200-901 Infrastructure and Automation Practice Question
A developer is building a Python script that authenticates to the Cisco DNA Center REST API. The script must avoid hardcoding credentials in source control and must run unattended in a CI pipeline. The team already stores secrets in environment variables on the build agent. Which approach best meets these requirements?
⚠ Common exam trap
The trap here is assuming that a private repository or a separate config file makes stored credentials safe, when any committed secret is still exposed and violates the no-hardcoding requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read the credentials with os.environ at runtime and pass them to the DNA Center authentication endpoint to obtain a token.
Credentials supplied through environment variables let the same script run locally and in CI without modification, and they never land in the repository. The script authenticates against the DNA Center token service and reuses the resulting token for the API calls it needs, satisfying both the secrecy and unattended-execution constraints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the credentials in a plaintext YAML file in the repository and load it with a relative path.
Why it's wrong here
A plaintext YAML file in version control is functionally the same exposure as hardcoding; the secret is still committed and readable. Relative path loading does not add protection, and the file will be cloned by every pipeline job. It contradicts the requirement to avoid storing credentials in source control.
- ✗
Embed the username and password as string literals in the script and commit it to a private Git repository.
Why it's wrong here
Hardcoding credentials into a tracked script exposes them to anyone with repository read access and to every historical commit, even after rotation. A private repo does not satisfy the requirement to keep secrets out of source control, and CI logs or forks can leak the values. This approach fails the stated constraint outright.
- ✗
Prompt the operator for credentials with input() each time the pipeline executes.
Why it's wrong here
An interactive prompt blocks unattended execution, which is precisely what a CI pipeline cannot provide. The requirement states the script must run without human interaction, so asking for input defeats the purpose. It also gives no mechanism for the build agent to supply credentials automatically.
- ✓
Read the credentials with os.environ at runtime and pass them to the DNA Center authentication endpoint to obtain a token.
Why this is correct
Pulling credentials from environment variables keeps them out of the codebase while allowing the script to run unattended, because the CI agent injects the values at execution time. The script then authenticates to the DNA Center token endpoint and uses the returned token for subsequent calls, which matches both the security and automation requirements.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.