200-901 Application Deployment and Security Practice Question
A developer is building a CI/CD pipeline that must securely manage secrets such as API keys and database passwords. Which two practices should be implemented to protect these secrets throughout the pipeline? (Choose two.)
⚠ Common exam trap
The trap here is believing that encrypting secrets before committing them to a repository is sufficient, when in fact any storage in version control remains risky and violates best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store secrets in a dedicated secrets manager and inject them at runtime.
To protect secrets in a CI/CD pipeline, they should be stored in a dedicated secrets manager and injected at runtime, avoiding persistent storage in code or configuration. Additionally, using environment variables with masking ensures secrets are not exposed in logs. These practices minimize the attack surface and align with the principle of least privilege. Encrypting and committing secrets or hardcoding them are insecure, and disabling all logging is impractical.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store secrets in a dedicated secrets manager and inject them at runtime.
Why this is correct
Using a dedicated secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager) centralizes secret storage with encryption, access controls, and audit logging. Injecting secrets at runtime avoids embedding them in code or configuration files, reducing exposure. This is a best practice for secure secret management in CI/CD pipelines.
- ✗
Encrypt secrets and commit them to the repository for versioning.
Why it's wrong here
Committing encrypted secrets to the repository still exposes them to anyone with repository access, and decryption keys may also be compromised. It also creates a risk of accidental decryption or key leakage. Secrets should never be stored in version control, even if encrypted, because it violates the principle of least exposure and complicates rotation.
- ✗
Disable logging for all pipeline stages to prevent secret leakage.
Why it's wrong here
Disabling logging entirely hinders troubleshooting and auditability, which are critical for CI/CD pipelines. It does not specifically protect secrets and may violate compliance requirements. Instead, secrets should be masked in logs while maintaining necessary logging for other information. This approach is overly broad and counterproductive.
- ✗
Hardcode secrets in the pipeline configuration file for simplicity.
Why it's wrong here
Hardcoding secrets in pipeline configuration files is a severe security risk because the configuration is often stored in version control and accessible to many team members. It also makes rotation difficult and can lead to accidental exposure. This practice should never be used in any environment, especially production.
- ✓
Use environment variables to pass secrets to build steps without logging them.
Why this is correct
Environment variables can be used to inject secrets into build steps, and many CI systems mask them in logs. However, they must be handled carefully to avoid exposure in process listings or debug output. When combined with a secrets manager and proper masking, this is a common and effective practice for CI/CD pipelines.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.