問題文
A repository was made public by mistake for two hours. Within a day, a database credential that had been written directly into the source of one service was being used from an unfamiliar address. What was missing?
選択肢
- A shorter interval between planned replacements of the credential, so that a copy taken from the source stops working before it can be used.
- Encryption of the repository at rest, because a repository whose contents are unreadable exposes nothing even during the two hours it was public.
- Examination of the source and the build for embedded secrets, so a credential written into the code never reaches a released artifact.
- Protection for the running workload, because a component that observes what a service does would have recognized the use of the credential from an unfamiliar address and refused it, which removes the need to examine the source for what it happens to contain.