ETExamTower
Q53Application Deployment and Security

A developer has just finished configuring an API that connects sensitive internal systems. Under company policy, data security is a high priority. Which approach must be used to protect API keys and passwords?

← → navigate · a answer
Community votes
D
100% (4)
A
0% (0)
B
0% (0)
C
0% (0)
Discussion · 8
5
I’d go with "D. Change them periodically." "Do not embed API keys or signing secrets directly in code. Do not store API keys or signing secrets in files inside your application's source tree." https://developers.google.com/maps/api-key-best-practices
3
I'm going to say that it's probably 'D' because it says "Based on your company's policies" - which would mean something like regularly changing keys and rotating passwords. If I had to take a guess, a static hidden file is less secure than a key that changes often.
3
"D" https://blogs.cisco.com/developer/dna-center-api-authentication-with-vault
2
A. - you are basically exposing it B. - you can hide it but you cannot run remember the hackers are good at finding hidden objects. C. - why would you keep it in the source tree, that is a giveaway? D. - Change them periodically makes sense and in fact every companies general policy is to change password periodically.
D 2
Selected Answer: D D is the only one that really makes sense. But the truly correct answer should be: store them in local environmental variables. But also, recently there is a now aproach which is to keep them in a safe location and retrieve them via a safe program, such as conjur, that way you only need conjur key/secret and obtain from them all the other keys.
1
I think both "B" and "D" make sence
D 1
Selected Answer: D D is the best practice here.
D 1
Selected Answer: D Correct ansewr: D https://blogs.cisco.com/developer/dna-center-api-authentication-with-vault