easyMultiple Choice
CCSP Practice Question: Is a key practice for secure management of cloud…
Which of the following is a key practice for secure management of cloud credentials in application code?
⚠ Common exam trap
A common misconception is that environment variables are a secure alternative to hardcoding, but they are still plaintext and can be exposed through process listings, container orchestration tools, or misconfigured logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use IAM roles or managed identities
Using IAM roles or managed identities eliminates the need to embed long-term credentials in application code. This approach relies on temporary, automatically rotated credentials obtained via the cloud provider's metadata service (e.g., AWS IMDSv2, Azure Instance Metadata Service), which significantly reduces the risk of credential leakage and simplifies credential management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcode credentials in environment variables
Why it's wrong here
Environment variables are readable by any process or user with access to the runtime environment and are frequently captured in logs, crash dumps and CI output, so they are not a secure store. A dedicated secrets manager with access control and rotation is the correct mechanism.
- ✓
Use IAM roles or managed identities
Why this is correct
IAM roles and managed identities issue short-lived, automatically rotated credentials to workloads, eliminating hard-coded secrets in application code. This satisfies secure credential management by removing static keys that could be leaked, committed to repositories, or exfiltrated.
- ✗
Store credentials in source code comments
Why it's wrong here
Source code comments are committed to version control and visible to everyone with repository read access, offering no confidentiality whatsoever. Secrets belong in a managed vault with auditing and rotation; comments are for documentation, never credentials.
- ✗
Encrypt credentials with a static key in the codebase
Why it's wrong here
A static key embedded in the codebase is itself a secret that anyone with repository access can extract, so encryption provides no protection once code leaks. Key management services such as Azure Key Vault or AWS KMS exist precisely to hold keys outside source control.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.