EX294 Manage automation security and operations Practice Question
You are using Ansible Automation Platform to manage a large number of servers. You need to ensure that playbooks that run against production servers use a separate set of credentials than those used for development servers. The production credentials must be stored securely and audited. Which Ansible Automation Platform feature should you use to achieve this?
⚠ Common exam trap
The trap here is thinking that Ansible Vault alone can provide the same level of secure storage and auditing as automation controller credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create separate credentials in automation controller and assign them to different job templates based on the environment.
Automation controller credentials are designed for secure storage and auditing. By creating separate credentials for production and development and assigning them to the appropriate job templates, you ensure that each environment uses its own set of secrets. The controller encrypts credentials and logs their usage, providing the required audit trail. The other options either store credentials insecurely or lack centralized management and auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the `--ask-pass` and `--ask-become-pass` options when launching playbooks from the command line.
Why it's wrong here
Using interactive password prompts does not store credentials securely and does not provide auditing. It also cannot be automated for scheduled jobs. This method is manual and error-prone, and it does not differentiate credentials based on environment in a managed way. It fails to meet the requirement for secure storage and auditing.
- ✗
Use Ansible Vault to encrypt the production credentials and store them in the playbook repository.
Why it's wrong here
While Ansible Vault can encrypt credentials, storing them in a repository requires managing vault passwords and does not provide the centralized auditing and access control that automation controller offers. It also risks exposing the vault password. The scenario specifically requires secure storage and auditing, which are features of automation controller credentials, not just vault encryption.
- ✗
Configure the production inventory with a separate `ansible_user` and `ansible_ssh_pass` in the inventory file.
Why it's wrong here
Storing credentials in plain text in an inventory file is insecure and does not provide auditing. Even if the file is encrypted with Ansible Vault, it lacks the centralized management and audit trail of automation controller credentials. This approach also makes it difficult to rotate credentials and control access. It does not meet the security and auditing requirements.
- ✓
Create separate credentials in automation controller and assign them to different job templates based on the environment.
Why this is correct
Automation controller allows you to create multiple credentials, each with its own secrets, and associate them with job templates. By creating distinct credentials for production and development, you ensure that playbooks use the appropriate set. Credentials are stored encrypted in the controller's database and their usage is audited in job runs. This directly meets the requirement for secure storage and auditing.
Go deeper
Related to this question
About these practice questions
This EX294 question is part of Courseiva's 392-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Red Hat exam blueprint
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.