200-901 Application Deployment and Security Practice Question
A developer is writing a Python application that interacts with a REST API. The API requires authentication using an API key. The developer wants to avoid hardcoding the API key in the source code. Which approach should be used to securely provide the API key to the application?
⚠ Common exam trap
The trap here is believing that a private Git repository or a private cloud storage bucket is secure enough for secrets, when they still pose significant exposure risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use environment variables to pass the API key at runtime.
Using environment variables keeps the API key out of source code and version control, allowing it to be injected securely at runtime. This practice supports separation of configuration from code and is recommended for secrets management. Hardcoding, committing to Git, or using public storage all risk exposing the key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Embed the API key directly in the source code as a constant.
Why it's wrong here
Hardcoding the API key in source code makes it visible to anyone who can view the code, including in version control history. This is a critical security anti-pattern. If the code is shared or the repository is breached, the key is immediately compromised. It also makes rotation difficult because it requires code changes and redeployment.
- ✗
Store the API key in a configuration file that is committed to the Git repository.
Why it's wrong here
Committing a configuration file with an API key to a Git repository exposes the secret to anyone with access to the repository, including history. This is a common security mistake. Even if the repository is private, it violates the principle of least privilege and can lead to credential leakage if the repository is compromised or made public.
- ✓
Use environment variables to pass the API key at runtime.
Why this is correct
Environment variables allow secrets to be injected at runtime without being stored in code or committed files. This separates configuration from code and is a widely accepted practice. The application reads the key from the environment, and the value can be set by the deployment environment, CI/CD system, or orchestration platform, reducing the risk of accidental exposure.
- ✗
Store the API key in a public cloud storage bucket and retrieve it at runtime.
Why it's wrong here
Storing an API key in a public cloud storage bucket exposes it to anyone on the internet, which is extremely insecure. Even if the bucket is private, retrieving it at runtime adds complexity and potential failure points. Secure secret management services, such as AWS Secrets Manager or HashiCorp Vault, are designed for this purpose and provide encryption and access controls.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.