200-901 Software Development and Design Practice Question
A developer is preparing a Python script that will be shared with a team and run in multiple environments. The script relies on several third-party libraries. Which TWO practices should be followed to ensure reproducible dependency management? (Choose two.)
⚠ Common exam trap
The trap here is thinking that installing packages globally or omitting version pins is acceptable for shared projects, when both practices lead to inconsistent environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pin exact versions of dependencies in a requirements.txt file using the == operator.
Reproducible dependency management requires isolating project packages and recording exact versions. A virtual environment prevents interference from system-wide packages, while pinning versions in requirements.txt ensures that every installation uses the same releases. Together they allow any team member or CI system to recreate the exact environment. Global installs, unpinned versions, and committing the virtual environment all introduce variability and are not recommended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install packages globally with pip install --user to avoid permission issues.
Why it's wrong here
Installing globally with --user places packages in the user site-packages directory, which is shared across all projects for that user. This can lead to version conflicts and makes it difficult to track which packages belong to which project. It does not provide isolation or reproducibility, and it can mask missing dependencies in requirements.txt because the packages are already available system-wide.
- ✗
Commit the entire virtual environment directory to the Git repository.
Why it's wrong here
Committing a virtual environment bloats the repository with platform-specific binaries and absolute paths that break on other machines. It is not portable and defeats the purpose of using requirements.txt for dependency specification. Best practice is to exclude the virtual environment via .gitignore and share only the requirements file, allowing each environment to recreate the environment cleanly.
- ✓
Pin exact versions of dependencies in a requirements.txt file using the == operator.
Why this is correct
Pinning exact versions with == ensures that every environment installs the same package versions, preventing unexpected behavior from newer releases. This is a cornerstone of reproducible builds. When combined with a virtual environment, it guarantees that the dependencies resolved during development match those in testing and production, which is essential for collaborative projects and consistent API interactions.
- ✗
Rely on the latest versions of dependencies by omitting version specifiers in requirements.txt.
Why it's wrong here
Omitting version specifiers means pip will install the newest available versions each time, which can introduce breaking changes or subtle behavioral differences. This directly undermines reproducibility because two installations at different times may resolve to different versions. It also makes debugging harder when an issue arises only in one environment due to a newer dependency release.
- ✓
Use a virtual environment to isolate project dependencies from the system Python installation.
Why this is correct
A virtual environment creates an isolated Python installation where project-specific packages are installed without affecting global site-packages. This prevents version conflicts between projects and ensures that the requirements.txt file accurately reflects the dependencies needed. It is a best practice for reproducibility because it eliminates interference from system-wide packages that may differ across machines.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.