Skip to content
CNPA
Platform Observability, Security, and Conformance
medium
Question 6 of 40

A platform team wants to detect secrets accidentally committed to a Git repository before they are pushed to the remote server. Which practice most directly addresses this at the earliest possible point?

ARunning static code analysis only in the CD pipeline after artifacts are built
BUsing pre-commit hooks with a secrets scanning tool to intercept commits locally before they reach the remote
CRotating all secrets on a daily scheduled basis regardless of exposure
DEncrypting all Git commits with GPG signatures to verify author identity

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion