CompTIA SecurityX (CAS-005)Security EngineeringEasy

A cloud architect is designing a new microservices-based application in a public cloud environment. Each microservice needs to securely access sensitive credentials (e.g., API keys, database passwords) without embedding them directly in code or configuration files. The solution should also ensure that these credentials are automatically rotated and audited. Which security engineering practice is MOST appropriate for managing these sensitive credentials?

  1. AImplementing a custom credential obfuscation algorithm
  2. BUsing a secrets management solution
  3. CHardcoding credentials in environment variables
  4. DStoring credentials in an encrypted S3 bucket
Show answer & explanation

Correct answer: B. Using a secrets management solution

A secrets management solution (like HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) is specifically designed to securely store, distribute, and manage sensitive credentials for applications, including features like automatic rotation, auditing, and fine-grained access control. This directly addresses the need to avoid hardcoding and to manage credentials securely and dynamically.

Why the other options are wrong

  • A. Custom obfuscation algorithms are typically weak, provide a false sense of security, and do not offer secure storage, rotation, or auditing.
  • C. Hardcoding credentials, even in environment variables, is insecure as they can still be exposed or persist longer than necessary.
  • D. Storing credentials in an encrypted S3 bucket is better than hardcoding but lacks the dynamic rotation, fine-grained access control, and auditing capabilities of a dedicated secrets management solution.

Secrets Management

Secrets management is the practice of securing and managing sensitive digital authentication credentials (secrets) that are used by applications, services, and users.

  • Prevents hardcoding of credentials.
  • Enables automatic rotation and auditing of secrets.
  • Centralizes and controls access to sensitive credentials.

Memory trick: Secrets management is the vault for your app's keys.

More Security Engineering questions