Courseiva

EX294 Manage task execution and roles Practice Question

Exhibit

[root@controller ~]# ansible-playbook -i inventory.ini site.yml --ask-vault-pass
Vault password: 

PLAY [all] ***************************************************************

TASK [Gathering Facts] ***************************************************
ok: [server1]

TASK [common : Install httpd] ********************************************
fatal: [server1]: FAILED! => {"changed": false, "msg": "The task includes an option with an undefined variable. The error was: 'vault_httpd_port' is undefined"}

PLAY RECAP ****************************************************************
server1                     : ok=1    changed=0    unreachable=0    failed=1    skipped=0    rescued=0    ignored=0

Refer to the exhibit. An administrator runs an Ansible playbook and receives the error shown. The playbook uses a variable 'vault_httpd_port' that should be stored in an encrypted vault file. Which step should the administrator take first to resolve the issue?

⚠ Common exam trap

EX294 often tests the misconception that simply re-encrypting or changing the vault password resolves variable loading issues, when the real problem is that the vault file is not referenced in the playbook.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the vault file is referenced in the playbook using include_vars or vars_files, and that the vault password is correct.

The error indicates Ansible cannot find the variable 'vault_httpd_port' because the encrypted vault file containing it is not being loaded into the playbook's variable scope. The administrator must first verify that the vault file is properly referenced via include_vars or vars_files in the playbook, and that the correct vault password is supplied (e.g., via --ask-vault-pass or a vault password file). Without loading the vault file, the variable remains undefined regardless of encryption password changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Re-encrypt the vault file with a different password.

    Why it's wrong here

    Re-encrypting with a different password does not fix a playbook that cannot decrypt the existing vault; the error concerns the supplied password or vault ID, not the file's encryption key. Re-encryption suits rotating credentials after a compromise, not resolving a decryption error.

  • ✗

    Add 'vault_httpd_port' to the group_vars/all.yml file without encryption.

    Why it's wrong here

    Storing the variable unencrypted in group_vars/all.yml defeats the vault's purpose and does not address the decryption failure shown. Plain group_vars files are the right place for non-sensitive variables, so this would be correct only if the value were never meant to be secret.

  • ✗

    Use the --ask-vault-pass option again with a different password.

    Why it's wrong here

    Retrying with another password assumes the first was wrong, but the error typically indicates the vault password source was not supplied or the wrong vault ID was referenced. Re-prompting is correct when the administrator genuinely mistyped the password during an interactive run.

  • ✓

    Ensure the vault file is referenced in the playbook using include_vars or vars_files, and that the vault password is correct.

    Why this is correct

    Referencing the vault file via `vars_files` or `include_vars` is what actually loads `vault_httpd_port` into the play's variable scope; without that, Ansible cannot decrypt or resolve it, producing the undefined-variable error. Supplying the correct vault password then allows decryption to succeed, satisfying the stem's encrypted-vault constraint.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.