EX294 Manage automation security and operations Practice Question
An organization needs to implement security best practices for Ansible automation. Which three measures should be taken? (Choose three.)
⚠ Common exam trap
Candidates often think disabling SSH host key checking is acceptable for convenience in lab environments, but the exam expects you to recognize it as a security risk that should never be applied globally in production.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use ansible-vault to encrypt sensitive variables
Option A is correct because ansible-vault encrypts sensitive variables and files (e.g., via `ansible-vault encrypt` or `encrypt_string`) so secrets such as passwords and API keys are not exposed in plain text within playbooks or repositories. Option C is correct because regularly rotating Ansible Vault passwords limits the impact of a compromised vault password and should be paired with `ansible-vault rekey` to re-encrypt vaulted content under the new password. Option E is correct because limiting access to the automation controller with role-based access control (RBAC) enforces least privilege, ensuring only authorized users or teams can launch jobs, edit credentials, or manage inventories. Option B is not acceptable since storing secrets in plain text in a repository exposes them to anyone with repo access and violates security best practices. Option D is wrong because disabling SSH host key checking globally removes protection against man-in-the-middle attacks and should not be done as a security measure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use ansible-vault to encrypt sensitive variables
Why this is correct
Encrypting sensitive variables with ansible-vault protects credentials and secrets at rest, satisfying the requirement to secure automation data. Vault-encrypted files remain usable in playbooks via the vault password, so confidentiality is achieved without breaking execution. This directly addresses the security best-practise constraint in the stem.
- ✗
Store all secrets in plain text in repository
Why it's wrong here
Plain-text secrets in a repository expose credentials to anyone with read access and to Git history indefinitely, violating the vault-backed lookup requirement. It is tempting because it is the quickest way to make variables available to playbooks, and it would be correct only for non-sensitive placeholder values that carry no authentication or privilege.
- ✓
Regularly rotate Ansible Vault passwords
Why this is correct
Rotating vault passwords limits the window in which a compromised password remains usable, and rekeying re-encrypts existing vault files under the new password. This satisfies the requirement to reduce exposure from leaked or stale credentials.
- ✗
Disable SSH host key checking globally
Why it's wrong here
Disabling SSH host key checking removes the verification that a managed node's presented key matches the known_hosts entry, permitting silent man-in-the-middle substitution of the target host. It is tempting because it eliminates prompts during first connection, and it would be correct only in disposable lab environments where host authenticity is genuinely irrelevant.
- ✓
Limit access to automation controller using RBAC
Why this is correct
Role-based access control in automation controller restricts which users and teams can launch jobs, view credentials or edit inventories, enforcing least privilege. This satisfies the requirement to limit who can reach automation resources and their secrets.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.