EX294 Manage inventories and credentials Practice Question
An administrator is using Ansible Vault to protect sensitive variables in an inventory project. The project has a vault-encrypted file 'secrets.yml' that contains the variable 'db_password'. The playbook needs to use this variable. Which TWO statements are correct about using vault-encrypted variables in this scenario? (Choose two.)
⚠ Common exam trap
The trap here is believing that vault-encrypted variables require special configuration like vault_identity_list or an unencrypted reference file, when they can be decrypted directly with a password provided at runtime.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vault password can be provided at runtime using the --ask-vault-pass option when running ansible-playbook.
Providing the vault password interactively with --ask-vault-pass or via a vault password file with --vault-password-file are both valid methods to decrypt vault-encrypted files. The password file can be a script that outputs the password, which is useful for automation. Vault-encrypted files can be used for any variables, including inventory variables, and do not require an unencrypted reference file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The variable db_password must be defined in a separate unencrypted file that references the encrypted one.
Why it's wrong here
Variables can be defined directly in a vault-encrypted file; there is no need for an unencrypted file to reference it. Ansible automatically decrypts vault-encrypted files when the vault password is provided. This option describes an unnecessary and incorrect extra step that would complicate the setup.
- ✓
The vault password can be provided at runtime using the --ask-vault-pass option when running ansible-playbook.
Why this is correct
The --ask-vault-pass option prompts for the vault password interactively when running ansible-playbook. This allows decryption of vault-encrypted files without storing the password in plain text. It is a secure and common method for providing the vault password during playbook execution, especially in interactive or ad-hoc runs.
- ✗
The vault-encrypted file must be listed in the ansible.cfg file under the [defaults] section as vault_identity_list.
Why it's wrong here
vault_identity_list in ansible.cfg is used to specify vault identity files for multiple vault passwords, but it is not required to simply use a vault-encrypted file. The file can be decrypted by providing a password via --ask-vault-pass or a vault password file. This option incorrectly states a mandatory configuration.
- ✗
Vault-encrypted variables can only be used in playbooks, not in inventory variables.
Why it's wrong here
Vault-encrypted files can be used for both playbook variables and inventory variables, including group_vars and host_vars. Ansible decrypts them transparently regardless of where they are loaded. This option incorrectly limits the use of vault encryption to playbooks only, which is not true.
- ✓
A vault password file can be specified using the --vault-password-file option, and it can be a script that outputs the password.
Why this is correct
The --vault-password-file option allows specifying a file containing the vault password. This file can be an executable script that outputs the password to stdout, enabling dynamic password retrieval from secure stores. This is a supported and flexible method for automating vault decryption in CI/CD pipelines.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.