Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

Application Security: Secrets, Encryption, Data Handling

Three application-security topics the CCNAAUTO 200-901 4.8 exam asks you to describe: protecting secrets (API keys, tokens), encryption at rest and in transit, and data handling practices.

Quick summary
  • Secrets (API keys, passwords, tokens) belong in a secret manager or environment variables, never in Git.
  • Encryption in transit = TLS (HTTPS). Encryption at rest = disk or DB encryption. Both, always, in production.
  • Data handling = minimise what you store, encrypt what you must store, mask sensitive fields in logs, delete when no longer needed.

Mental model

Cisco objective 4.8 says “Describe application security issues related to secret protection, encryption (storage and transport), and data handling”. Three overlapping topics; each is a chapter in a real book, but you need the one-page version.

1. Secret protection

What is a secret

Anything that proves identity or permission: API keys, passwords, database connection strings, SSH private keys, signing keys, access tokens.

How secrets leak

  • Hardcoded in source code, then pushed to Git. Bots scan GitHub for leaked tokens within minutes.
  • Logged by accident (“about to call API with token=eyJhbGci…”). Logs end up in SIEM / S3 / vendor support cases.
  • Shared in Slack, email, Jira tickets.
  • In an image baked into a Docker image or AMI.
  • Dumped in config files on disk with world-readable permissions.

Where secrets belong

WhereGood for
Environment variables ($MERAKI_API_KEY) injected by the OS or orchestratorContainer deployments, CI/CD
.env file in .gitignoreLocal dev. Never commit.
Secret manager (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, Cisco Vault via NSO)Production, multi-service
Secrets Store CSI driverKubernetes workloads

Three rules

  1. Never commit a secret to a repo. Add .env, *.pem, *.key to .gitignore from day one.
  2. Rotate on any suspicion of leak. Treat the compromised secret as burned.
  3. Use the shortest-lived credential your workflow allows (OAuth2 tokens over API keys when possible).

2. Encryption

Two scopes:

In transit

Any data moving over a network must be encrypted. Modern baseline: TLS 1.2+ on every API, every management interface, every backup copy.

  • HTTPS instead of HTTP.
  • SSH instead of Telnet.
  • NETCONF (over SSH) instead of SNMP v1/v2c (plain-text).
  • SNMPv3 if you must do SNMP.

At rest

Data sitting on disk must be encrypted too.

  • Full-disk encryption on servers (dm-crypt / LUKS, BitLocker, FileVault).
  • Database-level encryption (TDE in Oracle/SQL Server/Postgres).
  • Object storage: enable server-side encryption on your S3 / GCS buckets.
  • Backups: encrypted before leaving the source.

Keys

Encryption is only as strong as key management. Keys live in an HSM (hardware security module) or a cloud KMS (AWS KMS, Azure Key Vault, GCP KMS). Rotate keys periodically.

3. Data handling

Beyond “encrypt everything” there are practical day-to-day habits.

Minimise

Only collect data you actually need. Fewer fields → smaller breach impact. The record you never collected is the one that cannot leak.

Mask / redact

Logs are indexed, shared, and shipped off-box. Mask or redact sensitive fields BEFORE they are logged:

log.info(f"API call to {url} with token={token[:4]}***")

Not:

log.info(f"API call to {url} with token={token}")

Separate

Keep PII (personally identifiable info) in a dedicated table/service with stricter access. Everything else can be less protected.

Delete

Have a retention policy. “Keep forever” is a liability. GDPR, CCPA, and sector regulations (HIPAA, PCI-DSS) impose maximum retention periods.

Validate on input

Reject or sanitise untrusted input at the earliest possible layer. See OWASP top threats for XSS, SQLi, CSRF.

Common anti-patterns to call out in a code review

  • Secret in requirements.txt, settings.py, terraform.tfvars.
  • Hardcoded TLS verify=False to “make it work” (ignores every cert error, including attacker’s).
  • Logging HTTP request/response bodies without redaction.
  • Email of PII in Jira tickets or Slack.
  • Backups copied to a bucket with no encryption and world-read.
  • Shared service account with everyone’s password written on a sticky note.

FAQ

What if my team uses a shared vault spreadsheet? Replace with a proper secret manager this quarter. Even a free-tier HashiCorp Vault or Bitwarden is miles better than a shared doc.

Is ‘rotate every 90 days’ still recommended for passwords? For human user passwords, NIST 800-63B says no — only rotate on evidence of compromise. For machine credentials and API keys, periodic rotation (quarterly) is still standard.

My cert expired and now TLS fails. Should I verify=False to buy time? No. Renew the cert. verify=False in production disables the entire security story.

What does “encryption at rest” mean for a Cisco switch? The running config on the switch is in memory; copies on flash can be encrypted (depends on model). Backup configs stored on a central server must be encrypted there.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Application Security: Secrets, Encryption, Data Handling. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Application Security: Secrets, Encryption, Data Handling fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.