AAIA AI Operations Practice Question
You are configuring a CI/CD pipeline for ML using GitHub Actions to deploy to a Kubernetes cluster. To ensure sensitive credentials for your container registry are not exposed in logs, what is the best practice?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store credentials in GitHub Secrets
Using GitHub Secrets is the standard way to inject sensitive data into CI/CD pipelines securely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store credentials in GitHub Secrets
Why this is correct
GitHub Secrets masks values in logs and encrypts them at rest.
- ✗
Use environment variables in the workflow file
Why it's wrong here
Environment variables in plain text are visible in the repository and logs.
- ✗
Hardcode credentials in the Dockerfile
Why it's wrong here
Hardcoding is a security violation.
- ✗
Commit a .env file to the repository
Why it's wrong here
Committing .env files exposes secrets to anyone with repo access.
About these practice questions
Courseiva writes every AAIA question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official ISACA exam blueprint
This AAIA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AAIA exam.