hardMultiple Choice
200-901 Practice Question: A team is designing a CI/CD pipeline that uses…
A team is designing a CI/CD pipeline that uses the Cisco ACI REST API to deploy tenant policies. Which best practice should be followed for secure credential management?
⚠ Common exam trap
200-901 often tests secure credential handling — candidates may pick a convenient but insecure option like plain-text config or hardcoding, missing that secrets management with runtime injection is the expected best practice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a secrets management service and reference it in the pipeline
Using a secrets management service (such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault) and referencing it from the pipeline is the recommended best practice for securing credentials used by the Cisco ACI REST API. This centralizes secret storage, enables rotation, enforces access controls, and keeps credentials out of code and configuration files. It aligns with zero-trust and least-privilege principles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store credentials in plain text in the pipeline configuration
Why it's wrong here
Plain-text credentials in pipeline configuration are readable by anyone with repository or build-log access, exposing the ACI API. It tempts because it is the quickest way to get a pipeline authenticating, and would be acceptable only for throwaway local testing with no real credentials.
- ✓
Use a secrets management service and reference it in the pipeline
Why this is correct
Hard-coded credentials in pipeline scripts or repositories leak through logs and version control. A dedicated secrets management service stores the ACI credentials externally and injects them at runtime, so the pipeline references the secret rather than embedding it, satisfying the secure credential management requirement.
- ✗
Hardcode credentials in the source code
Why it's wrong here
Embedding credentials in source code exposes them to anyone with repository access and leaks them permanently into version history, defeating rotation. It is tempting because it makes pipeline scripts self-contained and quick to run. Vault-backed secret injection or environment-scoped credentials would be correct where the pipeline must authenticate unattended.
- ✗
Use a shared user account with no MFA
Why it's wrong here
A shared account without MFA removes per-user attribution and lets one leaked credential compromise every pipeline run, and no audit trail identifies the actor. It is tempting because it avoids distributing individual credentials. Federated workload identity or short-lived tokens would be correct where pipelines need non-interactive authentication.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.