Courseiva

200-901 Software Development and Design Practice Question

A developer is preparing a Python script that will be committed to a shared Git repository used by a team of network automation engineers. The team wants to ensure that sensitive credentials and environment-specific files are never committed. Which TWO actions should the developer take? (Choose two.)

⚠ Common exam trap

The trap here is believing that deleting a committed credentials file removes it from history, when Git retains all past commits unless history is rewritten.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use environment variables to supply credentials at runtime instead of hardcoding them.

The team needs to prevent sensitive files from entering Git. A .gitignore file excludes specified files and patterns from being tracked, and using environment variables for credentials means secrets never need to be stored in the repository. Committing credentials even temporarily, storing them in documentation, or relying on manual unstaging all risk exposing secrets and do not provide a reliable safeguard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use environment variables to supply credentials at runtime instead of hardcoding them.

    Why this is correct

    Reading credentials from environment variables keeps secrets out of the codebase entirely. The script can access them at runtime without any sensitive values being stored in Git. This complements .gitignore by removing the need to commit credentials at all, satisfying the team's requirement to protect sensitive information.

  • ✓

    Add a .gitignore file listing files such as .env and credentials.json.

    Why this is correct

    A .gitignore file tells Git which untracked files and patterns to exclude from commits. By listing .env and credentials.json, the developer prevents accidental staging of sensitive files. This is a standard practice for keeping secrets out of version control, directly addressing the team's requirement.

  • ✗

    Store the credentials in a README.md file so the team can easily find them.

    Why it's wrong here

    Placing credentials in a README.md file commits them to the repository in plain text, making them visible to anyone with access, including in history. This directly violates the requirement to keep sensitive data out of the shared repository and is a serious security anti-pattern.

  • ✗

    Run git add . to stage all files, then manually unstage credentials before committing.

    Why it's wrong here

    Running git add . stages everything, and manual unstaging is error-prone; a forgotten file can slip into a commit. This approach relies on human vigilance rather than a systematic safeguard, so it does not reliably prevent credentials from being committed, failing the team's requirement for a dependable solution.

  • ✗

    Commit the credentials file once, then delete it in a later commit.

    Why it's wrong here

    Committing a credentials file even once stores it permanently in the repository history. Deleting it later does not remove it from past commits, so anyone with repository access can recover the secret. This approach fails the requirement because it still exposes sensitive data and violates the team's security goal.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.