Courseiva

EX294 Manage automation security and operations Practice Question

An automation controller administrator must ensure that a job template handling credentials follows security best practices for both storage and execution. Which TWO actions should be taken in automation controller? (Choose two.)

⚠ Common exam trap

The trap here is assuming that a job template option can globally hide Ansible output, when output masking is handled per task with no_log and controller's role is encrypted storage plus runtime injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reference the credential from the job template so it is injected at runtime instead of hardcoding it in the playbook.

Automation controller stores credentials encrypted and injects them at run time, so keeping SSH keys in a machine credential and referencing that credential from the job template removes secrets from source control and from static inventories. Together these actions centralize secret storage and limit exposure to the moment of execution, which is the intended best practice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reference the credential from the job template so it is injected at runtime instead of hardcoding it in the playbook.

    Why this is correct

    Attaching the credential to the job template lets automation controller inject it into the execution environment at run time, removing hardcoded secrets from playbooks and inventories. This complements encrypted storage and ensures the value is only present transiently during the job, which is the intended best practice.

  • ✗

    Enable the job template option to suppress Ansible output so sensitive data is not written to job logs.

    Why it's wrong here

    Automation controller does not provide a job template toggle that globally suppresses all Ansible output; output suppression is controlled at the task level with no_log. Relying on a nonexistent template option would leave credentials visible in job output, so this action does not meet the requirement.

  • ✗

    Grant the operator system administrator role on the organization so they can manage all credentials centrally.

    Why it's wrong here

    Broad privileges increase risk and contradict least-privilege principles; operators who launch templates do not need to administer credentials. This action would violate the security best practice the scenario asks for rather than satisfy it, because it expands access instead of limiting credential exposure.

  • ✓

    Store the SSH private key as a machine credential in automation controller rather than in a project repository.

    Why this is correct

    Machine credentials keep SSH keys encrypted inside the controller database and inject them only at job runtime, so the private key never lands in a Git repository. This is the supported storage model and satisfies the requirement that credentials are managed centrally and not exposed in project source.

  • ✗

    Mark the job template as prompting for the credential on launch so operators supply secrets interactively.

    Why it's wrong here

    Prompting for credentials is valid for some scenarios but does not by itself establish secure storage or prevent exposure in job output; it shifts secret handling to the operator and can still leave values in logs if tasks print them. It is not one of the two actions that best satisfy the stated best-practice requirement for stored credentials.

About these practice questions

This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.