Secrets & Config interview questions

54 Secrets & Config questions from the DevOps & SRE bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Secret?

Junior
  1. A.a short-lived credential generated on demand and automatically revoked after use
  2. B.periodically replacing a secret with a new value to limit exposure window
  3. C.encrypting data with a data key that is itself encrypted by a key-management master key
  4. D.a sensitive value like a password or token that must be protected from exposure

Answer + AI explanation with Pro

2. Which term means: "a sensitive value like a password or token that must be protected from exposure"?

Junior
  1. A.Secret
  2. B.Dynamic secret
  3. C.Secret manager
  4. D.Least privilege

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Secret — a sensitive value like a password or token that must be protected from exposure
  2. B.Secret — protecting data moving over the network, typically with TLS
  3. C.Secret — a short-lived credential generated on demand and automatically revoked after use
  4. D.Secret — the bootstrapping challenge of securely delivering the first credential used to fetch others

Answer + AI explanation with Pro

4. What is Environment variable?

Junior
  1. A.binding a cloud identity to a workload so it authenticates without static credentials
  2. B.a short-lived credential generated on demand and automatically revoked after use
  3. C.periodically replacing a secret with a new value to limit exposure window
  4. D.a key-value pair injected into a process to configure runtime behavior

Answer + AI explanation with Pro

5. Which term means: "a key-value pair injected into a process to configure runtime behavior"?

Junior
  1. A.Dynamic secret
  2. B.Environment variable
  3. C.Secret
  4. D.Secret rotation

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.Environment variable — a key-value pair injected into a process to configure runtime behavior
  2. B.Environment variable — granting an identity only the minimum permissions needed to do its job
  3. C.Environment variable — protecting data moving over the network, typically with TLS
  4. D.Environment variable — the bootstrapping challenge of securely delivering the first credential used to fetch others

Answer + AI explanation with Pro

7. What is Secret manager?

Junior
  1. A.granting an identity only the minimum permissions needed to do its job
  2. B.a dedicated service that stores, controls access to, and audits secrets
  3. C.an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
  4. D.periodically replacing a secret with a new value to limit exposure window

Answer + AI explanation with Pro

8. Which term means: "a dedicated service that stores, controls access to, and audits secrets"?

Junior
  1. A.Encryption in transit
  2. B.Sealed secret
  3. C.Secret manager
  4. D.Envelope encryption

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Secret manager — a dedicated service that stores, controls access to, and audits secrets
  2. B.Secret manager — a short-lived credential generated on demand and automatically revoked after use
  3. C.Secret manager — granting an identity only the minimum permissions needed to do its job
  4. D.Secret manager — a sensitive value like a password or token that must be protected from exposure

Answer + AI explanation with Pro

10. What is Encryption at rest?

Junior
  1. A.a sensitive value like a password or token that must be protected from exposure
  2. B.a short-lived credential generated on demand and automatically revoked after use
  3. C.periodically replacing a secret with a new value to limit exposure window
  4. D.protecting stored data by encrypting it on disk

Answer + AI explanation with Pro

11. Which term means: "protecting stored data by encrypting it on disk"?

Junior
  1. A.Encryption at rest
  2. B.Dynamic secret
  3. C.Workload identity
  4. D.Envelope encryption

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Encryption at rest — a key-value pair injected into a process to configure runtime behavior
  2. B.Encryption at rest — a short-lived credential generated on demand and automatically revoked after use
  3. C.Encryption at rest — granting an identity only the minimum permissions needed to do its job
  4. D.Encryption at rest — protecting stored data by encrypting it on disk

Answer + AI explanation with Pro

13. What is Encryption in transit?

Junior
  1. A.protecting data moving over the network, typically with TLS
  2. B.the bootstrapping challenge of securely delivering the first credential used to fetch others
  3. C.a key-value pair injected into a process to configure runtime behavior
  4. D.a short-lived credential generated on demand and automatically revoked after use

Answer + AI explanation with Pro

14. Which term means: "protecting data moving over the network, typically with TLS"?

Junior
  1. A.Encryption in transit
  2. B.Environment variable
  3. C.Workload identity
  4. D.Secret

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Encryption in transit — a sensitive value like a password or token that must be protected from exposure
  2. B.Encryption in transit — protecting data moving over the network, typically with TLS
  3. C.Encryption in transit — the bootstrapping challenge of securely delivering the first credential used to fetch others
  4. D.Encryption in transit — encrypting data with a data key that is itself encrypted by a key-management master key

Answer + AI explanation with Pro

16. What is Secret rotation?

Mid
  1. A.granting an identity only the minimum permissions needed to do its job
  2. B.periodically replacing a secret with a new value to limit exposure window
  3. C.protecting stored data by encrypting it on disk
  4. D.protecting data moving over the network, typically with TLS

Answer + AI explanation with Pro

17. Which term means: "periodically replacing a secret with a new value to limit exposure window"?

Mid
  1. A.Secret rotation
  2. B.Encryption at rest
  3. C.Secret manager
  4. D.Secret zero problem

Answer + AI explanation with Pro

18. Which statement is correct?

Mid
  1. A.Secret rotation — granting an identity only the minimum permissions needed to do its job
  2. B.Secret rotation — a sensitive value like a password or token that must be protected from exposure
  3. C.Secret rotation — periodically replacing a secret with a new value to limit exposure window
  4. D.Secret rotation — protecting data moving over the network, typically with TLS

Answer + AI explanation with Pro

19. What is Least privilege?

Mid
  1. A.a key-value pair injected into a process to configure runtime behavior
  2. B.binding a cloud identity to a workload so it authenticates without static credentials
  3. C.a dedicated service that stores, controls access to, and audits secrets
  4. D.granting an identity only the minimum permissions needed to do its job

Answer + AI explanation with Pro

20. Which term means: "granting an identity only the minimum permissions needed to do its job"?

Mid
  1. A.Sealed secret
  2. B.Environment variable
  3. C.Secret rotation
  4. D.Least privilege

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Least privilege — the bootstrapping challenge of securely delivering the first credential used to fetch others
  2. B.Least privilege — granting an identity only the minimum permissions needed to do its job
  3. C.Least privilege — protecting data moving over the network, typically with TLS
  4. D.Least privilege — a short-lived credential generated on demand and automatically revoked after use

Answer + AI explanation with Pro

22. What is Dynamic secret?

Mid
  1. A.an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
  2. B.binding a cloud identity to a workload so it authenticates without static credentials
  3. C.a short-lived credential generated on demand and automatically revoked after use
  4. D.a dedicated service that stores, controls access to, and audits secrets

Answer + AI explanation with Pro

23. Which term means: "a short-lived credential generated on demand and automatically revoked after use"?

Mid
  1. A.Dynamic secret
  2. B.Sealed secret
  3. C.Encryption at rest
  4. D.Environment variable

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Dynamic secret — protecting stored data by encrypting it on disk
  2. B.Dynamic secret — protecting data moving over the network, typically with TLS
  3. C.Dynamic secret — a short-lived credential generated on demand and automatically revoked after use
  4. D.Dynamic secret — granting an identity only the minimum permissions needed to do its job

Answer + AI explanation with Pro

25. What is Sealed secret?

Mid
  1. A.periodically replacing a secret with a new value to limit exposure window
  2. B.an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
  3. C.the bootstrapping challenge of securely delivering the first credential used to fetch others
  4. D.a sensitive value like a password or token that must be protected from exposure

Answer + AI explanation with Pro

26. Which term means: "an encrypted secret safe to store in Git, decryptable only by an in-cluster controller"?

Mid
  1. A.Dynamic secret
  2. B.Environment variable
  3. C.Least privilege
  4. D.Sealed secret

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Sealed secret — encrypting data with a data key that is itself encrypted by a key-management master key
  2. B.Sealed secret — a key-value pair injected into a process to configure runtime behavior
  3. C.Sealed secret — an encrypted secret safe to store in Git, decryptable only by an in-cluster controller
  4. D.Sealed secret — a short-lived credential generated on demand and automatically revoked after use

Answer + AI explanation with Pro

28. What is Envelope encryption?

Senior
  1. A.encrypting data with a data key that is itself encrypted by a key-management master key
  2. B.binding a cloud identity to a workload so it authenticates without static credentials
  3. C.protecting data moving over the network, typically with TLS
  4. D.a key-value pair injected into a process to configure runtime behavior

Answer + AI explanation with Pro

29. Which term means: "encrypting data with a data key that is itself encrypted by a key-management master key"?

Senior
  1. A.Workload identity
  2. B.Secret zero problem
  3. C.Encryption at rest
  4. D.Envelope encryption

Answer + AI explanation with Pro

30. Which statement is correct?

Senior
  1. A.Envelope encryption — a key-value pair injected into a process to configure runtime behavior
  2. B.Envelope encryption — a short-lived credential generated on demand and automatically revoked after use
  3. C.Envelope encryption — granting an identity only the minimum permissions needed to do its job
  4. D.Envelope encryption — encrypting data with a data key that is itself encrypted by a key-management master key

Answer + AI explanation with Pro

Showing 30 of 54 Secrets & Config questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Secrets & Config question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers