Courseiva

200-901 Application Deployment and Security Practice Question

A development team is using Cisco Intersight to manage their on-premises and cloud infrastructure. They want to ensure that API access to Intersight is secure and follows best practices. Which TWO measures should they implement to protect their Intersight API credentials and access? (Choose two.)

⚠ Common exam trap

The trap here is thinking that simplifying key management by using one key or embedding keys in code is acceptable for convenience.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use API keys with restricted permissions and rotate them regularly.

Restricting API key permissions and rotating them regularly, combined with storing keys in a secure vault and retrieving them at runtime, significantly reduces the risk of credential compromise. These practices ensure least privilege and prevent secrets from being exposed in code or configuration files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Embed API keys directly in application source code for easy access.

    Why it's wrong here

    Hardcoding API keys in source code is a serious security risk because code repositories may be shared or leaked. It violates the principle of separating secrets from code and can lead to unauthorized access if the repository is compromised. This practice should be avoided.

  • ✓

    Use API keys with restricted permissions and rotate them regularly.

    Why this is correct

    API keys should be scoped to the minimum required permissions and rotated periodically to limit the impact of a compromised key. This follows the principle of least privilege and reduces the window of exposure, making it a core security practice for Intersight API access.

  • ✗

    Disable multi-factor authentication for API access to streamline automation.

    Why it's wrong here

    Disabling multi-factor authentication reduces security and is not a recommended practice for protecting API access. MFA adds an extra layer of protection even for API interactions, and Intersight supports secure authentication mechanisms. Streamlining automation should not come at the cost of weakening security controls.

  • ✓

    Store API keys in a secure vault or secrets manager and retrieve them at runtime.

    Why this is correct

    Storing API keys in a secure vault or secrets manager prevents hardcoding them in source code or configuration files. Retrieving them at runtime reduces the risk of accidental exposure through code repositories or logs, aligning with secure credential management best practices.

  • ✗

    Use a single API key for all applications and environments to simplify management.

    Why it's wrong here

    Using a single API key across all applications and environments increases the blast radius if the key is compromised. It also makes it difficult to audit and revoke access for specific applications. Best practice is to use separate keys with least privilege for each use case.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.