Courseiva

EX294 Manage automation security and operations Practice Question

An automation team uses Ansible Automation Platform to manage a large number of servers. They need to ensure that sensitive data such as passwords and API keys are not stored in plain text in playbooks or inventory files. They decide to use Ansible Vault to encrypt these secrets. Which of the following best describes how Ansible Vault integrates with playbook execution to protect secrets at runtime?

⚠ Common exam trap

The trap here is assuming that managed nodes perform decryption or that a shared vault password is used on managed nodes, when in fact decryption only happens on the control node.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ansible Vault decrypts secrets on the control node at runtime and passes the decrypted values to managed nodes as needed.

Ansible Vault decrypts encrypted files on the control node when the playbook runs, using the vault password supplied via command line or configuration. The decrypted variables are then used in playbook execution and can be passed to managed nodes as needed. This keeps secrets encrypted at rest in source control while enabling their use in automation. The other options incorrectly place decryption on managed nodes or describe non-existent keyring features.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ansible Vault decrypts secrets on the control node at runtime and passes the decrypted values to managed nodes as needed.

    Why this is correct

    Ansible Vault operates on the control node. When a playbook references a vault-encrypted file, Ansible decrypts it using the provided vault password. The decrypted variables are then available during playbook execution and are passed to managed nodes as part of task parameters when required. This ensures secrets are not stored in plain text in the repository while still allowing them to be used in automation.

  • ✗

    Ansible Vault stores secrets in an encrypted keyring on the control node and retrieves them only when explicitly requested by a task.

    Why it's wrong here

    Ansible Vault does not maintain an encrypted keyring. It decrypts entire files or variables at runtime when the vault password is provided. There is no separate keyring mechanism; the encrypted file itself is decrypted in memory. This option invents a feature that does not exist in Ansible Vault, leading to a misunderstanding of its architecture.

  • ✗

    Ansible Vault decrypts secrets on the managed node and stores them in memory only during task execution.

    Why it's wrong here

    Ansible Vault decrypts secrets on the control node, not on the managed node. The decrypted data is then passed to the managed node as part of the task execution, typically in module arguments. While the data may reside in memory on the managed node during execution, the decryption itself happens on the control node. This option misstates where decryption occurs.

  • ✗

    Ansible Vault encrypts secrets on the control node and decrypts them on the managed node using a shared vault password.

    Why it's wrong here

    Ansible Vault does not use a shared vault password on managed nodes. Decryption occurs exclusively on the control node. The managed node never receives the vault password or the encrypted file; it only receives the decrypted content as part of the module invocation. This option incorrectly suggests that managed nodes participate in decryption, which is not how Ansible Vault works.

About these practice questions

This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.