db_password. Which Ansible feature should be used?

⚠ Common exam trap

It's easy for candidates to confuse Ansible Vault, which encrypts secrets stored in the project, with lookup plugins that retrieve secrets from an external service at run time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A lookup plugin such as community.hashi_vault.hashi_vault referenced in a set_fact task.

Lookup plugins execute on the control node and query external data sources during a play run, which is the supported way to pull secrets from services such as HashiCorp Vault. Assigning the lookup result to a variable with set_fact makes the secret usable by later tasks while keeping it out of the repository entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An ansible-vault encrypted file committed to the project and decrypted with a password file.

    Why it's wrong here

    Ansible Vault protects secrets stored inside the repository, but the stem explicitly requires retrieval from an external vault service rather than local encrypted storage. Encrypting a file still means the secret is committed, which contradicts the stated design and does not integrate with the external service.

  • ✗

    A fact gathered by the setup module from the managed node's /etc/shadow file.

    Why it's wrong here

    The setup module gathers system facts and does not read arbitrary secret files such as /etc/shadow; even if it did, copying secrets from the managed node is not external vault retrieval and would be insecure. This option neither implements the required integration nor provides the named variable reliably.

  • ✓

    A lookup plugin such as community.hashi_vault.hashi_vault referenced in a set_fact task.

    Why this is correct

    Lookup plugins query external systems at execution time, so a HashiCorp Vault lookup can fetch db_password dynamically without persisting it in the repository. Assigning the result with set_fact makes the value available to subsequent tasks, which matches the requirement for runtime secret retrieval from an external vault service.

  • ✗

    A host variable defined in the inventory and marked with no_log on the consuming task.

    Why it's wrong here

    no_log hides output but does not secure storage, and a host variable in the inventory is still a static secret committed with the inventory. This fails the requirement to fetch the value from an external vault service at runtime and leaves the secret exposed in inventory files.

About these practice questions

Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.