200-901 Application Deployment and Security Practice Question
A security team is reviewing a Python application that integrates with Cisco DNA Center. The application authenticates with a username and password and stores them in a configuration file that is deployed to multiple servers. The team wants to reduce the risk of credential exposure while keeping the application functional. Which TWO actions should be taken? (Choose two.)
⚠ Common exam trap
The trap here is treating file permissions as sufficient on their own, or assuming that hiding credentials in source code is safer than a protected configuration file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the configuration file with restrictive file permissions and exclude it from version control.
Reducing credential exposure involves both limiting how long secrets live and limiting who can read them. Short-lived tokens from the Cisco DNA Center authentication API shrink the useful lifetime of a stolen secret, while restrictive file permissions and exclusion from version control protect the configuration file itself. Together these controls address the risk without breaking the integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable TLS verification for Cisco DNA Center API calls to simplify certificate management.
Why it's wrong here
Disabling TLS verification exposes credentials and tokens to interception, which directly undermines the security objective. It may also cause the DNA Center API to reject requests or behave unpredictably. Certificate management can be handled properly without weakening transport security, so this action should not be taken.
- ✗
Embed the credentials in the Python source code so the configuration file can be deleted.
Why it's wrong here
Embedding credentials in source code moves the secret into a location that is typically committed to version control and shared broadly, which increases exposure rather than reducing it. It also makes rotation harder because a code change and redeployment are required. This contradicts the goal of reducing credential exposure across multiple servers.
- ✗
Log the credentials at startup so operators can confirm the configuration is correct.
Why it's wrong here
Logging credentials writes secrets into log files that are often aggregated and retained, creating a new exposure path. Operators do not need to see plaintext credentials to verify configuration; they can confirm connectivity through successful API responses. This action increases risk and should be avoided.
- ✓
Store the configuration file with restrictive file permissions and exclude it from version control.
Why this is correct
Restricting file permissions limits which local users can read the credentials, and excluding the file from version control prevents accidental commits that would expose secrets to anyone with repository access. Together these controls reduce the attack surface for a deployed configuration file. They complement, rather than replace, token-based authentication.
- ✓
Replace static credentials with short-lived tokens obtained from the Cisco DNA Center authentication API.
Why this is correct
Cisco DNA Center issues time-limited tokens through its authentication endpoint, so the application can avoid storing long-lived usernames and passwords. Tokens expire and can be reissued, which limits the window of exposure if a configuration file is compromised. This directly reduces credential risk while preserving API access.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.