nextRound
TechnologiesCoding ProblemsBookmarksLearning PathsLogin
nextRound
TechnologiesCoding ProblemsBookmarksLearning PathsLogin
nextRound

AI-powered interview preparation platform. Practice with curated questions, mock interviews, and personalized learning paths to crack your dream tech interview.

Quick Links

  • Technologies
  • Mock Interviews
  • Saved Questions
  • Pricing

Company

  • About Us
  • Contact Us

Legal

  • Privacy Policy
  • Terms of Use

© 2026 nextRound. All rights reserved.

Questions
1 of 5
1How should sensitive credentials (API keys, passwords) be managed in a Python application rather than hardcoded?
2How can deserializing data with pickle from an untrusted source lead to remote code execution?
3Why is using eval() or exec() on untrusted input a serious security risk?
4What is SQL injection, and how do parameterized queries in Python's database libraries prevent it?
5What risks does using subprocess with shell=True and untrusted input introduce?
PythonPython
Basics
Control Flow and Functions
Data Structures
Comprehensions & Functional Programming
Iterators, Generators & Decorators
Object-Oriented Programming
Exception Handling & Debugging
Concurrency & Parallelism
Performance & Optimization
Testing
Security
Modules, Packaging & Environment
Type Hinting & Modern Python
System Design & Architecture with Python
Best Practices & Design Patterns
Edge Cases & Tricky Interview Questions
01 / 05

How should sensitive credentials (API keys, passwords) be managed in a Python application rather than hardcoded?

Difficulty: 6/10
Credentials, Secrets Management, Environment Variables, Configuration

Use environment variables or a secrets manager, never hardcode credentials in code or config

Hardcoded credentials end up in version control, container images, logs, and error reports. The standard practice is to keep secrets out of the codebase entirely. For local development, read them from environment variables, optionally loaded from a .env file that is gitignored. In production, use a secrets manager such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, or HashiCorp Vault, and have the application fetch the secret at startup or on rotation. Inject secrets as environment variables or mount them as files, and never bake them into images. Use a library like python-dotenv only for local development, not as a production secret store. For generated tokens, use the secrets module rather than random. Add pre-commit hooks and secret scanning to CI to catch accidental commits. Rotate credentials regularly and make rotation automated so it is not an outage risk.

  1. 1

    Environment variables: simple, works with most platforms, but visible to child processes and in some crash dumps.

  2. 2

    Secrets managers: access-controlled, auditable, support rotation. Preferred for production.

  3. 3

    Never commit secrets. Use .gitignore for .env and add secret scanning in CI.

  4. 4

    Use the secrets module for tokens and passwords generated in code.

  5. 5

    Avoid logging secrets. Mask them in logs and error reports.

  6. 6

    Trade-off: environment variables are easy but hard to rotate and easy to leak. Secrets managers add a dependency and startup latency but are auditable.

  7. 7

    Common mistake: storing secrets in a config file that is checked into version control, even if the repo is private.

  8. 8

    Common mistake: using python-dotenv in production, which often means the .env file is deployed alongside the code.

  9. 9

    Version note: the secrets module was added in 3.6. There is no version-specific security requirement beyond that.

Scenario Questions

0-2 years experience

  1. 1Where should you store a database password for a local development environment?
  2. 2Why is committing a .env file to Git a problem?

2-5 years experience

  1. 1You need to deploy a service to production. How do you inject a secret without putting it in the image?
  2. 2A developer accidentally logged an API key. What steps do you take?

5-8 years experience

  1. 1You need to rotate database credentials every 30 days without downtime. How do you design the application to handle rotation?
  2. 2You have multiple environments and teams. How do you structure secret access control and auditing?

8+ years experience

  1. 1Design a secret management architecture for a multi-cloud platform that includes rotation, least privilege, auditing, and emergency revocation.
  2. 2Explain how to detect and prevent secret leakage across code, images, logs, and CI artifacts, and how to respond when a leak occurs.

Follow-up Questions

  • Why is python-dotenv a poor choice for production secret management?
  • How would you implement automatic secret rotation without restarting the service?
Sharethis question

Share via WhatsApp, X, Facebook, LinkedIn or copy link. Open Graph preview enabled.