CompTIA SecurityX (CAS-005)Security EngineeringEasy
A cloud architect is designing a new microservices-based application in a public cloud environment. Each microservice needs to securely access specific secrets (e.g., database credentials, API keys) without embedding them directly in the application code or configuration files. Which solution is BEST suited for managing and distributing these secrets dynamically and securely?
- AUtilizing a dedicated secrets management service (e.g., AWS Secrets Manager, HashiCorp Vault).
- BHardcoding secrets into the microservice containers and rebuilding them for every change.
- CStoring secrets in environment variables on each microservice instance.
- DEncrypting secrets in a Git repository and decrypting them at runtime with a shared key.
Show answer & explanationAnswer & explanation
Correct answer: A. Utilizing a dedicated secrets management service (e.g., AWS Secrets Manager, HashiCorp Vault).
Dedicated secrets management services are designed to securely store, manage, and distribute sensitive information, integrating with application frameworks to retrieve secrets dynamically at runtime without exposing them in code or configuration. This is a fundamental best practice for cloud-native applications.
Why the other options are wrong
- B. Hardcoding secrets is a severe security anti-pattern, making them difficult to change, prone to exposure, and requiring full rebuilds and redeployments for updates.
- C. Environment variables are better than hardcoding, but they can still be exposed through process listings or misconfigurations and lack centralized management, auditing, and dynamic rotation.
- D. Storing encrypted secrets in Git is better than plaintext, but still requires managing the shared decryption key and doesn't offer dynamic rotation or fine-grained access control.
Secrets Management
The tools and methods used to manage digital authentication credentials (secrets) for applications, services, and users, ensuring their secure storage, access, and lifecycle.
- Secure storage for credentials, API keys, tokens.
- Dynamic delivery to applications.
- Centralized control, auditing, and rotation.
Memory trick: Secrets in the Vault, never in the code.