Courseiva

200-901 Software Development and Design Practice Question

A developer is designing a Python script that must authenticate to a Cisco Meraki API using an API key. The key should not be hardcoded in the script. Which method is most secure for managing the API key?

⚠ Common exam trap

The trap here is thinking that obfuscation or config files are sufficient, but they can still leak secrets; environment variables are preferred for automation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use environment variables to pass the API key to the script.

Using environment variables is a secure and standard way to manage secrets like API keys. It keeps them out of code and version control, and allows different environments to use different keys. The other options either store the key insecurely, use reversible obfuscation, or are impractical for automation. Environment variables strike a balance between security and usability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Prompt the user to enter the API key each time the script runs.

    Why it's wrong here

    Prompting for the API key each time is secure in that it is not stored, but it is impractical for automation and scripts that run unattended. It also exposes the key in memory and potentially in logs. For automated scripts, environment variables or secret managers are more suitable.

  • ✗

    Hardcode the API key in the script but obfuscate it using Base64 encoding.

    Why it's wrong here

    Base64 encoding is not encryption; it is easily reversible. Hardcoding even an obfuscated key still exposes it to anyone with access to the source code. This practice is insecure and should be avoided. Secrets should never be stored in code, regardless of encoding.

  • ✓

    Use environment variables to pass the API key to the script.

    Why this is correct

    Environment variables keep sensitive data out of the source code and configuration files, reducing the risk of accidental exposure. They can be set securely in the deployment environment and are easily managed by CI/CD systems. This is a widely recommended practice for secrets management in twelve-factor apps.

  • ✗

    Store the API key in a configuration file and read it at runtime.

    Why it's wrong here

    Storing the API key in a configuration file is better than hardcoding, but if the file is committed to version control or accessible to others, it can be exposed. It lacks encryption and access controls. Environment variables or secret management services provide better security by keeping secrets out of the codebase and files.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.