200-901 Software Development and Design Practice Question
A developer is preparing a Python script that authenticates to a Cisco DNA Center controller, retrieves a list of network devices, and writes the inventory into a reusable module consumed by other teams. The team lead requires that the credentials never be stored in the source code. Which TWO practices satisfy that requirement? (Choose two.)
⚠ Common exam trap
The trap here is treating encoding or renaming as protection, when only keeping the secret outside the committed source actually removes it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Load the credentials from a separate configuration file that is listed in .gitignore and provisioned on each host.
Secrets must be injected from outside the repository so that committed code never contains them. Environment variables and an ignored, per-host configuration file both achieve this, letting each consumer supply its own values while the module itself holds only the logic that reads them. Encoding or renaming secrets inside the source leaves the values in version history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Load the credentials from a separate configuration file that is listed in .gitignore and provisioned on each host.
Why this is correct
A config file excluded by .gitignore is never committed, so the secret does not enter the repository history. Each environment supplies its own file, and the parsing code can be committed safely because it contains no secret values, satisfying the requirement while remaining convenient for other teams.
- ✗
Encode the credentials with base64 inside the module so they are unreadable to anyone browsing the source.
Why it's wrong here
Base64 is a reversible encoding, not encryption, so anyone with repository access can trivially decode the string back to plaintext. The secret would still be committed and would persist in Git history, which directly violates the requirement that credentials never live in the source code.
- ✗
Commit the credentials in an encrypted form and keep the decryption key in the same repository branch for convenience.
Why it's wrong here
Storing the decryption key beside the ciphertext gives no protection at all, because anyone who can read the repository can also read the key. The secret effectively remains in the source tree and in history, so this approach fails the stated requirement.
- ✓
Read the credentials at runtime from environment variables that are set outside the repository on the execution host.
Why this is correct
Environment variables keep secrets out of version control entirely, since the values live in the shell or orchestration platform rather than in committed files. The module can read them with os.environ or os.getenv at runtime, so every consumer supplies its own values and the repository stays free of credentials.
- ✗
Hard-code the credentials as module-level constants but rename the variables so they are not obviously credentials.
Why it's wrong here
Obfuscating variable names does not remove the secret from the source; the literal values are still committed and readable in plaintext. Any clone of the repository exposes them, and rotating them later requires a code change, so this practice does not meet the requirement.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.