Courseiva

EX294 Manage automation security and operations Practice Question

You are using Ansible Automation Platform to manage a large number of servers. You need to ensure that playbooks that run against production servers use a separate set of credentials than those used for development servers. The production credentials must be stored securely and audited. Which Ansible Automation Platform feature should you use to achieve this?

⚠ Common exam trap

The trap here is thinking that Ansible Vault alone can provide the same level of secure storage and auditing as automation controller credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create separate credentials in automation controller and assign them to different job templates based on the environment.

Automation controller credentials are designed for secure storage and auditing. By creating separate credentials for production and development and assigning them to the appropriate job templates, you ensure that each environment uses its own set of secrets. The controller encrypts credentials and logs their usage, providing the required audit trail. The other options either store credentials insecurely or lack centralized management and auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the `--ask-pass` and `--ask-become-pass` options when launching playbooks from the command line.

    Why it's wrong here

    Using interactive password prompts does not store credentials securely and does not provide auditing. It also cannot be automated for scheduled jobs. This method is manual and error-prone, and it does not differentiate credentials based on environment in a managed way. It fails to meet the requirement for secure storage and auditing.

  • ✗

    Use Ansible Vault to encrypt the production credentials and store them in the playbook repository.

    Why it's wrong here

    While Ansible Vault can encrypt credentials, storing them in a repository requires managing vault passwords and does not provide the centralized auditing and access control that automation controller offers. It also risks exposing the vault password. The scenario specifically requires secure storage and auditing, which are features of automation controller credentials, not just vault encryption.

  • ✗

    Configure the production inventory with a separate `ansible_user` and `ansible_ssh_pass` in the inventory file.

    Why it's wrong here

    Storing credentials in plain text in an inventory file is insecure and does not provide auditing. Even if the file is encrypted with Ansible Vault, it lacks the centralized management and audit trail of automation controller credentials. This approach also makes it difficult to rotate credentials and control access. It does not meet the security and auditing requirements.

  • ✓

    Create separate credentials in automation controller and assign them to different job templates based on the environment.

    Why this is correct

    Automation controller allows you to create multiple credentials, each with its own secrets, and associate them with job templates. By creating distinct credentials for production and development, you ensure that playbooks use the appropriate set. Credentials are stored encrypted in the controller's database and their usage is audited in job runs. This directly meets the requirement for secure storage and auditing.

About these practice questions

This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Red Hat exam blueprint

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.