EC-Council Certified Ethical Hacker (CEH) v12Cloud ComputingHard

A penetration tester is evaluating a cloud-native application that uses a serverless function to process data uploaded to an S3 bucket. During the assessment, the tester discovers that the serverless function's code contains hardcoded API keys for a third-party service. Which cloud security best practice is violated by this practice?

  1. ASeparation of concerns for secrets management.
  2. BUsing immutable infrastructure.
  3. CAdhering to the Shared Responsibility Model.
  4. DImplementing robust logging and monitoring.
Show answer & explanation

Correct answer: A. Separation of concerns for secrets management.

Hardcoding API keys directly into application code violates the principle of separating sensitive credentials (secrets) from the application logic. Best practices dictate using dedicated secrets management services, environment variables, or IAM roles for credentials.

Why the other options are wrong

  • B. Immutable infrastructure focuses on not changing deployed components, which is unrelated to hardcoding secrets.
  • C. The Shared Responsibility Model defines security boundaries, but doesn't dictate specific secret handling methods within the customer's responsibility.
  • D. Logging and monitoring are about visibility, not how secrets are handled.

Cloud Secrets Management

The practice of securely storing, retrieving, and managing sensitive information like API keys, database credentials, and certificates in a cloud environment.

  • Avoids hardcoding secrets in code.
  • Utilizes dedicated secrets management services (e.g., AWS Secrets Manager, Azure Key Vault).
  • Rotates secrets regularly and applies least privilege access.

Memory trick: Secrets management: Don't put the keys under the doormat.

More Cloud Computing questions