mediumMultiple Choice
CCSP Practice Question: During a code review, a developer discovers…
During a code review, a developer discovers hardcoded AWS access keys in a configuration file that was committed to the repository. Which tool is specifically designed to detect such secrets in code repositories?
⚠ Common exam trap
CCSP often tests the difference between secret-scanning tools and IaC misconfiguration scanners — candidates who see 'code review' and 'configuration file' may incorrectly pick tfsec or Checkov, which target infrastructure misconfigurations, not hardcoded secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GitGuardian
GitGuardian is a security platform specifically designed to detect secrets such as API keys, passwords, and tokens in source code repositories, including historical commits. It integrates with version control systems and CI/CD pipelines to scan for hardcoded credentials, making it the correct tool for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
GitGuardian
Why this is correct
GitGuardian scans repository history and commits specifically for exposed secrets such as AWS access keys, alerting on hardcoded credentials. This directly satisfies the stem's requirement for a tool designed to detect secrets committed to code repositories, rather than general static analysis.
- ✗
tfsec
Why it's wrong here
tfsec statically analyses Terraform configuration for security misconfigurations, such as unencrypted storage or permissive security groups; it does not scan for hardcoded AWS access keys in arbitrary configuration files. It tempts because it inspects committed infrastructure code, but its scope is Terraform resource settings, not secret detection.
- ✗
Checkov
Why it's wrong here
Checkov performs static analysis of infrastructure-as-code templates such as Terraform and CloudFormation for misconfigurations, not for hardcoded credentials in application configuration files. It tempts because it scans committed code, yet its detection targets resource settings like open buckets, not embedded AWS access keys.
- ✗
Snyk
Why it's wrong here
Snyk scans open-source dependencies and container images for known vulnerabilities; it does not primarily detect hardcoded credentials in committed configuration files. It tempts because Snyk does offer some secret-scanning capability, but its core purpose is dependency and code vulnerability analysis rather than repository secret detection.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.