Easy Security Question 60 of 226

Why should secrets never be committed to Git?

MERN Full Stack · Speak this in 60–90 seconds · Faridabad & Delhi NCR

PICTURE THIS: DATABASE INDEX

Without indexScan every row
With indexJump to keys
CostWrites slower

Simple meaning

API keys, database URIs, and JWT secrets in Git history can be cloned or leaked forever.

1

WHY — Security instead of guessing?

Why interviewers care about Security:

They are checking judgment

on Security.

A good answer names

the situation, the default choice, and one exception - that reads as experience.

Stay structured

Name the idea, why it exists, then one short example.

Close cleanly

End with when you use it and one common pitfall.

2

STEPS — What happens step by step?

Before you speak the answer, walk the interviewer through these steps:

  1. 1
    API keys, database URIs,

    and JWT secrets in Git history can be cloned or leaked forever.

  2. 2
    Use a local .env

    file and host env vars or a secret manager in production.

  3. 3
    If a secret is

    committed, rotate it

  4. 4
    deleting the file does

    not erase history.

  5. 5
    Common mistake

    What juniors usually get wrong.

  6. 6
    Close

    When you pick this over the alternative.

3

EXAMPLE — See it in action

Here's a short line you can speak, broken into clear beats:

Say this line
“Use a local .env file and host env vars or a secret manager in production.”
Break into beats
Usealocalenvfileand
Speaking order
2987408337471632900

Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.

Key takeaway

API keys, database URIs, and JWT secrets in Git history can be cloned or leaked forever. Use a local .env file and host env vars or a secret manager in production.

Chat with us