EX294 Transform data with filters and plugins Practice Question
A security team requires that all passwords in an Ansible vault be encrypted with a different key from the host variables. They want to use a custom lookup plugin that fetches secrets from an external API. Which plugin type should be developed?
⚠ Common exam trap
Test-takers frequently confuse lookup plugins with modules, thinking that any external interaction requires a module, but modules are for remote host actions, while lookups are for controller-side data retrieval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lookup plugin
A lookup plugin is the correct choice because it is designed to retrieve data from external sources (like an API) and return it as a string or list for use in Ansible playbooks. This aligns with the requirement to fetch secrets from an external API, and lookup plugins can be used directly in variables or templates without modifying the host state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Lookup plugin
Why this is correct
A lookup plugin runs on the control node and returns data to Ansible, so it can query an external API for secrets at runtime. This satisfies the requirement to fetch vault passwords from a source separate from host variables, unlike vault password files or inventory variables.
- ✗
Module
Why it's wrong here
Modules run as discrete tasks on managed hosts and cannot be called inline within a template or variable expression. Modules are correct when the requirement is a repeatable task, such as installing packages or managing services.
- ✗
Action plugin
Why it's wrong here
Action plugins execute controller-side logic tied to a module's lifecycle, not standalone secret retrieval invoked by lookup. They suit wrapping module behaviour, such as custom copy or template handling, rather than querying an external secrets API.
- ✗
Filter plugin
Why it's wrong here
Filter plugins transform data within Jinja2 expressions and cannot fetch secrets from an external API during task execution. They are correct for custom data manipulation, such as parsing or reformatting values already available to the playbook.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.