200-901 Application Deployment and Security Practice Question
A developer is reviewing a CI/CD pipeline that builds and deploys a containerized application. The team wants to protect sensitive values such as API keys and registry passwords used during the pipeline. Which TWO practices should be used? (Choose two.)
⚠ Common exam trap
The trap here is treating repository privacy or log verification as equivalent to secret protection, when both still expose the values.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store secrets in the CI/CD platform's encrypted secret store and reference them as masked variables in pipeline steps.
Protecting pipeline secrets requires both keeping them out of source and pipeline definitions and retrieving them from controlled stores at the moment they are needed. Encrypted secret stores with masking prevent accidental disclosure in logs, while runtime retrieval from a secrets manager limits exposure and supports rotation. Practices that persist secrets in repositories or logs defeat these protections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Commit the secrets to a private repository branch so only team members can read them.
Why it's wrong here
Private repositories still expose secrets to every user with access and retain them in Git history even after deletion. Any fork, clone, or compromised account leaks the values. This practice does not provide the protection the pipeline requires and contradicts standard secret management guidance.
- ✓
Store secrets in the CI/CD platform's encrypted secret store and reference them as masked variables in pipeline steps.
Why this is correct
Encrypted secret stores keep values out of the repository and mask them in logs, so pipeline output does not reveal them. Referencing them as variables allows jobs to consume secrets without hardcoding. This directly protects API keys and registry passwords during builds and deployments.
- ✗
Reuse the same secret value across all environments and rotate it only when a team member leaves.
Why it's wrong here
Sharing one secret across development, staging, and production increases blast radius if it leaks and complicates rotation. Infrequent rotation tied only to departures leaves credentials valid for long periods. This practice does not adequately protect the API keys and registry passwords used in the pipeline.
- ✓
Inject secrets at runtime from a dedicated secrets manager rather than baking them into the image or pipeline configuration.
Why this is correct
Retrieving secrets at runtime from a secrets manager means the image and pipeline definitions never contain the values. Rotation and access control are centralized, reducing exposure. This approach protects API keys and registry passwords even if the image or pipeline configuration is inspected.
- ✗
Print the decrypted secrets to the build log so the team can verify they are correct.
Why it's wrong here
Writing secrets to build logs exposes them to anyone who can read logs, including users with limited repository access and log aggregation systems. Even if the log is later cleaned, copies may persist. This practice directly undermines the goal of protecting sensitive values.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.