EX294 Manage automation security and operations Practice Question
An organization uses Ansible Automation Platform to manage a large infrastructure. They need to implement security best practices for managing secrets and credentials. Which TWO of the following actions should they take to enhance security? (Choose two.)
⚠ Common exam trap
The trap here is thinking that disabling all logging or sharing vault passwords insecurely might be acceptable shortcuts, when they actually undermine security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Ansible Vault to encrypt sensitive variables and files before committing them to source control.
Using Ansible Vault to encrypt sensitive data before committing to source control and integrating automation controller with external secret management systems are two key best practices. They ensure secrets are encrypted at rest and managed centrally with access controls. Storing secrets in plain text, disabling all logging, or sharing vault passwords insecurely are harmful practices that would weaken security. These two actions align with the principle of least privilege and defense in depth.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable logging for all playbook runs to prevent any possibility of secrets being logged.
Why it's wrong here
Disabling logging entirely is not a best practice; logs are essential for auditing, troubleshooting, and compliance. Instead, use `no_log` on specific tasks that handle sensitive data. Completely disabling logs would hinder operational visibility and incident response. This action would reduce security by eliminating audit trails, not enhance it.
- ✓
Use Ansible Vault to encrypt sensitive variables and files before committing them to source control.
Why this is correct
Ansible Vault encrypts sensitive data at rest, allowing safe storage in source control. By encrypting variables and files, the organization ensures that secrets are not exposed in plain text. This is a recommended best practice for managing secrets in Ansible. It integrates seamlessly with playbook execution, decrypting only at runtime with the proper password.
- ✗
Store all secrets in plain text in the Git repository to simplify version control.
Why it's wrong here
Storing secrets in plain text in a Git repository is a critical security risk. Anyone with repository access can view the secrets, and they may be exposed in commit history. This violates security best practices. Instead, secrets should be encrypted using Ansible Vault or stored in a secure external system like a vault server. This action would degrade security, not enhance it.
- ✗
Share the vault password among all team members via email to ensure everyone can run playbooks.
Why it's wrong here
Sharing vault passwords via email is insecure; email is not a secure channel and passwords could be intercepted or leaked. Best practices include using a secure password manager or vault system to distribute secrets. Additionally, limiting access to vault passwords based on roles reduces risk. This action would compromise security rather than improve it.
- ✓
Configure automation controller credentials to use external secret management systems like HashiCorp Vault or CyberArk.
Why this is correct
Integrating automation controller with external secret management systems centralizes secret storage and provides advanced features like auditing, rotation, and access control. This reduces the risk of secrets being scattered across playbooks or inventory. It is a best practice for enterprise environments. Automation controller supports credential plugins for such systems, enhancing overall security posture.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.