Courseiva

CCSP Cloud Application Security Practice Question

Which THREE are best practices for implementing secrets management in cloud applications?

⚠ Common exam trap

ISC2 often tests the misconception that logging secrets is acceptable for debugging (Option A) or that version control with .gitignore is sufficient to protect secrets (Option B), but the CCSP exam emphasizes that secrets must never be stored in logs or repositories, and must always be managed via dedicated, rotation-capable services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a dedicated secrets management service

Option C is correct because a dedicated secrets management service (e.g., AWS Secrets Manager, Azure Key Vault, HashiCorp Vault) centralizes storage, enforces access control via IAM policies, and provides audit logging and programmatic retrieval, which is the recommended pattern for cloud applications. Option D is correct because regularly rotating secrets limits the blast radius of a leaked credential and is a core requirement of standards like PCI DSS and NIST SP 800-57; managed services can automate rotation via Lambda or native rotation policies. Option E is correct because secrets must be encrypted at rest (e.g., AES-256 via KMS) and in transit (TLS 1.2+) to prevent exposure from compromised storage or network interception. Option A is not a best practice because embedding secrets in application logs exposes them to anyone with log access and defeats the purpose of secret confidentiality. Option B is not a best practice because storing secrets in version control repositories persists them in history, making them retrievable even after deletion and widely accessible to anyone with repo access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Embed secrets in application logs for debugging

    Why it's wrong here

    Logging secrets writes them into a widely readable, long-retained system, directly exposing credentials to anyone with log access. It is tempting because logs aid debugging, and verbose logging would be correct for non-sensitive diagnostic data, never for secrets themselves.

  • ✗

    Store secrets in version control repositories

    Why it's wrong here

    Version control retains full history, so a committed secret persists even after deletion and is exposed to every repository reader. It is tempting because version control is the standard place for configuration, and it would be correct for non-sensitive configuration values, not credentials.

  • ✓

    Use a dedicated secrets management service

    Why this is correct

    A dedicated secrets management service centralises storage, access control and auditing, removing hard-coded credentials from source and configuration. It enforces least-privilege retrieval and enables automated rotation, directly satisfying the best-practice requirement for controlling secret sprawl across cloud applications.

  • ✓

    Rotate secrets regularly

    Why this is correct

    Regular rotation limits the window in which a leaked or intercepted credential remains usable, containing blast radius. Because static secrets inevitably risk exposure over time, scheduled rotation through automation satisfies the best-practice requirement for reducing credential lifetime in cloud applications.

  • ✓

    Encrypt secrets at rest and in transit

    Why this is correct

    Encrypting secrets at rest protects stored values from unauthorised disk or backup access, while encryption in transit prevents interception during retrieval. Together they satisfy the best-practice requirement that secrets remain confidential throughout their lifecycle, regardless of where they are stored or transmitted.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.