Courseiva

200-901 Software Development and Design Practice Question

A developer is preparing a Python application that reads the API base URL and an API token from the environment. The developer wants to avoid hard-coding credentials and intends to deploy the same artifact to a lab and a production environment. Which approach should be used?

⚠ Common exam trap

The trap here is assuming a private repository or a default function argument makes a credential safe, when any value stored in source or in the artifact is exposed to everyone who can read the code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Read the base URL and token from environment variables at runtime, supplying different values per deployment environment.

Injecting configuration through environment variables separates code from environment-specific values and keeps secrets out of the repository. The same artifact can be promoted from lab to production because the base URL and token are supplied by the runtime platform, not compiled in. This is a standard twelve-factor configuration practice for cloud-native and containerized applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Embed the base URL and token as default arguments in the Python function signatures so they are easy to find.

    Why it's wrong here

    Default arguments live in the source code, so the token would still be committed and shipped inside the artifact. Anyone who obtains the code or the built package can read the credential, and rotating it requires a code change and redeploy. This does not remove hard-coded secrets; it merely moves them into function definitions.

  • ✗

    Prompt the user interactively for the base URL and token each time the application starts.

    Why it's wrong here

    Interactive prompting breaks unattended execution in containers, CI pipelines, and scheduled jobs where no operator is present. It also does not provide a clean way to manage different values per environment and can leak secrets into terminal logs or shell history. Automation requires non-interactive configuration, so this approach is unsuitable for deployment.

  • ✓

    Read the base URL and token from environment variables at runtime, supplying different values per deployment environment.

    Why this is correct

    Environment variables keep secrets out of source control and let the same build artifact run in lab and production by injecting different values at deploy time. Python accesses them through os.environ or os.getenv, so no code change is needed between environments. This directly satisfies the goal of avoiding hard-coded credentials while keeping a single artifact.

  • ✗

    Store the base URL and token in a configuration file that is committed to the Git repository, and read it at startup.

    Why it's wrong here

    Committing credentials to Git exposes them to anyone with repository access and creates a permanent secret in version history. Even a private repository is the wrong place for a production token, and the same artifact cannot safely move between lab and production if the values are baked into a tracked file. This fails the requirement to avoid hard-coded credentials.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.