Courseiva

EX294 Manage inventories and credentials Practice Question

Which THREE considerations are important when designing a credential strategy in Ansible Automation Platform? (Choose exactly three.)

⚠ Common exam trap

Candidates often assume all credentials must be stored inside the AAP database for security, but the platform is designed to delegate secret storage to external vaults, and the question tests awareness of that flexibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credentials should be assigned to job templates rather than embedded in playbooks

Ansible Automation Platform (AAP) best practices dictate that credentials should be assigned to job templates, not embedded in playbooks. This decouples sensitive authentication data from automation logic, allowing credentials to be managed, rotated, and audited centrally through the AAP controller without exposing them in version-controlled playbook files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All credentials must be stored within the AAP database for security

    Why it's wrong here

    External secret backends can be used for enhanced security.

  • ✗

    Playbooks should contain hardcoded credentials for simplicity

    Why it's wrong here

    Hardcoding credentials is insecure and against best practices.

  • ✓

    Credentials should be assigned to job templates rather than embedded in playbooks

    Why this is correct

    Best practice is to manage credentials via AAP and assign them to templates.

  • ✓

    Custom credential types allow integration with external secrets management systems

    Why this is correct

    Custom types can fetch secrets from Vault, CyberArk, etc.

  • ✓

    Credential access can be restricted using RBAC on organizations, teams, and users

    Why this is correct

    RBAC ensures only authorized users can use specific credentials.

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.