Which TWO practices help prevent hardcoded credentials in application code? (Choose TWO.)
HashiCorp Vault injects credentials dynamically at runtime, so no secret ever resides in source code or version control. This directly satisfies the stem's requirement to prevent hardcoded credentials, since applications authenticate to Vault and receive short-lived, rotated secrets instead of embedding static passwords or API keys.
Why this answer
Option A is correct because a secrets management tool such as HashiCorp Vault stores credentials outside the codebase and injects them at runtime via API calls or dynamic secrets, so no credential value ever appears in source files or version control. Option C is correct because keeping secrets in environment variables loaded from a .env file that is excluded from version control (e.g., listed in .gitignore) removes the credential from the code itself while still making it available to the running process. Option B is wrong because emailing secrets and pasting them into code during deployment is exactly the hardcoding anti-pattern and exposes credentials in mail systems and source history.
Option D is wrong because committing even a placeholder .env file to the repository normalizes storing secrets in version control and risks real values being committed later. Option E is wrong because embedding secrets directly in source code with comments is the definition of hardcoded credentials and leaks them to anyone with repository access.