Courseiva
hardMultiple Choice

200-901 Practice Question: A team is designing a CI/CD pipeline that uses…

A team is designing a CI/CD pipeline that uses the Cisco ACI REST API to deploy tenant policies. Which best practice should be followed for secure credential management?

⚠ Common exam trap

200-901 often tests secure credential handling — candidates may pick a convenient but insecure option like plain-text config or hardcoding, missing that secrets management with runtime injection is the expected best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a secrets management service and reference it in the pipeline

Using a secrets management service (such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault) and referencing it from the pipeline is the recommended best practice for securing credentials used by the Cisco ACI REST API. This centralizes secret storage, enables rotation, enforces access controls, and keeps credentials out of code and configuration files. It aligns with zero-trust and least-privilege principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store credentials in plain text in the pipeline configuration

    Why it's wrong here

    Plain-text credentials in pipeline configuration are readable by anyone with repository or build-log access, exposing the ACI API. It tempts because it is the quickest way to get a pipeline authenticating, and would be acceptable only for throwaway local testing with no real credentials.

  • ✓

    Use a secrets management service and reference it in the pipeline

    Why this is correct

    Hard-coded credentials in pipeline scripts or repositories leak through logs and version control. A dedicated secrets management service stores the ACI credentials externally and injects them at runtime, so the pipeline references the secret rather than embedding it, satisfying the secure credential management requirement.

  • ✗

    Hardcode credentials in the source code

    Why it's wrong here

    Embedding credentials in source code exposes them to anyone with repository access and leaks them permanently into version history, defeating rotation. It is tempting because it makes pipeline scripts self-contained and quick to run. Vault-backed secret injection or environment-scoped credentials would be correct where the pipeline must authenticate unattended.

  • ✗

    Use a shared user account with no MFA

    Why it's wrong here

    A shared account without MFA removes per-user attribution and lets one leaked credential compromise every pipeline run, and no audit trail identifies the actor. It is tempting because it avoids distributing individual credentials. Federated workload identity or short-lived tokens would be correct where pipelines need non-interactive authentication.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.