Courseiva

UiPath-ADPv1 Generic Automation Development Practice Question

Which TWO of the following configurations are best practices for managing credentials in an Orchestrator-connected environment?

⚠ Common exam trap

Candidates mistakenly store credentials in hardcoded variables or config files, ignoring the security risk of exposing plain-text passwords in the project files or log outputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Orchestrator Assets to store credentials and retrieve them using the Get Asset activity.

Centralizing credentials in Orchestrator ensures that secrets are not hardcoded in workflows, satisfying security audit requirements. By using Assets, developers can update values without redeploying code. Furthermore, leveraging the 'SecureString' data type for passwords ensures that sensitive information remains encrypted in memory during execution, preventing accidental exposure in log files or during debugging sessions. These configurations are essential for creating production-ready, secure, and maintainable automation deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store passwords in a Config.xlsx file with the 'Private' attribute enabled.

    Why it's wrong here

    Config files are static assets that are often included in source control repositories. Storing passwords here, even with Excel-level protection, is a major security vulnerability as it leaves credentials susceptible to unauthorized access and version control leakage, violating standard organizational security policies regarding credential management.

  • ✓

    Use Orchestrator Assets to store credentials and retrieve them using the Get Asset activity.

    Why this is correct

    Orchestrator Assets are the recommended mechanism for secure, centralized storage. Using Get Asset allows the robot to fetch credentials dynamically at runtime, ensuring that if a password changes, the robot can immediately use the new value without requiring the developer to modify or republish the automation project.

  • ✗

    Define passwords as String variables and set them as arguments in the main workflow.

    Why it's wrong here

    Passing passwords through workflow arguments creates a risk of logging sensitive data. When arguments are traced in logs or monitored during debugging, the plain-text password can become visible. String variables lack the inherent encryption protections of the SecureString type, making them inappropriate for handling sensitive authentication data.

  • ✓

    Retrieve credentials as SecureString and pass them to activity properties that support it.

    Why this is correct

    SecureString ensures the password is encrypted in memory. Many UiPath activities, such as 'Type Into' with 'SecureText' enabled, accept this format directly. This design prevents the credential from being output to logs or displayed in plaintext during the execution, adhering to strict data privacy and security compliance standards.

  • ✗

    Hardcode credentials in the workflow using a Dictionary object for quick access.

    Why it's wrong here

    Hardcoding credentials inside code logic is a critical security failure. It makes it impossible to rotate passwords without code changes, introduces significant security risks if the source code is accessed by unauthorized personnel, and violates almost every standard for secure software development and UiPath operational governance.

About these practice questions

One of 276 original UiPath-ADPv1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official UiPath exam blueprint

This UiPath-ADPv1 practice question is part of Courseiva's free UiPath certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the UiPath-ADPv1 exam.