200-901 Application Deployment and Security Practice Question
Which TWO practices help prevent hardcoded credentials in application code? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a secrets management tool like HashiCorp Vault to retrieve credentials at runtime
Option A is correct because a secrets management tool such as HashiCorp Vault stores credentials outside the codebase and injects them at runtime via API calls or dynamic secrets, so no credential value ever appears in source files or version control. Option C is correct because keeping secrets in environment variables loaded from a .env file that is excluded from version control (e.g., listed in .gitignore) removes the credential from the code itself while still making it available to the running process. Option B is wrong because emailing secrets and pasting them into code during deployment is exactly the hardcoding anti-pattern and exposes credentials in mail systems and source history. Option D is wrong because committing even a placeholder .env file to the repository normalizes storing secrets in version control and risks real values being committed later. Option E is wrong because embedding secrets directly in source code with comments is the definition of hardcoded credentials and leaks them to anyone with repository access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a secrets management tool like HashiCorp Vault to retrieve credentials at runtime
Why this is correct
HashiCorp Vault injects credentials dynamically at runtime, so no secret ever resides in source code or version control. This directly satisfies the stem's requirement to prevent hardcoded credentials, since applications authenticate to Vault and receive short-lived, rotated secrets instead of embedding static passwords or API keys.
- ✗
Share secrets via email and paste them into the code during deployment
Why it's wrong here
Emailing secrets and pasting them into code during deployment hardcodes credentials and exposes them in mail systems and repositories. It is tempting as a quick handoff, but a secrets manager or CI/CD variable injection is the correct mechanism for supplying credentials at runtime.
- ✓
Store secrets in environment variables from a .env file that is not committed to version control
Why this is correct
Loading secrets from a .env file excluded via .gitignore keeps credential values out of version control history, so the repository contains only code. This satisfies the constraint that secrets must not be committed alongside application source.
- ✗
Commit a .env file with placeholder values to the repository
Why it's wrong here
Committing a .env file, even with placeholders, places a secrets file under version control where real values are later added and leaked. It is tempting because .env files are a common local pattern, but .gitignore plus a vault or pipeline-injected variables is the correct approach.
- ✗
Embed secrets directly in the source code with comments
Why it's wrong here
Embedding secrets in source code with comments is the exact hardcoding practice the question asks you to eliminate; comments do not remove the credential from version control. It is tempting as documentation, but a secrets manager or environment variables is what actually keeps credentials out of code.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.