Courseiva

200-901 Application Deployment and Security Practice Question

A developer is building a CI/CD pipeline that must securely manage secrets such as API keys and database passwords. Which two practices should be implemented to protect these secrets throughout the pipeline? (Choose two.)

⚠ Common exam trap

The trap here is believing that encrypting secrets before committing them to a repository is sufficient, when in fact any storage in version control remains risky and violates best practices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store secrets in a dedicated secrets manager and inject them at runtime.

To protect secrets in a CI/CD pipeline, they should be stored in a dedicated secrets manager and injected at runtime, avoiding persistent storage in code or configuration. Additionally, using environment variables with masking ensures secrets are not exposed in logs. These practices minimize the attack surface and align with the principle of least privilege. Encrypting and committing secrets or hardcoding them are insecure, and disabling all logging is impractical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store secrets in a dedicated secrets manager and inject them at runtime.

    Why this is correct

    Using a dedicated secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager) centralizes secret storage with encryption, access controls, and audit logging. Injecting secrets at runtime avoids embedding them in code or configuration files, reducing exposure. This is a best practice for secure secret management in CI/CD pipelines.

  • ✗

    Encrypt secrets and commit them to the repository for versioning.

    Why it's wrong here

    Committing encrypted secrets to the repository still exposes them to anyone with repository access, and decryption keys may also be compromised. It also creates a risk of accidental decryption or key leakage. Secrets should never be stored in version control, even if encrypted, because it violates the principle of least exposure and complicates rotation.

  • ✗

    Disable logging for all pipeline stages to prevent secret leakage.

    Why it's wrong here

    Disabling logging entirely hinders troubleshooting and auditability, which are critical for CI/CD pipelines. It does not specifically protect secrets and may violate compliance requirements. Instead, secrets should be masked in logs while maintaining necessary logging for other information. This approach is overly broad and counterproductive.

  • ✗

    Hardcode secrets in the pipeline configuration file for simplicity.

    Why it's wrong here

    Hardcoding secrets in pipeline configuration files is a severe security risk because the configuration is often stored in version control and accessible to many team members. It also makes rotation difficult and can lead to accidental exposure. This practice should never be used in any environment, especially production.

  • ✓

    Use environment variables to pass secrets to build steps without logging them.

    Why this is correct

    Environment variables can be used to inject secrets into build steps, and many CI systems mask them in logs. However, they must be handled carefully to avoid exposure in process listings or debug output. When combined with a secrets manager and proper masking, this is a common and effective practice for CI/CD pipelines.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.