mediumMultiple ChoiceObjective-mapped
Secure Secret Management in Docker Containers
A DevOps team is deploying a microservices application on Cisco UCS using Docker containers. They need to ensure that secrets such as database credentials are securely managed without hardcoding them in the application code or container images. Which approach should they use?
Quick Answer
The answer is to use a secure secret store like HashiCorp Vault and retrieve secrets at runtime via API. This approach is correct because it decouples sensitive data—such as database credentials—from application code and container images, following the core principle of secret management for Docker containers. By authenticating to Vault’s REST API at runtime, microservices can fetch dynamic, encrypted secrets without ever embedding them in a Dockerfile or environment variable, which eliminates the risk of exposure in image layers or version control. On the Cisco DevNet Associate 200-901 exam, this tests your understanding of secure application deployment patterns within containerized environments on UCS, often appearing as a scenario where a team must avoid hardcoded credentials. A common trap is selecting “environment variables at container start,” which still leaves secrets visible in process listings or logs. Memory tip: think “Vault decouples, runtime retrieves”—the secret never sleeps in the image.
⚠ Common exam trap
Cisco often tests the misconception that environment variables in Docker Compose or build arguments are secure enough for secrets, but the trap here is that these methods leave secrets exposed in plaintext within the image layers, logs, or runtime environment, whereas a dedicated secret store like Vault provides encryption, rotation, and access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a secure secret store like HashiCorp Vault and retrieve secrets at runtime via API.
It follows the principle of secret management by decoupling sensitive data from application code and container images. HashiCorp Vault provides a centralized, encrypted secret store with dynamic secrets, access policies, and audit logging, allowing the microservices to authenticate and retrieve credentials at runtime via its REST API, eliminating the need to hardcode secrets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Embed secrets directly in the container image using COPY instructions.
Why it's wrong here
Embedding secrets in the image makes them accessible to anyone with image access and violates principle of least privilege.
- ✗
Pass secrets as build arguments in the Docker build command.
Why it's wrong here
Build arguments are stored in image layers and can be retrieved using docker history.
- ✓
Use a secure secret store like HashiCorp Vault and retrieve secrets at runtime via API.
Why this is correct
A secret store provides dynamic, audited, and encrypted access to secrets without embedding them in code or images.
- ✗
Store secrets as environment variables in the Docker Compose file.
Why it's wrong here
Environment variables in Docker Compose can be read during container inspection and may be leaked in logs.
Go deeper
Related to this question
About these practice questions
One of 989 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-901
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a security audit, an engineer discovers that a CI/CD pipeline is storing API keys in plain text in environment variables. Which best practice should be implemented to mitigate this risk?
medium- A.Store secrets in a .env file and add it to the repository with restricted access.
- B.Encrypt the environment variables using a tool like openssl and store the key elsewhere.
- ✓ C.Use a dedicated secrets management service like HashiCorp Vault or AWS Secrets Manager and retrieve secrets at runtime.
- D.Remove the API keys from the pipeline and require manual entry each time a build runs.
Why C: Dedicated secrets management services like HashiCorp Vault or AWS Secrets Manager provide secure storage, access control, and audit logging for sensitive data. They allow the CI/CD pipeline to retrieve API keys at runtime via authenticated API calls, ensuring secrets are never stored in plain text in environment variables or configuration files. This approach aligns with the principle of least privilege and eliminates the risk of exposure through source code or build logs.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.