Courseiva

EX294 Implement advanced Ansible automation Practice Question

A playbook uses the `ansible.builtin.uri` module to interact with a REST API. The API requires a Bearer token that is stored in an encrypted variable file. The playbook must ensure the token is not exposed in logs. Which approach best meets the requirement?

⚠ Common exam trap

The trap here is assuming that encrypting the variable file with ansible-vault automatically prevents the token from being logged.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set `no_log: true` on the task that uses the `uri` module.

To prevent a sensitive token from appearing in logs, the task that uses the token must have no_log set to true. This suppresses all output from that task, including module arguments and results. While vault encrypts the token at rest, it does not prevent logging during execution. Therefore, no_log is the necessary control in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set `ANSIBLE_DEBUG` to false in the environment.

    Why it's wrong here

    ANSIBLE_DEBUG controls debug output, but even with debug disabled, Ansible logs task arguments and results at normal verbosity levels. The token could still appear in logs if the task output is not suppressed with no_log. Disabling debug does not specifically protect secrets; it only reduces the amount of diagnostic information displayed.

  • ✓

    Set `no_log: true` on the task that uses the `uri` module.

    Why this is correct

    The no_log directive prevents the task's output, including any sensitive data like tokens, from being logged or displayed. When set to true on the uri task, Ansible will not show the module arguments or results, which could contain the Bearer token. This is the standard way to protect secrets from being exposed in logs or console output during playbook execution.

  • ✗

    Encrypt the variable file with `ansible-vault` and reference it in the playbook.

    Why it's wrong here

    Encrypting the variable file with ansible-vault protects the token at rest, but once decrypted during playbook execution, the token is in plaintext in memory and can be logged. The requirement is to prevent exposure in logs, which vault alone does not achieve. You must also use no_log on tasks that handle the token to avoid logging its value.

  • ✗

    Use `vars_prompt` to ask for the token at runtime.

    Why it's wrong here

    vars_prompt is used to interactively request variables before a play starts, but it does not prevent the token from being logged if used in a task. The token would still be passed to the uri module and could appear in verbose output or logs unless no_log is used. Additionally, vars_prompt is not suitable for automation where the token is stored in an encrypted file.

About these practice questions

Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.