EX294 Manage inventories and credentials Practice Question
An administrator needs to store sensitive credentials for a playbook that will be run from a control node. The credentials include an SSH password and a sudo password. The administrator wants to keep these encrypted at rest and avoid hardcoding them in the playbook. Which TWO methods are valid for providing these credentials securely? (Choose two.)
⚠ Common exam trap
The trap here is thinking that any method that supplies the password value is acceptable, ignoring the need for encryption at rest and avoidance of exposure in logs or process lists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the passwords in the inventory file as host variables, and encrypt the inventory file with ansible-vault.
Ansible Vault is the primary tool for encrypting sensitive data at rest. Encrypting a vars file and including it with vars_files, or encrypting an inventory file that contains host variables, both securely provide passwords to playbooks. The vault password can be supplied separately. Command-line extra vars, debug printing, and environment variables either expose secrets or fail to encrypt them at rest, so they are not valid secure methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define the passwords as extra variables using the -e option on the command line, like -e "ansible_password=secret".
Why it's wrong here
Passing passwords via -e exposes them in the command line, which can be seen in process listings and shell history. It also does not encrypt them at rest. While it provides the values, it violates the requirement to keep credentials secure and avoid hardcoding. This method is insecure and not recommended for sensitive data.
- ✗
Set the passwords as environment variables on the control node and reference them with lookup('env', 'SSH_PASSWORD') in the playbook.
Why it's wrong here
Environment variables are not encrypted at rest and can be exposed through process listings or shell environments. Referencing them with lookup('env') does not provide secure storage; it merely reads the value. This approach does not meet the requirement to keep credentials encrypted at rest and avoid hardcoding. It is less secure than using Ansible Vault.
- ✗
Use the ansible.builtin.debug module to print the passwords from a vault-encrypted file, then manually copy them into the playbook.
Why it's wrong here
Printing passwords with debug exposes them in logs and console output, defeating the purpose of encryption. Manually copying them into the playbook would hardcode them in plaintext, which is explicitly to be avoided. This method is insecure and does not provide a secure way to manage credentials. It fails both the encryption and the no-hardcoding requirements.
- ✓
Store the passwords in the inventory file as host variables, and encrypt the inventory file with ansible-vault.
Why this is correct
Inventory files can contain host variables, including ansible_password and ansible_become_password. Encrypting the entire inventory file with ansible-vault protects the credentials at rest. Ansible can decrypt the inventory at runtime if the vault password is provided. This method is valid and keeps sensitive data encrypted, meeting the requirement.
- ✓
Use ansible-vault to encrypt a vars file containing the passwords, and include it with vars_files in the playbook.
Why this is correct
Ansible Vault encrypts files or variables, allowing secure storage of sensitive data. By encrypting a vars file and including it via vars_files, the playbook can access the passwords without exposing them in plaintext. The vault password can be supplied at runtime via a file or prompt. This is a standard, secure method for managing credentials in Ansible.
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.