EX294 Manage automation security and operations Practice Question
A playbook uses the `copy` module to distribute a configuration file to managed nodes. The file contains a sensitive API key. You want to ensure the API key is not visible in the playbook source or in Ansible logs. Which approach should you use?
⚠ Common exam trap
The trap here is assuming Ansible automatically hides sensitive data in module parameters, when only explicit no_log: true suppresses task output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the API key in a vault-encrypted variable file, reference it in the copy module's content parameter, and set no_log: true on the task.
To protect a sensitive API key, it should be stored encrypted using Ansible Vault and referenced in the playbook without exposing plaintext. Marking the task with no_log: true prevents the secret from appearing in output or logs. Using plaintext variables, hardcoded values, or environment variables without no_log leaves the secret exposed in the playbook source or execution logs, failing the security requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the API key in an environment variable on the control node and use the `lookup` plugin `env` to inject it into the copy module.
Why it's wrong here
Using an environment variable on the control node may keep the key out of the playbook, but the lookup result can still appear in task output unless no_log is set. Environment variables are also not encrypted at rest and can be exposed to other processes. This method does not provide the same level of protection as a vault-encrypted file with no_log, and it lacks secure storage.
- ✗
Use the `copy` module with the API key hardcoded in the content parameter and rely on Ansible's automatic log redaction.
Why it's wrong here
Ansible does not automatically redact arbitrary secrets in module parameters; only tasks marked with no_log: true suppress output. Hardcoding the API key in the content parameter leaves it visible in the playbook and potentially in logs. This approach fails to protect the secret and does not meet the security requirement.
- ✗
Use the `template` module with a Jinja2 template that includes the API key as a plaintext variable defined in the playbook.
Why it's wrong here
Defining the API key as a plaintext variable in the playbook exposes it in the source code and in any logs that show variable values. Even if the template module renders the file correctly, the secret is not protected at rest or during execution. This violates the requirement to keep the API key out of the playbook source and logs.
- ✓
Store the API key in a vault-encrypted variable file, reference it in the copy module's content parameter, and set no_log: true on the task.
Why this is correct
Using a vault-encrypted variable file keeps the API key encrypted at rest and out of the playbook source. Referencing it in the content parameter allows the file to be generated with the secret. Setting no_log: true prevents the task output from displaying the secret in logs or console. Together, these measures protect the key in both storage and execution, meeting the requirement.
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.