Courseiva

CCSP Cloud Application Security Practice Question

A cloud-native application team is adopting a secrets management service to eliminate hardcoded credentials in source code and configuration files. Which two practices best align with secure secrets management in the cloud? (Choose two.)

⚠ Common exam trap

The trap here is believing that storing secrets in environment variables or encrypted in source control is equivalent to using a secrets manager with workload identity and rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic rotation of secrets on a defined schedule and update dependent applications through the secrets manager.

Secure secrets management favours dynamic, identity-based retrieval and routine rotation over static storage. Workload identity removes static credentials, and automatic rotation limits exposure windows; environment variables, encrypted secrets in repositories, and embedded secrets all retain long-lived or broadly accessible copies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Commit encrypted secrets to the source repository so they are version-controlled alongside application code.

    Why it's wrong here

    Committing encrypted secrets to source control still exposes ciphertext and the decryption material to anyone with repository access or build permissions. It also complicates rotation and audit, and is not a recommended cloud secrets management pattern.

  • ✗

    Store secrets in environment variables injected at container start to keep them out of the image.

    Why it's wrong here

    Environment variables may avoid hardcoding in images, but they are visible to processes in the container, can be captured in crash dumps, and are not rotated automatically. They also tend to persist in deployment manifests, so they are not a secure secrets management practice.

  • ✓

    Enable automatic rotation of secrets on a defined schedule and update dependent applications through the secrets manager.

    Why this is correct

    Automatic rotation limits the useful lifetime of a compromised secret and reduces the window of exposure. When rotation is coupled with dynamic retrieval from the secrets manager, applications pick up new values without redeployment, maintaining availability while improving security.

  • ✓

    Grant the application a workload identity so it retrieves secrets dynamically at runtime from the secrets manager.

    Why this is correct

    Workload identity lets the application authenticate to the secrets manager without static credentials and fetch secrets at runtime. This removes long-lived secrets from code and configuration, supports rotation, and limits exposure if the workload is compromised.

  • ✗

    Embed secrets in the container image and rely on image scanning to detect accidental exposure.

    Why it's wrong here

    Embedding secrets in images makes them available to anyone who can pull the image and persists them across every deployment. Scanning may detect some exposures but does not prevent disclosure, and rotation becomes impractical because the image must be rebuilt.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.