CompTIA SecurityX (CAS-005)Security OperationsEasy

A security architect is reviewing the security posture of an organization's continuous integration/continuous deployment (CI/CD) pipeline. They observe that sensitive API keys and database credentials are hardcoded directly into application source code within the Git repository. What is the MOST significant security risk introduced by this practice?

  1. AExposure of sensitive credentials to anyone with access to the source code repository or build artifacts.
  2. BSlower deployment times due to the need for manual credential updates.
  3. CIncreased build failure rates due to incorrect credentials.
  4. DDifficulty in managing different credentials for development, staging, and production environments.
Show answer & explanation

Correct answer: A. Exposure of sensitive credentials to anyone with access to the source code repository or build artifacts.

Hardcoding sensitive credentials directly into source code and storing them in a Git repository (C) poses the most significant security risk. Anyone with access to the repository (developers, auditors, or even attackers if compromised) can easily retrieve these credentials, leading to unauthorized access to critical systems and data. The other options are operational or management challenges, not direct security risks of exposure.

Why the other options are wrong

  • B. Slower deployment times are an operational inefficiency, not a security risk of credential exposure.
  • C. Build failure rates are an operational issue, not a direct security risk of credential exposure.
  • D. Difficulty in managing different credentials is a configuration management challenge, not the primary security risk of exposure.

Hardcoded Credentials Risk

The security risk associated with embedding sensitive authentication information (like API keys, passwords, or tokens) directly into application source code or configuration files. This practice makes credentials easily discoverable, difficult to rotate, and highly vulnerable if the code repository or compiled application is compromised.

  • Credentials exposed in source code.
  • Anyone with code access can retrieve them.
  • Difficult to manage and rotate.
  • Common source of data breaches.

Memory trick: Hardcoded Credentials are a Hard NO for Security.

More Security Operations questions