Courseiva

EX294 Manage automation security and operations Practice Question

An automation controller administrator needs to ensure that a vault password used by multiple job templates is rotated periodically without editing each job template. Which approach is most efficient and secure?

⚠ Common exam trap

The trap here is thinking that separate credentials per job template or storing the password in the repository is necessary, when a shared credential provides centralized rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a single vault credential, attach it to all relevant job templates, and update the credential when rotating the password.

A shared vault credential in automation controller allows multiple job templates to use the same secret. Rotating the password only requires updating the credential, which automatically applies to all attached job templates. This is both efficient and secure, as the credential is encrypted and access-controlled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the vault password in a file on the automation controller and reference it from each job template's extra variables.

    Why it's wrong here

    Storing the password in a file and referencing it via extra variables is insecure and not a supported pattern. Extra variables are visible in job output and logs, exposing the password. This approach also requires updating each job template when the password changes, defeating the goal of efficiency.

  • ✗

    Use a separate vault credential for each job template so that rotation can be done independently.

    Why it's wrong here

    Using separate credentials for each job template means that rotation requires updating each credential individually, which is inefficient and error-prone. The requirement is to rotate without editing each job template, so a shared credential is more appropriate.

  • ✓

    Create a single vault credential, attach it to all relevant job templates, and update the credential when rotating the password.

    Why this is correct

    A single vault credential can be shared across multiple job templates. When the password is rotated, updating the credential automatically propagates the new password to all attached job templates, avoiding individual edits. This centralizes management and reduces the risk of missing a template.

  • ✗

    Embed the vault password in the playbook repository and use a source control webhook to trigger updates.

    Why it's wrong here

    Embedding the vault password in the repository is a severe security risk, as it would be accessible to anyone with repository access. A webhook does not secure the password. This approach violates security best practices and does not meet the requirement for secure rotation.

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.