200-901 Application Deployment and Security Practice Question
A security review of a CI/CD pipeline finds that build jobs run with credentials that have far more privilege than needed, and that the same long-lived token is reused across repositories. Which TWO changes reduce the blast radius if a pipeline credential is compromised? (Choose two.)
⚠ Common exam trap
The trap here is equating safer secret storage with reduced privilege, when storage location does not change what a stolen credential can access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the pipeline identity the minimum permissions required for its deployment tasks.
Blast radius is governed by how much a credential can do and how long it remains valid. Issuing short-lived, per-job credentials and constraining the pipeline identity to least privilege both directly reduce the impact of theft. Encryption at rest, verbose logging, and runner placement improve hygiene or visibility but leave the credential's power and lifetime intact, so they do not shrink the damage an attacker can inflict.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run all pipeline jobs on self-hosted runners located inside the corporate network.
Why it's wrong here
Runner placement changes where jobs execute and can improve network control, but it does not alter the permissions or lifetime of the credential itself. A stolen token still works from anywhere it is accepted, so this measure does not limit the damage a compromised credential can cause, leaving the blast radius essentially unchanged.
- ✗
Store the shared token in the CI platform's encrypted secret store instead of in the repository.
Why it's wrong here
Moving the token into an encrypted secret store is good hygiene and prevents casual exposure, but the token remains long-lived, broadly scoped, and valid across repositories. If it is exfiltrated from the pipeline at runtime, the attacker still gains the same wide access, so this does not reduce the blast radius.
- ✓
Grant the pipeline identity the minimum permissions required for its deployment tasks.
Why this is correct
Least privilege limits what an attacker can do with a stolen credential, even inside its validity window. If the identity can only push to one registry namespace or update one service, compromise does not yield broad access to other repositories or cloud resources, which is the core of reducing blast radius in this scenario.
- ✗
Enable verbose debug logging for all pipeline jobs so credential usage can be audited after an incident.
Why it's wrong here
Verbose logs improve after-the-fact visibility but do not constrain what a stolen credential can do, and they risk printing secrets into log storage, widening exposure. Auditing alone does not reduce blast radius; the requirement is to limit the credential's power and lifetime, not merely to observe its use more closely.
- ✓
Replace the shared long-lived token with short-lived credentials issued per job by the CI platform's identity integration.
Why this is correct
Per-job, short-lived credentials expire quickly and are scoped to a single run, so a leaked value has a narrow window and limited reuse. This directly shrinks the blast radius compared with a shared token that works across repositories indefinitely, and it removes the need to rotate a single secret everywhere when one repository is breached.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.