EX294 Manage inventories and credentials Practice Question
Which THREE of the following are best practices for managing credentials in Ansible Automation Controller?
⚠ Common exam trap
Watch out — candidates often think storing all secrets inside Automation Controller is safer than using an external vault, but Red Hat specifically recommends integrating with external secret managers for centralized control and rotation, making Option A a common misconception.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict credential 'Use' permissions to specific users or teams
Ansible Automation Controller's Role-Based Access Control (RBAC) allows administrators to assign granular 'Use' permissions to specific users or teams, ensuring that only authorized entities can leverage a credential for job runs. This prevents unauthorized access to sensitive secrets and aligns with the principle of least privilege, which is a core security best practice in automation environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid using external secret management systems; keep all secrets in Automation Controller
Why it's wrong here
External secret managers are recommended for better security and rotation.
- ✗
Share the same credential across multiple organizations for simplicity
Why it's wrong here
This violates the principle of least privilege.
- ✓
Restrict credential 'Use' permissions to specific users or teams
Why this is correct
This ensures only authorized users can use the credential.
- ✓
Use custom credential types to store secrets for third-party APIs
Why this is correct
Custom types allow secure injection of non-standard secrets.
- ✓
Use Vault credentials to store and encrypt sensitive variables in playbooks
Why this is correct
Vault credentials protect sensitive data at rest.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.