EX294 Manage automation security and operations Practice Question
An automation team wants to securely store SSH private keys for use in playbooks. Which Ansible feature should they use?
⚠ Common exam trap
The trap here is that candidates might confuse Ansible Vault with Ansible Galaxy, assuming Galaxy provides security features because it is a central repository, but Galaxy only distributes content and has no encryption or secure storage capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ansible Vault
Ansible Vault is the correct feature for securely storing SSH private keys because it encrypts sensitive data at rest using AES-256, allowing keys to be decrypted at runtime when a vault password or key is provided. This enables playbooks to reference encrypted SSH key files without exposing plaintext credentials in version control or on disk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ansible Collections
Why it's wrong here
Collections package modules, roles and plugins for distribution; they provide no encryption or vault mechanism for credentials. They are tempting as the standard way to bundle and share automation content, but storing SSH private keys securely requires Ansible Vault, which encrypts the file and decrypts it during playbook execution.
- ✓
Ansible Vault
Why this is correct
Ansible Vault encrypts sensitive files and variables at rest using AES-256, so SSH private keys can be stored in encrypted form and decrypted at runtime with the vault password. This satisfies the requirement for secure storage rather than plaintext in the repository.
- ✗
Ansible Fact Cache
Why it's wrong here
Fact Cache stores gathered host facts between runs to speed execution; it neither encrypts nor protects credentials. It is tempting because it persists data across playbook runs, but SSH private keys need Ansible Vault, which encrypts secrets at rest and supplies them decrypted at runtime.
- ✗
Ansible Galaxy
Why it's wrong here
Galaxy distributes community roles and collections, holding no encrypted secret storage or decryption mechanism for playbook use. It is tempting as a central repository for sharing automation content, but secrets require Ansible Vault, which encrypts values at rest and decrypts them at runtime.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.