EX294 Manage automation security and operations Practice Question
An organization uses automation controller and must ensure that sensitive data such as passwords and API keys are not exposed in job output. Which TWO actions should the administrator take? (Choose two.)
⚠ Common exam trap
The trap here is believing that increasing logging or relying on file permissions alone will protect secrets, when in fact those approaches can increase exposure or fail to secure the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use automation controller credentials to store secrets instead of plaintext variables.
Using no_log: true on tasks that handle secrets prevents their output from being logged or displayed. Storing secrets in automation controller credentials keeps them out of playbooks and job output. Together, these actions ensure sensitive data is not exposed while maintaining operational visibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use automation controller credentials to store secrets instead of plaintext variables.
Why this is correct
Automation controller credentials securely store secrets and inject them at runtime without writing them to job output. Using credentials instead of plaintext variables in playbooks prevents accidental exposure in logs and job details, aligning with the requirement to keep sensitive data out of output.
- ✗
Disable job output entirely for all job templates that use secrets.
Why it's wrong here
Disabling job output entirely would hinder troubleshooting and auditing, and is not a standard or necessary measure. The goal is to prevent sensitive data from appearing, not to remove all output. Other mechanisms like no_log and credentials achieve the requirement without eliminating useful output.
- ✓
Mark sensitive variables as no_log: true in tasks that might display them.
Why this is correct
The no_log: true directive on a task prevents its output from being logged or displayed, including any variables or command results. Applying it to tasks that handle secrets ensures those values do not appear in job output or logs, directly addressing the requirement to avoid exposure.
- ✗
Enable verbose logging on the job template to audit variable usage.
Why it's wrong here
Verbose logging increases the amount of data recorded, which can include variable values and command output. This would likely expose sensitive data rather than protect it. Verbose logging is useful for debugging but conflicts with the goal of preventing secret exposure in job output.
- ✗
Store all secrets in an unencrypted file on the automation controller and rely on file permissions.
Why it's wrong here
Unencrypted files, even with restrictive permissions, are not a secure storage method for secrets. They can be read by privileged users or processes and may be included in backups. This approach does not prevent exposure in job output and violates security best practices.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.