Courseiva

UiPath-ADPv1 Generic Automation Development Practice Question

When designing a large-scale automation, which approach is most effective for managing sensitive configuration data and credentials?

⚠ Common exam trap

Many candidates choose 'hard-coding in a config file' because it is easy, failing to realize that config files are often stored in source control, which exposes credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Orchestrator Assets to retrieve credentials during runtime.

Using Orchestrator Assets is the industry standard for securing sensitive data. It separates the credentials from the project code, ensuring that sensitive information is encrypted at rest and accessed only by authorized robots. This approach facilitates environment-specific configuration, allowing the same code to run in Development, UAT, and Production by simply pointing to different Orchestrator asset values without modifying the underlying workflow files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store credentials as clear-text inside an Excel configuration file.

    Why it's wrong here

    Storing clear-text credentials in configuration files is a major security vulnerability. Anyone with access to the file system or source control would be able to read the sensitive information, violating standard data protection policies and risking unauthorized access to integrated systems.

  • ✓

    Use Orchestrator Assets to retrieve credentials during runtime.

    Why this is correct

    Orchestrator Assets provide a centralized, secure repository for configuration data and credentials. They enable environment-specific management and ensure that sensitive info is never exposed in the source code, making it the most robust and secure method for managing automation configuration.

  • ✗

    Hard-code credentials directly in the activity properties for performance.

    Why it's wrong here

    Hard-coding sensitive information directly into properties is insecure and makes the automation rigid. If credentials change, a developer must manually update the workflow, re-test, and redeploy. This is inefficient, error-prone, and presents a significant security risk to the enterprise environment.

  • ✗

    Implement a custom local JSON file with hashed passwords.

    Why it's wrong here

    While hashing provides a small layer of obfuscation, it is not a substitute for secure credential management. Custom local files are still prone to unauthorized access and lack the centralized auditability and environment-based access control provided by native Orchestrator features.

About these practice questions

Courseiva writes every UiPath-ADPv1 question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official UiPath exam blueprint

This UiPath-ADPv1 practice question is part of Courseiva's free UiPath certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the UiPath-ADPv1 exam.