Courseiva

EX294 · topic practice

Manage automation security and operations practice questions

This domain covers securing Ansible automation and operating it at scale: protecting secrets with Ansible Vault, controlling access in Automation Controller, and building custom execution environments. Questions are scenario-based, asking you to choose correct practices or configuration approaches rather than recall syntax, so you must understand how vault, RBAC, credentials, and containerized execution fit together.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage automation security and operations

What the exam tests

What to know about Manage automation security and operations

You must be able to encrypt sensitive data with Ansible Vault, store credentials such as SSH keys in Automation Controller, and scope team permissions to specific job templates. The most important thing is applying least privilege: grant only the access needed and never expose secrets in plaintext.

Encrypting variables and files with ansible-vault and supplying vault passwords at runtime

Storing SSH private keys as Automation Controller credentials instead of plaintext in playbooks

Assigning Automation Controller roles and teams so users only launch permitted job templates

Building custom execution environments with ansible-builder and container tooling for jobs

Watch out for

Common Manage automation security and operations exam traps

  • ▸Committing vault-encrypted files without managing the vault password securely, or hardcoding the password in playbooks and inventory instead of supplying it separately.
  • ▸Granting broad Automation Controller roles such as System Administrator or Organization Admin when only job template launch access was required for the team.
  • ▸Assuming the default execution environment contains every collection or Python dependency, then failing to build and register a custom execution environment.

Practice set

Manage automation security and operations questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Ansible explanation →

An Ansible automation controller job template uses a custom credential type that requires a secret token. The token is stored as an extra variable in the job template definition. A security audit reveals the token is visible in plaintext in the job output. Which action should the administrator take to secure the secret?

Question 2hardmultiple choice
Read the full Ansible explanation →

A Red Hat Ansible Automation Platform deployment uses automation mesh to manage remote nodes across a high-latency WAN. An administrator notices that some job runs fail intermittently due to connection timeouts. The administrator wants to improve reliability without changing network infrastructure. Which configuration change is most effective?

Question 3easymultiple choice
Read the full Ansible explanation →

An organization requires that all Ansible playbooks be executed using a specific service account that has limited permissions. The account can only run playbooks from a specific directory. Which approach best enforces this requirement in automation controller?

Question 4hardmultiple choice
Read the full Ansible explanation →

A managed node is not responding to Ansible automation. The administrator verifies that the node is reachable via SSH and that the SSH key is correctly deployed. However, 'ansible all -m ping' fails with 'UNREACHABLE'. The automation controller uses a custom execution environment. What is the most likely cause?

Question 5mediummulti select
Read the full Ansible explanation →

An automation controller administrator must ensure that a playbook's output does not expose sensitive data. Which TWO actions should be taken? (Choose exactly two.)

An organization has multiple automation controller clusters spread across different geographic regions. The security policy requires that job artifacts (such as logs and assets) must remain in the region where the job ran. Which THREE configurations support this requirement? (Choose exactly three.)

Question 7hardmultiple choice
Read the full Ansible explanation →

You are managing an Ansible Automation Platform deployment that uses automation mesh with one control node and two execution nodes. The control node is in the DMZ, and the execution nodes are in a private network. The organization's security policy requires that all secrets (e.g., SSH keys, API tokens) be encrypted at rest and never transmitted in plaintext. You have configured vault-encrypted credentials and set the vault password as a credential on the control node. However, a recent audit reveals that when a job runs, the vault password is visible in the job output on the execution nodes. The execution nodes are configured to stream job events back to the control node. The automation controller version is 4.3. The following settings are in place: 'no_log' is not set for any variables; the vault password is stored as a 'Vault password' credential type. The job template uses a custom credential type that injects the vault password as an environment variable. The execution nodes have access to the vault password via that environment variable. The audit shows the environment variable is printed in the job output because the playbook uses the 'env' module to display environment variables for debugging. You must prevent the vault password from appearing in any job output without breaking the ability to decrypt vault-encrypted variables. Which action should you take?

Question 8hardmultiple choice
Read the full Ansible explanation →

Your team manages a fleet of 200 Red Hat Enterprise Linux 8 servers. Security policy requires that all servers have a specific set of security configurations: (1) SELinux must be enforcing, (2) the firewall must allow only SSH and HTTPS, (3) SSH root login must be disabled, and (4) the 'auditd' service must be running and enabled. You have created an Ansible role 'security-hardening' that applies these settings. The role is idempotent and uses the 'lineinfile' module to modify /etc/ssh/sshd_config, the 'firewalld' module to configure firewall rules, the 'selinux' module to set SELinux to enforcing, and the 'service' module to enable and start auditd. You run the playbook against a test group of 10 servers, and it reports 'changed=0' for all tasks, indicating the servers are already compliant. However, a subsequent manual audit reveals that on two servers, SELinux is permissive and SSH root login is still permitted. What is the most likely cause of this discrepancy?

Match each Linux command to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Socket statistics

Query systemd journal

Show current SELinux mode

Manage firewalld rules

Extend a logical volume

Question 10mediummultiple choice
Read the full Ansible explanation →

A playbook fails with 'ERROR! 'become' is not a valid attribute for a Play'. What is the most likely cause?

Question 11mediummultiple choice
Read the full Ansible explanation →

An Ansible playbook is failing due to an undefined variable. Which approach would best help identify the source of the variable?

An administrator needs to limit the number of concurrent jobs that can run on a specific automation controller node. Which setting should be adjusted?

Question 13mediummultiple choice
Read the full Ansible explanation →

A playbook using the 'uri' module is timing out when connecting to an external API. The network team confirms connectivity. What Ansible configuration parameter can be adjusted to increase the timeout?

A security team requires that all automation controller job logs be forwarded to an external SIEM system. Which integration should be used?

Question 15mediummultiple choice
Read the full Ansible explanation →

Refer to the exhibit. The user ran ansible-navigator without specifying an inventory. What does the warning indicate about the target hosts?

Network Topology
$ ansible-navigator run playbook.ymlmode stdoutPLAY [all] *********************************************************************TASK [Gathering Facts] *********************************************************ok: [localhost]TASK [debug] *******************************************************************ok: [localhost] => {"msg": "Hello"PLAY RECAP *********************************************************************localhostok=2 changed=0 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0

Refer to the exhibit. An automation job failed with the given error. What is the most likely cause?

Exhibit

TASK [deploy app] **************************************************************
fatal: [web01.example.com]: FAILED! => {"changed": false, "msg": "Failed to connect to the host via ssh: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).", "unreachable": true}

Which two conditions could prevent an automation controller job from starting? (Choose two.)

Question 18easymultiple choice
Read the full Ansible explanation →

A systems administrator needs to securely store a database password for use in an Ansible playbook. The password should be encrypted at rest and decrypted only at runtime when the playbook is executed. Which approach should the administrator take?

Question 19mediummultiple choice
Read the full Ansible explanation →

An administrator is configuring a job template in automation controller that runs a playbook to deploy a web application. The playbook requires a database password that changes quarterly. To avoid updating the credential each quarter, what is the best approach to dynamically provide the password without exposing it in the playbook?

A workflow template in automation controller consists of three job templates that must run sequentially with different credentials. The first job template uses a machine credential to provision a VM, the second uses a network credential to configure the switch, and the third uses a cloud credential to deploy the application. To secure the credential usage, what should the administrator configure?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage automation security and operations sessions

Start a Manage automation security and operations only practice session

Every question in these sessions is drawn from the Manage automation security and operations domain — nothing else.

Related practice questions

Related EX294 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the EX294 exam test about Manage automation security and operations?
You must be able to encrypt sensitive data with Ansible Vault, store credentials such as SSH keys in Automation Controller, and scope team permissions to specific job templates. The most important thing is applying least privilege: grant only the access needed and never expose secrets in plaintext.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage automation security and operations questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage automation security and operations domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other EX294 topics?
Use the topic links above to move to related areas, or go back to the EX294 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the EX294 exam covers. They are not copied from any real exam or dump site.