Courseiva
mediumMultiple Choice

CCSP Practice Question: A developer accidentally commits cloud access…

A developer accidentally commits cloud access keys to a public GitHub repository. Which tool would be most effective in detecting this secret exposure?

⚠ Common exam trap

The trap is confusing infrastructure-as-code scanners (tfsec, Checkov) or dependency scanners (npm audit) with secret detection tools — only dedicated secret scanners catch hardcoded credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GitGuardian

GitGuardian is a dedicated secrets detection platform that scans repositories (including public GitHub repos) for exposed credentials, API keys, and tokens using pattern matching and entropy analysis. It integrates with GitHub via webhooks or CI/CD to alert on commits containing secrets. This directly addresses the scenario of accidentally committed cloud access keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terraform

    Why it's wrong here

    Terraform provisions and manages cloud infrastructure as code; it neither scans repositories nor inspects commit history for credentials. It is tempting because it handles cloud resources and can reference secrets, but secret detection in a public GitHub repo requires a dedicated scanning tool such as git-secrets or GitHub secret scanning.

  • ✓

    GitGuardian

    Why this is correct

    GitGuardian continuously scans repositories and commit history for exposed credentials, using pattern matching and entropy analysis to detect cloud access keys even after commits are pushed. It alerts immediately and supports remediation, directly addressing the accidental public exposure of keys described in the scenario.

  • ✗

    npm audit

    Why it's wrong here

    npm audit inspects installed Node.js dependencies against a vulnerability advisory database; it does not scan repository contents or commit history for exposed credentials. It is tempting because it is a security-scanning command run in developer workflows, but committed cloud access keys require dedicated secret-scanning tooling.

  • ✗

    tfsec

    Why it's wrong here

    tfsec statically analyses Terraform configuration files for infrastructure misconfigurations; it does not detect credentials committed to a repository. It is tempting because it is a security scanner operating on code, but its scope is IaC weaknesses, whereas exposed access keys in GitHub demand secret-scanning tooling.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.