CV0-004 Security Practice Question
A company is implementing a secrets management solution. The security team wants to ensure that secrets are protected and rotated regularly. Which THREE of the following are best practices for secrets management?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit access to secrets to detect unauthorized usage.
Best practices include using a dedicated vault, rotating secrets, avoiding hard-coded secrets, and auditing access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Audit access to secrets to detect unauthorized usage.
Why this is correct
Auditing secret access produces an immutable record of who read or modified each credential, exposing misuse, stale integrations or compromised identities. It satisfies the stem's protection goal by enabling detection of unauthorised usage before rotation alone would reveal it.
- ✗
Hard-code secrets in application source code for simplicity.
Why it's wrong here
Hard-coding secrets embeds credentials in source control and build artefacts, so they cannot be rotated without redeploying code and are exposed to anyone with repository access. It is tempting for convenience, but the correct approach stores secrets in a dedicated vault or secrets manager that supports rotation and audit.
- ✓
Use a dedicated secrets management service like AWS Secrets Manager or Azure Key Vault.
Why this is correct
A dedicated service such as AWS Secrets Manager or Azure Key Vault centralises storage with encryption at rest, fine-grained access policies and built-in rotation. It satisfies the stem by providing the managed platform on which protection and regular rotation practises depend.
- ✓
Enable automatic rotation of secrets on a regular schedule.
Why this is correct
Scheduled automatic rotation limits the useful lifetime of any leaked credential, shrinking the window an attacker can exploit it. It directly satisfies the stem's requirement that secrets be rotated regularly, removing reliance on manual, easily forgotten rotation.
- ✗
Store secrets in environment variables for easy access by applications.
Why it's wrong here
Environment variables are readable by any process in the container or host and persist in process listings, so rotation requires restarting the application. They are tempting because injection is simple, but the correct approach uses a secrets manager that issues short-lived, dynamically rotated credentials.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.