mediumMultiple Choice
Secure Secret Management in Docker Containers
During a security audit, an engineer discovers that a CI/CD pipeline is storing API keys in plain text in environment variables. Which best practice should be implemented to mitigate this risk?
⚠ Common exam trap
Cisco often tests the misconception that encrypting secrets or storing them in a restricted repository is sufficient, when the correct answer is always to use a dedicated secrets management service that retrieves secrets at runtime, avoiding any persistent storage of sensitive data in the pipeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a dedicated secrets management service like HashiCorp Vault or AWS Secrets Manager and retrieve secrets at runtime.
Dedicated secrets management services like HashiCorp Vault or AWS Secrets Manager provide secure storage, access control, and audit logging for sensitive data. They allow the CI/CD pipeline to retrieve API keys at runtime via authenticated API calls, ensuring secrets are never stored in plain text in environment variables or configuration files. This approach aligns with the principle of least privilege and eliminates the risk of exposure through source code or build logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store secrets in a .env file and add it to the repository with restricted access.
Why it's wrong here
Committing a .env file still places plaintext secrets in version control, exposing them to anyone with repository read access and to its history. It is tempting because .env files suit local development convenience, but a secrets manager or CI/CD secret store injects values at runtime without persisting them.
- ✗
Encrypt the environment variables using a tool like openssl and store the key elsewhere.
Why it's wrong here
Encrypting variables in place still ships the decryption key through the pipeline, so the secret remains recoverable by anyone with pipeline access. It is tempting because encryption feels like a direct fix, and it would be correct for protecting data at rest outside CI/CD, but a managed secrets store with scoped, short-lived credentials addresses the exposure.
- ✓
Use a dedicated secrets management service like HashiCorp Vault or AWS Secrets Manager and retrieve secrets at runtime.
Why this is correct
A dedicated secrets manager stores API keys encrypted at rest and issues them only at runtime, eliminating plain-text environment variables from the pipeline. HashiCorp Vault and AWS Secrets Manager also provide audit logging, automatic rotation and fine-grained access policies, directly satisfying the audit's requirement to remove hard-coded credentials from CI/CD configuration.
- ✗
Remove the API keys from the pipeline and require manual entry each time a build runs.
Why it's wrong here
Manual entry removes automation and introduces human error, and the keys still exist in plaintext wherever they are typed. It is tempting as an apparent way to keep secrets out of the pipeline, but a dedicated secrets manager is the correct choice, injecting credentials at runtime with audit and rotation.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.