EX294 Manage task execution and roles Practice Question
Exhibit
[root@controller ~]# ansible-playbook -i inventory.ini site.yml --ask-vault-pass
Vault password:
PLAY [all] ***************************************************************
TASK [Gathering Facts] ***************************************************
ok: [server1]
TASK [common : Install httpd] ********************************************
fatal: [server1]: FAILED! => {"changed": false, "msg": "The task includes an option with an undefined variable. The error was: 'vault_httpd_port' is undefined"}
PLAY RECAP ****************************************************************
server1 : ok=1 changed=0 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0Refer to the exhibit. An administrator runs an Ansible playbook and receives the error shown. The playbook uses a variable 'vault_httpd_port' that should be stored in an encrypted vault file. Which step should the administrator take first to resolve the issue?
⚠ Common exam trap
EX294 often tests the misconception that simply re-encrypting or changing the vault password resolves variable loading issues, when the real problem is that the vault file is not referenced in the playbook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the vault file is referenced in the playbook using include_vars or vars_files, and that the vault password is correct.
The error indicates Ansible cannot find the variable 'vault_httpd_port' because the encrypted vault file containing it is not being loaded into the playbook's variable scope. The administrator must first verify that the vault file is properly referenced via include_vars or vars_files in the playbook, and that the correct vault password is supplied (e.g., via --ask-vault-pass or a vault password file). Without loading the vault file, the variable remains undefined regardless of encryption password changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Re-encrypt the vault file with a different password.
Why it's wrong here
Re-encrypting with a different password does not fix a playbook that cannot decrypt the existing vault; the error concerns the supplied password or vault ID, not the file's encryption key. Re-encryption suits rotating credentials after a compromise, not resolving a decryption error.
- ✗
Add 'vault_httpd_port' to the group_vars/all.yml file without encryption.
Why it's wrong here
Storing the variable unencrypted in group_vars/all.yml defeats the vault's purpose and does not address the decryption failure shown. Plain group_vars files are the right place for non-sensitive variables, so this would be correct only if the value were never meant to be secret.
- ✗
Use the --ask-vault-pass option again with a different password.
Why it's wrong here
Retrying with another password assumes the first was wrong, but the error typically indicates the vault password source was not supplied or the wrong vault ID was referenced. Re-prompting is correct when the administrator genuinely mistyped the password during an interactive run.
- ✓
Ensure the vault file is referenced in the playbook using include_vars or vars_files, and that the vault password is correct.
Why this is correct
Referencing the vault file via `vars_files` or `include_vars` is what actually loads `vault_httpd_port` into the play's variable scope; without that, Ansible cannot decrypt or resolve it, producing the undefined-variable error. Supplying the correct vault password then allows decryption to succeed, satisfying the stem's encrypted-vault constraint.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.