54 Secrets & Config questions from the DevOps & SRE bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.a short-lived credential generated on demand and automatically revoked after use
B.periodically replacing a secret with a new value to limit exposure window
C.encrypting data with a data key that is itself encrypted by a key-management master key
D.a sensitive value like a password or token that must be protected from exposure
Answer + AI explanation with Pro
2. Which term means: "a sensitive value like a password or token that must be protected from exposure"?
Junior
A.Secret
B.Dynamic secret
C.Secret manager
D.Least privilege
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.Secret — a sensitive value like a password or token that must be protected from exposure
B.Secret — protecting data moving over the network, typically with TLS
C.Secret — a short-lived credential generated on demand and automatically revoked after use
D.Secret — the bootstrapping challenge of securely delivering the first credential used to fetch others
Answer + AI explanation with Pro
4. What is Environment variable?
Junior
A.binding a cloud identity to a workload so it authenticates without static credentials
B.a short-lived credential generated on demand and automatically revoked after use
C.periodically replacing a secret with a new value to limit exposure window
D.a key-value pair injected into a process to configure runtime behavior
Answer + AI explanation with Pro
5. Which term means: "a key-value pair injected into a process to configure runtime behavior"?
Junior
A.Dynamic secret
B.Environment variable
C.Secret
D.Secret rotation
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.Environment variable — a key-value pair injected into a process to configure runtime behavior
B.Environment variable — granting an identity only the minimum permissions needed to do its job
C.Environment variable — protecting data moving over the network, typically with TLS
D.Environment variable — the bootstrapping challenge of securely delivering the first credential used to fetch others
Answer + AI explanation with Pro
7. What is Secret manager?
Junior
A.granting an identity only the minimum permissions needed to do its job
B.a dedicated service that stores, controls access to, and audits secrets
C.an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
D.periodically replacing a secret with a new value to limit exposure window
Answer + AI explanation with Pro
8. Which term means: "a dedicated service that stores, controls access to, and audits secrets"?
Junior
A.Encryption in transit
B.Sealed secret
C.Secret manager
D.Envelope encryption
Answer + AI explanation with Pro
9. Which statement is correct?
Junior
A.Secret manager — a dedicated service that stores, controls access to, and audits secrets
B.Secret manager — a short-lived credential generated on demand and automatically revoked after use
C.Secret manager — granting an identity only the minimum permissions needed to do its job
D.Secret manager — a sensitive value like a password or token that must be protected from exposure
Answer + AI explanation with Pro
10. What is Encryption at rest?
Junior
A.a sensitive value like a password or token that must be protected from exposure
B.a short-lived credential generated on demand and automatically revoked after use
C.periodically replacing a secret with a new value to limit exposure window
D.protecting stored data by encrypting it on disk
Answer + AI explanation with Pro
11. Which term means: "protecting stored data by encrypting it on disk"?
Junior
A.Encryption at rest
B.Dynamic secret
C.Workload identity
D.Envelope encryption
Answer + AI explanation with Pro
12. Which statement is correct?
Junior
A.Encryption at rest — a key-value pair injected into a process to configure runtime behavior
B.Encryption at rest — a short-lived credential generated on demand and automatically revoked after use
C.Encryption at rest — granting an identity only the minimum permissions needed to do its job
D.Encryption at rest — protecting stored data by encrypting it on disk
Answer + AI explanation with Pro
13. What is Encryption in transit?
Junior
A.protecting data moving over the network, typically with TLS
B.the bootstrapping challenge of securely delivering the first credential used to fetch others
C.a key-value pair injected into a process to configure runtime behavior
D.a short-lived credential generated on demand and automatically revoked after use
Answer + AI explanation with Pro
14. Which term means: "protecting data moving over the network, typically with TLS"?
Junior
A.Encryption in transit
B.Environment variable
C.Workload identity
D.Secret
Answer + AI explanation with Pro
15. Which statement is correct?
Junior
A.Encryption in transit — a sensitive value like a password or token that must be protected from exposure
B.Encryption in transit — protecting data moving over the network, typically with TLS
C.Encryption in transit — the bootstrapping challenge of securely delivering the first credential used to fetch others
D.Encryption in transit — encrypting data with a data key that is itself encrypted by a key-management master key
Answer + AI explanation with Pro
16. What is Secret rotation?
Mid
A.granting an identity only the minimum permissions needed to do its job
B.periodically replacing a secret with a new value to limit exposure window
C.protecting stored data by encrypting it on disk
D.protecting data moving over the network, typically with TLS
Answer + AI explanation with Pro
17. Which term means: "periodically replacing a secret with a new value to limit exposure window"?
Mid
A.Secret rotation
B.Encryption at rest
C.Secret manager
D.Secret zero problem
Answer + AI explanation with Pro
18. Which statement is correct?
Mid
A.Secret rotation — granting an identity only the minimum permissions needed to do its job
B.Secret rotation — a sensitive value like a password or token that must be protected from exposure
C.Secret rotation — periodically replacing a secret with a new value to limit exposure window
D.Secret rotation — protecting data moving over the network, typically with TLS
Answer + AI explanation with Pro
19. What is Least privilege?
Mid
A.a key-value pair injected into a process to configure runtime behavior
B.binding a cloud identity to a workload so it authenticates without static credentials
C.a dedicated service that stores, controls access to, and audits secrets
D.granting an identity only the minimum permissions needed to do its job
Answer + AI explanation with Pro
20. Which term means: "granting an identity only the minimum permissions needed to do its job"?
Mid
A.Sealed secret
B.Environment variable
C.Secret rotation
D.Least privilege
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.Least privilege — the bootstrapping challenge of securely delivering the first credential used to fetch others
B.Least privilege — granting an identity only the minimum permissions needed to do its job
C.Least privilege — protecting data moving over the network, typically with TLS
D.Least privilege — a short-lived credential generated on demand and automatically revoked after use
Answer + AI explanation with Pro
22. What is Dynamic secret?
Mid
A.an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
B.binding a cloud identity to a workload so it authenticates without static credentials
C.a short-lived credential generated on demand and automatically revoked after use
D.a dedicated service that stores, controls access to, and audits secrets
Answer + AI explanation with Pro
23. Which term means: "a short-lived credential generated on demand and automatically revoked after use"?
Mid
A.Dynamic secret
B.Sealed secret
C.Encryption at rest
D.Environment variable
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.Dynamic secret — protecting stored data by encrypting it on disk
B.Dynamic secret — protecting data moving over the network, typically with TLS
C.Dynamic secret — a short-lived credential generated on demand and automatically revoked after use
D.Dynamic secret — granting an identity only the minimum permissions needed to do its job
Answer + AI explanation with Pro
25. What is Sealed secret?
Mid
A.periodically replacing a secret with a new value to limit exposure window
B.an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
C.the bootstrapping challenge of securely delivering the first credential used to fetch others
D.a sensitive value like a password or token that must be protected from exposure
Answer + AI explanation with Pro
26. Which term means: "an encrypted secret safe to store in Git, decryptable only by an in-cluster controller"?
Mid
A.Dynamic secret
B.Environment variable
C.Least privilege
D.Sealed secret
Answer + AI explanation with Pro
27. Which statement is correct?
Mid
A.Sealed secret — encrypting data with a data key that is itself encrypted by a key-management master key
B.Sealed secret — a key-value pair injected into a process to configure runtime behavior
C.Sealed secret — an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
D.Sealed secret — a short-lived credential generated on demand and automatically revoked after use
Answer + AI explanation with Pro
28. What is Envelope encryption?
Senior
A.encrypting data with a data key that is itself encrypted by a key-management master key
B.binding a cloud identity to a workload so it authenticates without static credentials
C.protecting data moving over the network, typically with TLS
D.a key-value pair injected into a process to configure runtime behavior
Answer + AI explanation with Pro
29. Which term means: "encrypting data with a data key that is itself encrypted by a key-management master key"?
Senior
A.Workload identity
B.Secret zero problem
C.Encryption at rest
D.Envelope encryption
Answer + AI explanation with Pro
30. Which statement is correct?
Senior
A.Envelope encryption — a key-value pair injected into a process to configure runtime behavior
B.Envelope encryption — a short-lived credential generated on demand and automatically revoked after use
C.Envelope encryption — granting an identity only the minimum permissions needed to do its job
D.Envelope encryption — encrypting data with a data key that is itself encrypted by a key-management master key
Answer + AI explanation with Pro
Showing 30 of 54 Secrets & Config questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Secrets & Config question come with Pro.