Courseiva

EX294 Manage automation security and operations Practice Question

An automation team wants to securely store SSH private keys for use in playbooks. Which Ansible feature should they use?

⚠ Common exam trap

The trap here is that candidates might confuse Ansible Vault with Ansible Galaxy, assuming Galaxy provides security features because it is a central repository, but Galaxy only distributes content and has no encryption or secure storage capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ansible Vault

Ansible Vault is the correct feature for securely storing SSH private keys because it encrypts sensitive data at rest using AES-256, allowing keys to be decrypted at runtime when a vault password or key is provided. This enables playbooks to reference encrypted SSH key files without exposing plaintext credentials in version control or on disk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ansible Collections

    Why it's wrong here

    Collections package modules, roles and plugins for distribution; they provide no encryption or vault mechanism for credentials. They are tempting as the standard way to bundle and share automation content, but storing SSH private keys securely requires Ansible Vault, which encrypts the file and decrypts it during playbook execution.

  • ✓

    Ansible Vault

    Why this is correct

    Ansible Vault encrypts sensitive files and variables at rest using AES-256, so SSH private keys can be stored in encrypted form and decrypted at runtime with the vault password. This satisfies the requirement for secure storage rather than plaintext in the repository.

  • ✗

    Ansible Fact Cache

    Why it's wrong here

    Fact Cache stores gathered host facts between runs to speed execution; it neither encrypts nor protects credentials. It is tempting because it persists data across playbook runs, but SSH private keys need Ansible Vault, which encrypts secrets at rest and supplies them decrypted at runtime.

  • ✗

    Ansible Galaxy

    Why it's wrong here

    Galaxy distributes community roles and collections, holding no encrypted secret storage or decryption mechanism for playbook use. It is tempting as a central repository for sharing automation content, but secrets require Ansible Vault, which encrypts values at rest and decrypts them at runtime.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.