Courseiva

EX294 Manage automation security and operations Practice Question

An organization needs to implement security best practices for Ansible automation. Which three measures should be taken? (Choose three.)

⚠ Common exam trap

Candidates often think disabling SSH host key checking is acceptable for convenience in lab environments, but the exam expects you to recognize it as a security risk that should never be applied globally in production.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use ansible-vault to encrypt sensitive variables

Option A is correct because ansible-vault encrypts sensitive variables and files (e.g., via `ansible-vault encrypt` or `encrypt_string`) so secrets such as passwords and API keys are not exposed in plain text within playbooks or repositories. Option C is correct because regularly rotating Ansible Vault passwords limits the impact of a compromised vault password and should be paired with `ansible-vault rekey` to re-encrypt vaulted content under the new password. Option E is correct because limiting access to the automation controller with role-based access control (RBAC) enforces least privilege, ensuring only authorized users or teams can launch jobs, edit credentials, or manage inventories. Option B is not acceptable since storing secrets in plain text in a repository exposes them to anyone with repo access and violates security best practices. Option D is wrong because disabling SSH host key checking globally removes protection against man-in-the-middle attacks and should not be done as a security measure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use ansible-vault to encrypt sensitive variables

    Why this is correct

    Encrypting sensitive variables with ansible-vault protects credentials and secrets at rest, satisfying the requirement to secure automation data. Vault-encrypted files remain usable in playbooks via the vault password, so confidentiality is achieved without breaking execution. This directly addresses the security best-practise constraint in the stem.

  • ✗

    Store all secrets in plain text in repository

    Why it's wrong here

    Plain-text secrets in a repository expose credentials to anyone with read access and to Git history indefinitely, violating the vault-backed lookup requirement. It is tempting because it is the quickest way to make variables available to playbooks, and it would be correct only for non-sensitive placeholder values that carry no authentication or privilege.

  • ✓

    Regularly rotate Ansible Vault passwords

    Why this is correct

    Rotating vault passwords limits the window in which a compromised password remains usable, and rekeying re-encrypts existing vault files under the new password. This satisfies the requirement to reduce exposure from leaked or stale credentials.

  • ✗

    Disable SSH host key checking globally

    Why it's wrong here

    Disabling SSH host key checking removes the verification that a managed node's presented key matches the known_hosts entry, permitting silent man-in-the-middle substitution of the target host. It is tempting because it eliminates prompts during first connection, and it would be correct only in disposable lab environments where host authenticity is genuinely irrelevant.

  • ✓

    Limit access to automation controller using RBAC

    Why this is correct

    Role-based access control in automation controller restricts which users and teams can launch jobs, view credentials or edit inventories, enforcing least privilege. This satisfies the requirement to limit who can reach automation resources and their secrets.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.