mediumMultiple Select
CCSP Practice Question: Wants to prevent secrets from being exposed in…
An organization wants to prevent secrets from being exposed in source code. Which two practices should they adopt? (Choose TWO.)
⚠ Common exam trap
CCSP often tests the misconception that encrypting code or blocking network access protects secrets — the exam expects you to recognize that secrets must never be in code and must be scanned for continuously.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement secret scanning in the CI/CD pipeline
Option A is correct because implementing secret scanning in the CI/CD pipeline automatically detects hardcoded credentials (API keys, tokens, passwords) in commits and pull requests before they are merged or deployed, using tools like GitGuardian, TruffleHog, or GitHub secret scanning to fail the build and alert developers. Option D is correct because a secrets management service (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) stores credentials centrally and injects them at runtime via API calls or environment variables, so secrets never appear in source code or version control. Option B is not appropriate because encrypting source files does not prevent secrets from being committed and exposed; the plaintext secrets still exist in the repository and can be decrypted or leaked via build artifacts. Option C is wrong because a firewall controls network access to repositories but does nothing to stop developers from hardcoding secrets into code that is later pushed. Option E is incorrect because disabling git history destroys auditability and collaboration, and it does not prevent secrets from being written into new commits in the first place.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement secret scanning in the CI/CD pipeline
Why this is correct
Automated secret scanning inspects commits and pipeline artefacts for hard-coded credentials such as API keys and tokens, catching exposure before code merges or deploys. This directly satisfies the goal of preventing secrets from reaching source code, since detection occurs within the CI/CD workflow rather than after release.
- ✗
Encrypt all source code files
Why it's wrong here
Encrypting source files protects data at rest but leaves plaintext secrets visible to anyone with repository read access or build permissions. Encryption suits stored data confidentiality; preventing exposure requires detecting and blocking secrets before commit, such as scanning and pre-commit hooks.
- ✗
Use a firewall to block access to code repositories
Why it's wrong here
A firewall filtering repository traffic cannot detect secrets committed into source code, since the exposure occurs inside files rather than at the network perimeter. It is tempting because firewalls legitimately restrict who reaches a repository, which suits perimeter access control, not content inspection of commits.
- ✓
Use a secrets management service to retrieve credentials at runtime
Why this is correct
A secrets management service stores credentials centrally and issues them only at runtime, so no secret is ever committed to the repository. This satisfies the prevention goal by removing hard-coded values from source code entirely, rather than merely detecting them after exposure.
- ✗
Disable git history
Why it's wrong here
Deleting git history destroys auditability and rollback capability while leaving secrets in working trees and future commits. History rewriting is a remediation step after exposure, not a preventive control; secret scanning and pre-commit hooks stop credentials entering the repository in the first place.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.