CCAR-P Practice Question: Developer Productivity and Operational Enablement
To ensure organizational security and governance when using Anthropic's API, what is the best practice for managing API keys across a team of 50 developers?
⚠ Common exam trap
Candidates often suggest environment variables or shared files, which are insecure for large teams as they lack auditing, rotation, and granular access control for production credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a centralized secret management service to store and dynamically inject keys.
Using a centralized secret management service (like AWS Secrets Manager or HashiCorp Vault) is the industry standard for managing sensitive credentials. It allows for auditing, automatic rotation, and granular access control, ensuring that only authorized services and developers can access the keys. This approach drastically reduces the risk of accidental exposure and allows security teams to monitor usage effectively, which is essential for enterprise-scale operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store keys in a shared environment file (.env) in a private GitHub repository.
Why it's wrong here
Storing keys in a repository, even a private one, is a security risk. If the repository is ever made public or accessed by an unauthorized user, the keys are compromised. Secret management should be externalized to specialized services that offer better auditing, access control, and automatic key rotation capabilities.
- ✓
Use a centralized secret management service to store and dynamically inject keys.
Why this is correct
Centralized management provides a single source of truth for secrets, enabling audit logs, rotation policies, and identity-based access. This ensures that keys are never exposed in code or configuration files, significantly strengthening the organization's security posture and allowing for easier management as the team scales to 50+ developers.
- ✗
Create one master API key and share it among all team members via Slack.
Why it's wrong here
Sharing a single key is a massive security failure. It makes it impossible to attribute API usage to specific individuals or services, renders rotation impossible without downtime, and leaks credentials through insecure channels like Slack. This approach is prone to catastrophic compromise and violates basic security governance practices.
- ✗
Hardcode the keys in each microservice for faster startup times.
Why it's wrong here
Hardcoding keys exposes them to any developer or build tool with access to the source code. It is extremely difficult to rotate hardcoded keys, requiring a full code deployment every time. This practice is inherently insecure and creates a significant operational burden that slows down security updates and compliance efforts.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.