# Revision: Cheat Sheet and Self-Check — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/rot-revision

> Review the habits, commands and common interview questions from the whole course.

## Cheat sheet

**Never** commit or paste secrets. **Store** them in a manager with a strong master password, Secret Key and MFA or passkeys. **Share** by vault and group with least privilege. **Use** them through `op run` or `op inject`. **Scan** before pushing. **Rotate** on schedule and on any leak, revoking before cleaning history.

## Questions interviewers ask

Be ready to explain: why deleting a committed secret is not enough, how `op run` avoids writing secrets to disk, why passkeys resist phishing, what least privilege means for vaults, and the order of steps when a key leaks.

**Quiz:** A teammate asks for the staging API key in chat. What is the best reply?

- [ ] Paste it, it is only staging
- [x] Add them to the staging vault with the right permission
- [ ] Email it
- [ ] Tell them to guess

*Answer:* Add them to the staging vault with the right permission. Granting vault access is auditable and revocable; a pasted key is neither.

**Quiz:** Which command runs an app with secrets injected only into its environment?

- [ ] op signout
- [ ] op vault list
- [ ] git filter-repo
- [x] op run --env-file=.env.1p -- <command>

*Answer:* op run --env-file=.env.1p -- <command>. `op run` resolves references for that process without writing a plaintext file.

**Quiz:** What is the correct order after a key leaks publicly?

- [ ] Clean history, then think about the key
- [x] Revoke or rotate, redeploy, check logs, then clean up
- [ ] Delete the repo, then forget it
- [ ] Wait one week

*Answer:* Revoke or rotate, redeploy, check logs, then clean up. Stopping misuse comes first; cleanup is secondary.
