UiPath-ADPv1 Orchestrator Advanced Usage Practice Question
Which Orchestrator feature is best suited for sharing sensitive credentials between multiple processes without exposing them in plain text or hardcoding them in workflows?
⚠ Common exam trap
Candidates frequently store credentials in standard string assets or config files rather than dedicated Credential assets, unintentionally exposing plain text passwords in Orchestrator logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using Orchestrator Assets with the 'Credential' type.
Assets, specifically 'Credential' type assets, provide a secure, encrypted mechanism to store sensitive information in Orchestrator. When accessed by a robot, the credentials are decrypted on-the-fly and only at runtime. This practice adheres to the security principle of abstraction, ensuring that developers never interact with actual passwords, and administrators can rotate them centrally without modifying or redeploying any automation workflows across the enterprise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storing the credentials in a local text file.
Why it's wrong here
Storing credentials in local files is a severe security risk. Even if encrypted, local files lack the centralized auditability, rotation capabilities, and access control that Orchestrator assets provide. This approach makes credential management impossible at scale and violates standard compliance requirements for protecting enterprise systems from unauthorized access.
- ✓
Using Orchestrator Assets with the 'Credential' type.
Why this is correct
Credential assets in Orchestrator are specifically designed for secure storage and retrieval. They integrate with the Robot's security context, ensuring that sensitive values are never logged or exposed in the user interface. This is the recommended industry-standard approach for managing logins across multiple unattended robot workflows in production.
- ✗
Embedding the password in a custom configuration JSON.
Why it's wrong here
Embedding credentials within JSON files or any configuration object is highly insecure. These files are often stored in source control systems, which would expose the passwords to anyone with repository access. This practice bypasses all Orchestrator security controls and makes it impossible to rotate passwords securely across the environment.
- ✗
Passing credentials as arguments at runtime.
Why it's wrong here
Passing credentials as arguments exposes them in the Orchestrator job logs and history. Any user with access to view job details would be able to see the plain-text password. This practice is insecure and fails to meet basic auditing and data protection standards for sensitive information management in automation.
About these practice questions
One of 276 original UiPath-ADPv1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official UiPath exam blueprint
This UiPath-ADPv1 practice question is part of Courseiva's free UiPath certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the UiPath-ADPv1 exam.