Hint: Profile uses AWS CLI stored credentials, not env vars [OK]
Common Mistakes:
Assuming environment variables override profile
Thinking credentials are anonymous
Hardcoding keys inside provider block
4. This Terraform AWS provider configuration causes an error:
provider "aws" {
region = us-east-1
}
What is the cause of the error?
medium
A. The provider block name is missing quotes
B. The provider block is missing a closing brace
C. The equals sign is missing
D. The region value is missing quotes
Solution
Step 1: Check the region value syntax
In HCL, string values must be enclosed in double quotes.
Step 2: Identify the error
The region value us-east-1 is unquoted, causing a syntax error.
Final Answer:
The region value is missing quotes -> Option D
Quick Check:
String values require quotes in Terraform [OK]
Hint: Always quote string values like region names [OK]
Common Mistakes:
Forgetting quotes around strings
Misplacing braces or equals sign
Assuming unquoted strings are valid
5. You want to configure the AWS provider in Terraform to use the region 'eu-central-1' and a profile named 'devuser'. Which configuration is correct and follows best security practices?
hard
A. provider "aws" {
region = "eu-central-1"
profile = "devuser"
access_key = "AKIA..."
secret_key = "secret"
}
B. provider "aws" {
region = "eu-central-1"
profile = "devuser"
}
C. provider "aws" {
region = "eu-central-1"
access_key = "AKIA..."
secret_key = "secret"
}
D. provider "aws" {
region = "eu-central-1"
}
Solution
Step 1: Understand best security practices for AWS credentials
Hardcoding access keys in Terraform files is insecure and discouraged.
Step 2: Use AWS profiles for credential management
Using the 'profile' argument lets Terraform use credentials stored securely in AWS CLI config files.
Step 3: Confirm correct configuration
provider "aws" {
region = "eu-central-1"
profile = "devuser"
} specifies region and profile without hardcoding keys, following best practices.
Final Answer:
provider "aws" {
region = "eu-central-1"
profile = "devuser"
} -> Option B
Quick Check:
Use profiles, avoid hardcoding keys [OK]
Hint: Never hardcode keys; use profiles or env variables [OK]