Courseiva

200-901 Application Deployment and Security Practice Question

A developer is writing a Python script that calls a REST API. The script currently contains the API key as a string literal. The team wants to move the key out of source control and inject it at runtime in a CI/CD pipeline. Which approach best meets this requirement?

⚠ Common exam trap

The trap here is believing that encoding a secret, such as Base64, provides protection, when it is reversible and still counts as hardcoding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Read the API key from an environment variable populated by the pipeline's secret store

Injecting secrets through environment variables supplied by the pipeline's secret store keeps credentials out of the codebase and version history. The application reads the value at runtime, and the CI/CD system can mask it in logs and restrict access. This is the recommended pattern for automated deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Read the API key from an environment variable populated by the pipeline's secret store

    Why this is correct

    Environment variables populated from a CI/CD secret store keep the key out of the repository and inject it only at runtime. The application reads the value without hardcoding it, and the pipeline masks the value in logs. This is the standard pattern for separating configuration and secrets from code in automated builds.

  • ✗

    Store the API key in a configuration file committed to the repository

    Why it's wrong here

    Committing the key to the repository exposes it to anyone with read access and preserves it in version history even after removal. This directly violates the goal of moving the key out of source control. Configuration files are appropriate for non-sensitive settings, not credentials.

  • ✗

    Base64-encode the API key and place it in the script as a constant

    Why it's wrong here

    Base64 is an encoding, not encryption, and can be trivially decoded by anyone who sees the source. The key remains embedded in the code and in version control history, so the requirement to remove it from source is not met. This approach only obscures the value superficially.

  • ✗

    Have the script prompt the user for the API key on each execution

    Why it's wrong here

    Interactive prompting cannot work in an unattended CI/CD pipeline and would block automated runs. It also does not provide a secure, repeatable way to supply the credential to the application at runtime. This approach fails the automation and security goals of the scenario.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.