Courseiva
hardMultiple Choice

SSCP Practice Question: A security analyst is reviewing a script that…

A security analyst is reviewing a script that performs automated backups. The script uses a hardcoded password to connect to the database. What is the most secure alternative?

⚠ Common exam trap

The trap is thinking that environment variables or frequent password changes are 'secure enough'; the exam expects recognition that only a secrets manager removes the hardcoded secret and provides rotation, auditing, and least-privilege access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Retrieve the password from a secrets management service at runtime.

Retrieving the password from a secrets management service at runtime is the most secure alternative because it eliminates hardcoded credentials from the script and centralizes secret storage with access controls, auditing, and rotation. Services like AWS Secrets Manager, HashiCorp Vault, or Azure Key Vault issue short-lived credentials and log access. This removes the secret from source code and version control entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the password manually every week.

    Why it's wrong here

    Manual process is error-prone and still stored in script.

  • ✗

    Store the password in an environment variable.

    Why it's wrong here

    Environment variables are still visible in process listings and logs.

  • ✗

    Replace the password with SSH key authentication.

    Why it's wrong here

    SSH keys are for server access, not database authentication.

  • ✓

    Retrieve the password from a secrets management service at runtime.

    Why this is correct

    A secrets management service stores credentials encrypted and issues them only to authenticated, authorised callers at runtime, so the password never resides in the script or source control. This removes the hardcoded secret, satisfying the requirement for a more secure alternative.

  • ✗

    Use a more complex password.

    Why it's wrong here

    Complexity does not address the hardcoded vulnerability.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.