Which TWO of the following configurations are best practices for managing credentials in an Orchestrator-connected environment?
Orchestrator Assets are the recommended mechanism for secure, centralized storage. Using Get Asset allows the robot to fetch credentials dynamically at runtime, ensuring that if a password changes, the robot can immediately use the new value without requiring the developer to modify or republish the automation project.
Why this answer
Centralizing credentials in Orchestrator ensures that secrets are not hardcoded in workflows, satisfying security audit requirements. By using Assets, developers can update values without redeploying code. Furthermore, leveraging the 'SecureString' data type for passwords ensures that sensitive information remains encrypted in memory during execution, preventing accidental exposure in log files or during debugging sessions.
These configurations are essential for creating production-ready, secure, and maintainable automation deployments.
Exam trap
Candidates mistakenly store credentials in hardcoded variables or config files, ignoring the security risk of exposing plain-text passwords in the project files or log outputs.