51 Secrets Management questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.short-lived credentials generated on demand and automatically revoked after use
B.scoping each secret so only the workloads that need it can read it
C.sensitive credential such as a password, API key, token, or private key
D.automatically detecting committed credentials in repositories and history
Answer + AI explanation with Pro
2. Which term means: "sensitive credential such as a password, API key, token, or private key"?
Junior
A.Secret
B.Secret zero problem
C.Hardcoded secret
D.Envelope encryption
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.Secret — encrypting data with a data key that is itself encrypted by a key-encryption key
B.Secret — sensitive credential such as a password, API key, token, or private key
C.Secret — tamper-resistant device that generates and stores keys and performs crypto operations
D.Secret — exchanging a trusted workload identity for short-lived secrets without long-lived keys
Answer + AI explanation with Pro
4. What is Hardcoded secret?
Junior
A.credential embedded directly in source code, a frequent leak vector
B.the bootstrapping challenge of securely delivering the first credential to access a secrets store
C.short-lived credentials generated on demand and automatically revoked after use
D.sensitive credential such as a password, API key, token, or private key
Answer + AI explanation with Pro
5. Which term means: "credential embedded directly in source code, a frequent leak vector"?
Junior
A.Hardcoded secret
B.Hardware Security Module (HSM)
C.Secret
D.Secret zero problem
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.Hardcoded secret — short-lived credentials generated on demand and automatically revoked after use
B.Hardcoded secret — regularly replacing credentials to limit the window of exposure if one leaks
C.Hardcoded secret — credential embedded directly in source code, a frequent leak vector
D.Hardcoded secret — scoping each secret so only the workloads that need it can read it
Answer + AI explanation with Pro
7. What is Environment variable secret?
Junior
A.regularly replacing credentials to limit the window of exposure if one leaks
B.the bootstrapping challenge of securely delivering the first credential to access a secrets store
C.passing a credential to a process via an env var instead of committing it to code
D.sensitive credential such as a password, API key, token, or private key
Answer + AI explanation with Pro
8. Which term means: "passing a credential to a process via an env var instead of committing it to code"?
Junior
A.Secret zero problem
B.Secret scanning
C.Environment variable secret
D.Workload identity federation
Answer + AI explanation with Pro
9. Which statement is correct?
Junior
A.Environment variable secret — regularly replacing credentials to limit the window of exposure if one leaks
B.Environment variable secret — exchanging a trusted workload identity for short-lived secrets without long-lived keys
C.Environment variable secret — passing a credential to a process via an env var instead of committing it to code
D.Environment variable secret — automatically detecting committed credentials in repositories and history
Answer + AI explanation with Pro
10. What is Secret rotation?
Junior
A.credential embedded directly in source code, a frequent leak vector
B.scoping each secret so only the workloads that need it can read it
C.the bootstrapping challenge of securely delivering the first credential to access a secrets store
D.regularly replacing credentials to limit the window of exposure if one leaks
Answer + AI explanation with Pro
11. Which term means: "regularly replacing credentials to limit the window of exposure if one leaks"?
Junior
A.Hardware Security Module (HSM)
B.Secret rotation
C.Envelope encryption
D.Environment variable secret
Answer + AI explanation with Pro
12. Which statement is correct?
Junior
A.Secret rotation — tamper-resistant device that generates and stores keys and performs crypto operations
B.Secret rotation — sensitive credential such as a password, API key, token, or private key
C.Secret rotation — regularly replacing credentials to limit the window of exposure if one leaks
D.Secret rotation — automatically detecting committed credentials in repositories and history
Answer + AI explanation with Pro
13. What is Dynamic secrets?
Mid
A.encrypting data with a data key that is itself encrypted by a key-encryption key
B.sensitive credential such as a password, API key, token, or private key
C.automatically detecting committed credentials in repositories and history
D.short-lived credentials generated on demand and automatically revoked after use
Answer + AI explanation with Pro
14. Which term means: "short-lived credentials generated on demand and automatically revoked after use"?
Mid
A.Hardcoded secret
B.Secret zero problem
C.Dynamic secrets
D.Workload identity federation
Answer + AI explanation with Pro
15. Which statement is correct?
Mid
A.Dynamic secrets — credential embedded directly in source code, a frequent leak vector
B.Dynamic secrets — exchanging a trusted workload identity for short-lived secrets without long-lived keys
C.Dynamic secrets — encrypting data with a data key that is itself encrypted by a key-encryption key
D.Dynamic secrets — short-lived credentials generated on demand and automatically revoked after use
Answer + AI explanation with Pro
16. What is Secret scanning?
Mid
A.exchanging a trusted workload identity for short-lived secrets without long-lived keys
B.encrypting data with a data key that is itself encrypted by a key-encryption key
C.automatically detecting committed credentials in repositories and history
D.sensitive credential such as a password, API key, token, or private key
Answer + AI explanation with Pro
17. Which term means: "automatically detecting committed credentials in repositories and history"?
Mid
A.Workload identity federation
B.Hardware Security Module (HSM)
C.Envelope encryption
D.Secret scanning
Answer + AI explanation with Pro
18. Which statement is correct?
Mid
A.Secret scanning — exchanging a trusted workload identity for short-lived secrets without long-lived keys
B.Secret scanning — automatically detecting committed credentials in repositories and history
C.Secret scanning — passing a credential to a process via an env var instead of committing it to code
D.Secret scanning — tamper-resistant device that generates and stores keys and performs crypto operations
Answer + AI explanation with Pro
19. What is Envelope encryption?
Mid
A.sensitive credential such as a password, API key, token, or private key
B.encrypting data with a data key that is itself encrypted by a key-encryption key
C.automatically detecting committed credentials in repositories and history
D.the bootstrapping challenge of securely delivering the first credential to access a secrets store
Answer + AI explanation with Pro
20. Which term means: "encrypting data with a data key that is itself encrypted by a key-encryption key"?
Mid
A.Hardcoded secret
B.Envelope encryption
C.Secret scanning
D.Workload identity federation
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.Envelope encryption — tamper-resistant device that generates and stores keys and performs crypto operations
B.Envelope encryption — automatically detecting committed credentials in repositories and history
C.Envelope encryption — scoping each secret so only the workloads that need it can read it
D.Envelope encryption — encrypting data with a data key that is itself encrypted by a key-encryption key
Answer + AI explanation with Pro
22. What is Least-privilege secret access?
Mid
A.scoping each secret so only the workloads that need it can read it
B.short-lived credentials generated on demand and automatically revoked after use
C.regularly replacing credentials to limit the window of exposure if one leaks
D.credential embedded directly in source code, a frequent leak vector
Answer + AI explanation with Pro
23. Which term means: "scoping each secret so only the workloads that need it can read it"?
Mid
A.Secret scanning
B.Hardware Security Module (HSM)
C.Least-privilege secret access
D.Environment variable secret
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.Least-privilege secret access — credential embedded directly in source code, a frequent leak vector
B.Least-privilege secret access — exchanging a trusted workload identity for short-lived secrets without long-lived keys
C.Least-privilege secret access — scoping each secret so only the workloads that need it can read it
D.Least-privilege secret access — the bootstrapping challenge of securely delivering the first credential to access a secrets store
Answer + AI explanation with Pro
25. What is Hardware Security Module (HSM)?
Senior
A.encrypting data with a data key that is itself encrypted by a key-encryption key
B.automatically detecting committed credentials in repositories and history
C.scoping each secret so only the workloads that need it can read it
D.tamper-resistant device that generates and stores keys and performs crypto operations
Answer + AI explanation with Pro
26. Which term means: "tamper-resistant device that generates and stores keys and performs crypto operations"?
Senior
A.Environment variable secret
B.Secret zero problem
C.Workload identity federation
D.Hardware Security Module (HSM)
Answer + AI explanation with Pro
27. Which statement is correct?
Senior
A.Hardware Security Module (HSM) — credential embedded directly in source code, a frequent leak vector
B.Hardware Security Module (HSM) — tamper-resistant device that generates and stores keys and performs crypto operations
C.Hardware Security Module (HSM) — sensitive credential such as a password, API key, token, or private key
D.Hardware Security Module (HSM) — short-lived credentials generated on demand and automatically revoked after use
Answer + AI explanation with Pro
28. What is Secret zero problem?
Senior
A.regularly replacing credentials to limit the window of exposure if one leaks
B.exchanging a trusted workload identity for short-lived secrets without long-lived keys
C.tamper-resistant device that generates and stores keys and performs crypto operations
D.the bootstrapping challenge of securely delivering the first credential to access a secrets store
Answer + AI explanation with Pro
29. Which term means: "the bootstrapping challenge of securely delivering the first credential to access a secrets store"?
Senior
A.Hardware Security Module (HSM)
B.Secret
C.Least-privilege secret access
D.Secret zero problem
Answer + AI explanation with Pro
30. Which statement is correct?
Senior
A.Secret zero problem — scoping each secret so only the workloads that need it can read it
B.Secret zero problem — tamper-resistant device that generates and stores keys and performs crypto operations
C.Secret zero problem — the bootstrapping challenge of securely delivering the first credential to access a secrets store
D.Secret zero problem — passing a credential to a process via an env var instead of committing it to code
Answer + AI explanation with Pro
Showing 30 of 51 Secrets Management questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Secrets Management question come with Pro.