DevNet Associate (DEVASC) v1.0Application Deployment and SecurityHard

A development team is implementing a new microservice that requires access to several external APIs. Each API uses a different authentication method and requires a unique set of credentials (API keys, client secrets). To avoid hardcoding these credentials and manage them effectively across different environments (dev, staging, prod), they decide to use a centralized secrets management solution. Which of the following is the primary benefit of using such a solution over environment variables for sensitive data?

  1. AEnhances security by providing audit trails and dynamic secret generation.
  2. BReduces network latency for API calls by caching credentials.
  3. CSimplifies continuous integration pipeline configuration.
  4. DEnsures faster application startup times by pre-loading secrets.
Show answer & explanation

Correct answer: A. Enhances security by providing audit trails and dynamic secret generation.

Centralized secrets management solutions offer significant security enhancements beyond environment variables, including robust audit trails for who accessed what secret when, the ability to dynamically generate short-lived secrets, and stricter access controls, which are crucial for sensitive data.

Why the other options are wrong

  • B. Secrets management is about security and lifecycle, not network performance or caching.
  • C. While it can simplify configuration, this is a secondary benefit, not the primary security advantage.
  • D. Faster startup times are not a primary benefit; dynamic secret fetching might even slightly increase startup time in some scenarios.

Centralized Secrets Management

A system or platform designed to securely store, manage, and distribute sensitive information (secrets) like API keys, database credentials, and certificates across applications and environments. It provides features like access control, auditing, and dynamic secret generation.

  • Avoids hardcoding secrets.
  • Provides audit trails for secret access.
  • Enables dynamic and short-lived secrets.
  • Offers fine-grained access control.

Memory trick: Centralized secrets mean audit, dynamics, and no hardcoding.

More Application Deployment and Security questions