Courseiva
easyMultiple Choice

200-901 Practice Question: A Python script used for network automation…

A Python script used for network automation requires storing an API secret. Which approach is the most secure and recommended best practice?

⚠ Common exam trap

Cisco often tests the misconception that encryption within the script is sufficient, but the trap is that the decryption key must still be stored somewhere, creating a key management problem that environment variables solve by keeping secrets out of the code entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use environment variables

Storing secrets in environment variables decouples sensitive data from the source code, preventing accidental exposure in version control systems like Git. This approach follows the principle of least privilege and is recommended by security best practices such as the Twelve-Factor App methodology. Environment variables are managed outside the script, reducing the risk of credential leakage during code sharing or deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hardcode the secret in the Python script

    Why it's wrong here

    Hardcoding exposes the secret in plaintext to anyone with repository or file access, and it cannot be rotated without editing and redeploying code. It is tempting because it is the quickest way to get a script running locally, and it would suffice for a throwaway proof-of-concept that never leaves a personal machine.

  • ✗

    Store the secret in a plain text file in the repository

    Why it's wrong here

    Storing secrets in a repository file exposes them to anyone with read access and to permanent git history, so rotation cannot remediate the leak. Plain text files suit non-sensitive configuration such as feature flags or endpoint URLs. Secrets belong in a dedicated vault or environment-injected credential store.

  • ✗

    Encrypt the secret and store it in the script

    Why it's wrong here

    Encrypting a secret inside the script still ships the decryption key alongside the ciphertext, so anyone reading the file recovers the plaintext. It is tempting because encryption sounds protective, and it would suit a throwaway local script where no secret manager exists. The stem requires credentials kept outside source control entirely.

  • ✓

    Use environment variables

    Why this is correct

    Environment variables keep secrets outside source code and version control, so credentials are not committed or exposed in repositories. The script reads the value at runtime from the environment, satisfying the requirement for secure, recommended secret handling in automation.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.