Courseiva
mediumMultiple Select

CCSP Practice Question: Which TWO of the following are effective methods…

Which TWO of the following are effective methods for preventing hardcoded credentials from being committed to a cloud application's source code repository? (Select TWO)

⚠ Common exam trap

ISC2 CCSP often tests the distinction between preventive controls (pre-commit hooks, environment variables) and detective/reactive controls (code reviews, encryption) to see if candidates understand that only proactive measures can stop secrets from entering the repository in the first place.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing pre-commit hooks with secret scanning

Option A is correct because pre-commit hooks with secret scanning tools (e.g., git-secrets, gitleaks, detect-secrets) run locally before code is committed, detecting and blocking secrets such as API keys, passwords, and tokens before they ever enter the repository history. Option E is correct because storing credentials in environment variables (or a secrets manager) keeps sensitive values out of source files entirely, so nothing hardcoded can be committed. Option B is wrong because disabling SSH keys addresses developer authentication to Git, not the presence of hardcoded credentials in code. Option C is wrong because code reviews are a detective, manual control that may catch secrets but does not reliably prevent them from being committed. Option D is wrong because encrypting the repository at rest does not stop plaintext credentials from being committed and later exposed once decrypted or cloned.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implementing pre-commit hooks with secret scanning

    Why this is correct

    Pre-commit hooks run secret scanning locally before a commit is finalised, blocking credentials from ever entering repository history. This directly satisfies the stem's prevention requirement, unlike detection tools that only flag secrets after they have already been committed.

  • ✗

    Disabling SSH keys for developers

    Why it's wrong here

    Removing developer SSH keys blocks repository authentication entirely without addressing secrets in committed files. It appeals as access hardening, yet SSH keys are the correct control for authenticating Git operations, not for stopping credentials being written into source.

  • ✗

    Enforcing code reviews by senior developers

    Why it's wrong here

    Senior reviewers may catch secrets, but manual review is inconsistent and misses credentials already merged. It appeals because peer review is a genuine quality control, yet review is correct for logic and design defects; automated pre-commit secret scanning is what reliably blocks credential commits.

  • ✗

    Encrypting the entire repository

    Why it's wrong here

    Repository encryption protects data at rest but the credentials remain in plaintext to anyone with repository read access or a cloned working copy. It tempts as a data-protection measure, yet encryption is the right control for confidentiality of stored artefacts, not for detecting secrets in commits.

  • ✓

    Using environment variables instead of hardcoding

    Why this is correct

    Environment variables keep credentials outside the codebase, injecting them at runtime so nothing sensitive is committed. This removes the hardcoded value entirely, satisfying the stem's prevention goal rather than merely detecting exposure after the fact.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.