200-901 Application Deployment and Security Practice Question
A developer is writing a Python script that retrieves a device list from a Cisco DNA Center controller. The script must read the controller address and an API token from the environment rather than embedding them in source code. Which practice best supports secure, repeatable execution across developer machines and CI runners?
⚠ Common exam trap
The trap here is thinking that a .env file is safe by itself, when its safety depends entirely on it being excluded from version control and populated per environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read the values with os.environ or a library such as python-dotenv that loads a local, git-ignored .env file
Environment-driven configuration separates code from secrets and from environment-specific values. Developers can keep a local file that is excluded from version control, while CI systems inject the same variables from their own protected stores. The script itself remains identical everywhere, and credentials never appear in commits, images, or logs unless explicitly printed. This is the standard twelve-factor approach to configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the values in a public gist and fetch them at runtime over HTTPS
Why it's wrong here
A public gist is readable by anyone, so the credentials are effectively disclosed. Fetching over HTTPS protects them in transit but not from anyone who can read the gist. This adds a network dependency and a failure mode at startup while providing no confidentiality, making it unsuitable for secrets.
- ✗
Hardcode the values in a constants module that is imported by the main script
Why it's wrong here
Hardcoding secrets in a module places them directly in source control and in any distributed package or container image. Rotating a credential then requires a code change and redeployment. This is exactly the anti-pattern the scenario asks to avoid, and it makes audit and revocation far more difficult.
- ✓
Read the values with os.environ or a library such as python-dotenv that loads a local, git-ignored .env file
Why this is correct
Reading from environment variables keeps secrets out of the codebase and lets each environment supply its own values. A locally stored, git-ignored .env file provides convenience during development while CI runners inject values through their secret stores. This pattern adapts to both contexts without code changes and avoids leaking credentials into version history.
- ✗
Commit a .env file containing the values to the repository so every clone has them
Why it's wrong here
Committing secrets to version control exposes them to anyone with repository access and to history even after deletion. It also means the same credentials are used across all environments, removing isolation. The goal is to keep secrets out of source control while still making them available at runtime, so this approach defeats the purpose.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.