Courseiva

GCIH Securing Credentials and Data in Cloud Practice Question

Which feature is most effective for preventing the accidental upload of secrets to a public cloud source code repository?

⚠ Common exam trap

Candidates often choose server-side repository scanning or secret rotation services, which are reactive measures, failing to recognize that pre-commit hooks are the only proactive, preventative control that stops secrets before they are committed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using pre-commit hooks to scan code for patterns.

Pre-commit hooks are local scripts that run before a commit is finalized, scanning for patterns like API keys or passwords. They allow developers to catch mistakes immediately on their local machines before sensitive data is pushed to a remote repository. This prevents the secret from ever entering the version history, which is the most effective way to maintain the security of credentials in a distributed development workflow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementing a post-push webhook to scan the repository.

    Why it's wrong here

    Post-push webhooks detect secrets after they have already been committed and pushed to the remote repository. By this point, the secret is already in the Git history and potentially exposed. While helpful for identifying issues, it does not prevent the initial exposure, and cleaning Git history is notoriously difficult.

  • ✓

    Using pre-commit hooks to scan code for patterns.

    Why this is correct

    Pre-commit hooks catch secrets before they are committed to the local repository. This prevents sensitive data from ever reaching the remote server. It is a proactive, shift-left security control that empowers developers to fix mistakes locally, maintaining the integrity of the codebase and preventing accidental credential leakage effectively.

  • ✗

    Enabling public repository visibility scanning.

    Why it's wrong here

    Public scanning is a reactive detective control. It alerts administrators that a secret has already been leaked, but it does not prevent the leak from occurring in the first place. Relying on this approach means the organization must assume the credential is compromised and initiate costly revocation and rotation procedures.

  • ✗

    Enforcing HTTPS for all Git operations.

    Why it's wrong here

    HTTPS encryption protects the data in transit but does not prevent the inclusion of secrets within the code itself. If a developer commits a secret, HTTPS simply ensures that the transmission of that secret is encrypted. It does not mitigate the risk of storing sensitive credentials in plain text files.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.