Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HashiCorp Terraform-Associate-004 Exam - Topic 3 Question 10 Discussion

You're building a CI/CD (continuous integration/continuous delivery) pipeline and need to inject sensitive variables into your Terraform run. How can you do this safely?
D) Pass variables to Terraform with a -var flag
A) Copy the sensitive variables into your Terraform code
B) Store the sensitive variables in a secure_varS.tf file
C) Store the sensitive variables as plain text in a source code repository

HashiCorp Terraform-Associate-004 Exam - Topic 3 Question 10 Discussion

Actual exam question for HashiCorp's Terraform-Associate-004 exam
Question #: 10
Topic #: 3
[All Terraform-Associate-004 Questions]

You're building a CI/CD (continuous integration/continuous delivery) pipeline and need to inject sensitive variables into your Terraform run. How can you do this safely?

Show Suggested Answer Hide Answer
Suggested Answer: D

This is a secure way to inject sensitive variables into your Terraform run, as they will not be stored in any file or source code repository. You can also use environment variables or variable files with encryption to pass sensitive variables to Terraform.


Contribute your Thoughts:

0/2000 characters
Jerrod
4 days ago
Definitely B! We need to protect sensitive data at all costs.
upvoted 0 times
...
Clorinda
9 days ago
Storing as plain text? That's just asking for trouble.
upvoted 0 times
...
Jesusita
14 days ago
Copying sensitive variables into the code? That's a big no for me!
upvoted 0 times
...
Eun
19 days ago
Passing variables with -var is okay, but not as secure as B.
upvoted 0 times
...
Elouise
24 days ago
Agreed! A secure_varS.tf file keeps things organized and safe.
upvoted 0 times
...
Wilbert
29 days ago
I think option B is the best choice. Secure storage is key.
upvoted 0 times
...
Derrick
1 month ago
Surprised people still use plain text in repos!
upvoted 0 times
...
Thomasena
1 month ago
I thought plain text was okay for testing?
upvoted 0 times
...
Val
1 month ago
A is a definite no-go!
upvoted 0 times
...
Stephaine
2 months ago
Storing in a secure_varS.tf? Sounds risky.
upvoted 0 times
...
Jill
2 months ago
D is the best option for security!
upvoted 0 times
...
Carol
2 months ago
B sounds like a good compromise, but how secure is it really?
upvoted 0 times
...
Sheron
2 months ago
I thought passing variables with -var was less secure, is it really safe?
upvoted 0 times
...
Tambra
2 months ago
A is definitely a no-go, that's just asking for trouble.
upvoted 0 times
...
Paris
3 months ago
Storing in a secure_varS.tf? Seems risky to me.
upvoted 0 times
...
Shaniqua
3 months ago
D is the best option for security!
upvoted 0 times
...
Ethan
3 months ago
Storing sensitive variables as plain text in a repo is definitely a no-go, so C is out for sure!
upvoted 0 times
...
Annmarie
3 months ago
Passing variables with the -var flag sounds familiar, but I can't recall if it's secure enough for sensitive data.
upvoted 0 times
...
Sina
3 months ago
I think using a secure_varS.tf file could be a good option, but I'm not entirely sure if that's the best practice.
upvoted 0 times
...
Georgene
5 months ago
I remember we discussed how sensitive data shouldn't be hardcoded in Terraform files, so A seems wrong.
upvoted 0 times
...

Save Cancel