mediumMultiple Choice
CV0-004 Practice Question: Deploying a containerized microservices…
A company is deploying a containerized microservices application on a cloud platform. The operations team needs to manage secrets, such as database credentials and API keys, securely without embedding them in container images. Which solution should they use?
⚠ Common exam trap
CV0-004 often tests the misconception that encrypting an image or using environment variables is 'secure enough' — candidates pick environment variables because they are easy, ignoring that they are readable from the container runtime and logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a cloud-native secrets management service to inject secrets at runtime
A cloud-native secrets management service (e.g., AWS Secrets Manager, GCP Secret Manager, Azure Key Vault) injects secrets at runtime via API calls or sidecar/mounted volumes, so credentials never live in the image or the orchestrator's static config. This enables rotation, fine-grained IAM access, and audit trails without rebuilding images when a credential changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include secrets in the container image at build time and encrypt the image
Why it's wrong here
Baking secrets into the image at build time embeds them in every layer and registry copy, so rotation requires a rebuild and anyone pulling the image can extract them. It is tempting because encryption appears to protect the image, and it would be correct for immutable, non-sensitive configuration such as feature flags.
- ✓
Use a cloud-native secrets management service to inject secrets at runtime
Why this is correct
A cloud-native secrets management service stores credentials outside the image and injects them into containers at runtime, satisfying the requirement to avoid embedding secrets in images. This keeps secrets centralised, auditable and rotatable without rebuilding or redeploying container artefacts.
- ✗
Encrypt secrets and store them in a cloud storage bucket
Why it's wrong here
A storage bucket holds encrypted blobs but provides no runtime injection or access control, so containers cannot retrieve credentials without custom code and static keys. It is tempting because encryption at rest satisfies a compliance checkbox, and it would be correct for storing non-secret artefacts or backups rather than live credentials.
- ✗
Store secrets as environment variables in the container orchestration platform
Why it's wrong here
Environment variables are visible in container inspection, process listings and crash dumps, and cannot be rotated without restarting the workload. It is tempting because it is the simplest injection method, and it would be correct for non-sensitive settings like log levels or service endpoints.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.