200-901 Software Development and Design Practice Question
A developer maintains a Python library that calls a REST API and currently stores the API token in a module-level constant. The team wants to follow twelve-factor app principles so the same build artifact can be deployed to lab and production without code changes. Which change should the developer make?
⚠ Common exam trap
The trap here is thinking encryption at rest in the repository solves secret management, when the decryption key must also be externalized.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read the token from an environment variable, such as os.environ['API_TOKEN'], at runtime.
Twelve-factor configuration is stored in the environment, not in code or committed files. Reading the API token from an environment variable allows the identical build artifact to run in lab and production with different credentials, keeps secrets out of source control, and requires no code edits between deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move the token into a config.ini file that is committed to the repository and read at import time.
Why it's wrong here
Committing credentials to version control exposes secrets to anyone with repository access and does not allow per-environment values without editing the file. It also ties configuration to the artifact, violating the goal of deploying one build unchanged across environments, so this change is not appropriate.
- ✗
Encrypt the token with a symmetric key and store both the ciphertext and key in the repository for decryption at runtime.
Why it's wrong here
Storing the decryption key alongside the ciphertext in the repository provides no real protection and still bakes secrets into the artifact. It also prevents environment-specific values without code or file changes, so it does not meet the twelve-factor goal of externalized, per-environment configuration.
- ✓
Read the token from an environment variable, such as os.environ['API_TOKEN'], at runtime.
Why this is correct
Twelve-factor apps store configuration in the environment, so reading the token from an environment variable lets the same artifact run in lab and production with different values. This removes secrets from source code and enables per-environment configuration without rebuilding or editing files, satisfying the stated requirement.
- ✗
Detect the deployment environment by hostname and select a hardcoded token for each environment.
Why it's wrong here
Hardcoding tokens for each environment embeds secrets in the artifact and requires code changes to add environments. Hostname detection is fragile across clouds and containers, and the build still contains production credentials, so this approach conflicts with twelve-factor configuration and the deployment goal.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.