Courseiva
mediumMultiple Choice

Secure Secret Management in Docker Containers

During a security audit, an engineer discovers that a CI/CD pipeline is storing API keys in plain text in environment variables. Which best practice should be implemented to mitigate this risk?

⚠ Common exam trap

Cisco often tests the misconception that encrypting secrets or storing them in a restricted repository is sufficient, when the correct answer is always to use a dedicated secrets management service that retrieves secrets at runtime, avoiding any persistent storage of sensitive data in the pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a dedicated secrets management service like HashiCorp Vault or AWS Secrets Manager and retrieve secrets at runtime.

Dedicated secrets management services like HashiCorp Vault or AWS Secrets Manager provide secure storage, access control, and audit logging for sensitive data. They allow the CI/CD pipeline to retrieve API keys at runtime via authenticated API calls, ensuring secrets are never stored in plain text in environment variables or configuration files. This approach aligns with the principle of least privilege and eliminates the risk of exposure through source code or build logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store secrets in a .env file and add it to the repository with restricted access.

    Why it's wrong here

    Committing a .env file still places plaintext secrets in version control, exposing them to anyone with repository read access and to its history. It is tempting because .env files suit local development convenience, but a secrets manager or CI/CD secret store injects values at runtime without persisting them.

  • ✗

    Encrypt the environment variables using a tool like openssl and store the key elsewhere.

    Why it's wrong here

    Encrypting variables in place still ships the decryption key through the pipeline, so the secret remains recoverable by anyone with pipeline access. It is tempting because encryption feels like a direct fix, and it would be correct for protecting data at rest outside CI/CD, but a managed secrets store with scoped, short-lived credentials addresses the exposure.

  • ✓

    Use a dedicated secrets management service like HashiCorp Vault or AWS Secrets Manager and retrieve secrets at runtime.

    Why this is correct

    A dedicated secrets manager stores API keys encrypted at rest and issues them only at runtime, eliminating plain-text environment variables from the pipeline. HashiCorp Vault and AWS Secrets Manager also provide audit logging, automatic rotation and fine-grained access policies, directly satisfying the audit's requirement to remove hard-coded credentials from CI/CD configuration.

  • ✗

    Remove the API keys from the pipeline and require manual entry each time a build runs.

    Why it's wrong here

    Manual entry removes automation and introduces human error, and the keys still exist in plaintext wherever they are typed. It is tempting as an apparent way to keep secrets out of the pipeline, but a dedicated secrets manager is the correct choice, injecting credentials at runtime with audit and rotation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.