Q: 7
An analyst is asked to retrieve an API client secret from a previously generated key. How can they
achieve this?
Options
Discussion
Option D you can't get the client secret again after creation. That's standard for most APIs to protect credentials.
Probably D since most platforms only show client secrets once when they're generated. It's a security thing, so you have to generate a new secret if you lose it. I've seen similar behavior in AWS and Azure too. Anyone seen one allow option A or B in real life?
Yeah, D. Can't view the secret again after it's created.
Option D but not 100 percent sure if all platforms behave that way.
Its D, secret's only shown once. No way to get it back after that.
A , some UIs look like they’ll show secrets in pop-ups (trap option), so I’d have picked A. Guessing the analyst can just re-open edit to get it again, but maybe I’m missing something here.
Be respectful. No spam.
Question 7 of 35