Courseiva

EX294 Manage automation security and operations Practice Question

A playbook must write a sensitive token to a remote managed node's /etc/app/token.conf file. The security team requires that the token never appear in plaintext in the playbook or in the controller's job output. The token is stored in an Ansible Vault-encrypted variable file. Which task implementation best meets these requirements?

⚠ Common exam trap

The trap here is assuming that Vault encryption alone prevents secrets from appearing in job output; it protects the variable file at rest but does not suppress task logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the copy module with content: "{{ vault_token }}" and set no_log: true on the task.

The copy module with content and no_log: true ensures the decrypted vault variable is written to the remote file while suppressing sensitive task output. Storing the token only in the vault-encrypted file keeps the playbook free of plaintext. The other approaches either embed the secret in a template or allow the expanded token to be logged, violating the security requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the shell module with a command that echoes the token into the file and redirect the output to /dev/null.

    Why it's wrong here

    The shell module would expand the token in the command string, which Ansible logs at verbosity levels and in the task arguments. Redirecting stdout to /dev/null does not prevent the command itself from being recorded, so the token could still leak in the job output.

  • ✓

    Use the copy module with content: "{{ vault_token }}" and set no_log: true on the task.

    Why this is correct

    The copy module writes the decrypted token to the managed node without exposing it in logs when no_log is true. The variable is sourced from the vault-encrypted file, so the playbook itself contains no plaintext. This satisfies both the no-plaintext-in-playbook and no-leak-in-output requirements.

  • ✗

    Use the lineinfile module with line: "token={{ vault_token }}" and rely on Vault encryption alone.

    Why it's wrong here

    Vault encryption protects the variable file, but without no_log: true the lineinfile task would display the expanded line, including the decrypted token, in the job output. The requirement explicitly forbids plaintext exposure in output, so this approach fails.

  • ✗

    Use the template module with a Jinja2 template that contains the token literal and add no_log: true.

    Why it's wrong here

    Placing the token literal in the Jinja2 template means the plaintext secret exists in the template file, violating the requirement that the token never appear in plaintext in the playbook. While no_log: true would suppress output, the template file itself would still expose the secret if read.

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.