Courseiva

UiPath-ADAv1 Business and Platform Knowledge Practice Question

Which approach is recommended for managing sensitive credentials (like database passwords) in UiPath automations?

⚠ Common exam trap

Candidates often suggest 'storing in a text file' or 'using environment variables,' which are insecure and violate standard security practices for handling sensitive enterprise credentials in UiPath.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store them as Orchestrator Assets.

Using Orchestrator Assets to store sensitive information is the industry standard for security. It ensures that credentials are encrypted in the central database and are never hard-coded in the workflow. This separation of concerns allows for easier password rotation and prevents security breaches that could occur if hard-coded credentials were exposed in version control or project files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store them in a local text file with restricted permissions.

    Why it's wrong here

    Local text files are inherently insecure, as they could be accessed by other users or processes on the machine. Even with permissions, they don't provide the centralized auditing, encryption, and management capabilities provided by the Orchestrator platform, making them a significant security risk for any enterprise automation.

  • ✓

    Store them as Orchestrator Assets.

    Why this is correct

    Orchestrator Assets provide a secure, encrypted mechanism to store sensitive data. By using the 'Credential' type, the credentials are kept secure and only retrieved at runtime, ensuring that they are not stored in plain text within the automation projects or the robot's local configuration files.

  • ✗

    Hard-code them as String variables in a secure workflow.

    Why it's wrong here

    Hard-coding sensitive information is a critical security vulnerability. It makes the credentials visible to anyone with access to the source code or the project files. Credentials should always be externalized and managed through secure vaulting mechanisms to ensure compliance with security and audit requirements.

  • ✗

    Pass them as input arguments via the Command Line Interface.

    Why it's wrong here

    Passing credentials via the CLI exposes them in command history or process monitoring logs. This is a poor security practice that violates basic principles of protecting sensitive information. Credentials should always be handled through secure, encrypted channels that do not log or reveal the actual values.

About these practice questions

One of 285 original UiPath-ADAv1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official UiPath exam blueprint

This UiPath-ADAv1 practice question is part of Courseiva's free UiPath certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the UiPath-ADAv1 exam.