EX294 Manage automation security and operations Practice Question
After rotating the Ansible Vault password in the automation controller, several job templates that use vault credentials start failing with 'decryption failed'. The vault credential has been updated with the new password. What is the most likely cause of the failure?
⚠ Common exam trap
Many exam-takers assume updating the vault credential in the controller is sufficient, but they overlook that the vault file itself must be re-encrypted with the new password.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vault file in the project repository still uses the old vault password and needs to be re-encrypted with the new password.
The vault file itself is encrypted with a specific password. When the vault password is rotated in the automation controller, the vault file stored in the project repository is still encrypted with the old password. The job template uses the vault credential to decrypt the file, but since the credential now holds the new password, decryption fails. The vault file must be re-encrypted with the new password using `ansible-vault rekey` or by decrypting and re-encrypting it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The automation controller needs a restart to apply the new vault credential.
Why it's wrong here
Credentials are read at job runtime, so a controller restart is unnecessary; the failure stems from encrypted content still using the old password. It is tempting because restarts often resolve stale configuration, and a restart would be correct if the controller cached credential data at startup rather than reading it per job.
- ✓
The vault file in the project repository still uses the old vault password and needs to be re-encrypted with the new password.
Why this is correct
Re-encrypting the vault file with the new password is required because Ansible Vault decrypts file contents using the password embedded at encryption time. Updating the credential in the automation controller only changes the password supplied at runtime; the repository file still carries ciphertext derived from the old password, so decryption fails until re-encrypted.
- ✗
The vault credential is not linked to the job template correctly.
Why it's wrong here
If the credential were unlinked, the job would fail earlier with a missing-credential error, not 'decryption failed' after a successful password update. It is tempting because credential-to-template association is a common misconfiguration, and it is the correct answer when a template references no vault credential at all.
- ✗
The vault credential type requires the old password to be stored separately.
Why it's wrong here
No separate old-password field exists; the credential stores one vault password, so this cannot cause decryption failure after rotation. It is tempting because vault credential types do expose input fields, and a distinct old-password field would be the correct answer if the controller supported password history for re-keying.
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.