Bird
Raised Fist0
Terraformcloud~20 mins

Sensitive output values in Terraform - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Sensitive Output Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ service_behavior
intermediate
2:00remaining
What happens when an output is marked as sensitive in Terraform?

Consider this Terraform output configuration:

output "db_password" {
  value     = aws_db_instance.example.password
  sensitive = true
}

What is the effect of setting sensitive = true on this output?

Terraform
output "db_password" {
  value     = aws_db_instance.example.password
  sensitive = true
}
ATerraform will hide the output value in the CLI and state files, preventing it from being displayed or logged.
BTerraform will encrypt the output value automatically in the cloud provider's console.
CTerraform will print the output value in plain text but mark it with a warning.
DTerraform will prevent the output from being used as an input to other modules.
Attempts:
2 left
💡 Hint

Think about what sensitive means for output visibility.

❓ Configuration
intermediate
2:00remaining
Which Terraform output configuration correctly marks a secret as sensitive?

Choose the correct Terraform output block that marks the secret api_key as sensitive.

A
output "api_key" {
  value = var.api_key
  secret = true
}
B
output "api_key" {
  value = var.api_key
  sensitive = false
}
C
output "api_key" {
  value = var.api_key
  sensitive = true
}
D
output "api_key" {
  value = var.api_key
  hidden = true
}
Attempts:
2 left
💡 Hint

Check the exact attribute name Terraform uses for marking outputs sensitive.

❓ Architecture
advanced
2:30remaining
How should sensitive outputs be handled in a multi-team Terraform environment?

You manage Terraform code used by multiple teams. Some outputs contain sensitive data like passwords or keys.

Which approach best protects sensitive outputs while allowing teams to use necessary information?

AStore sensitive outputs in plain text files alongside Terraform code for easy access.
BRemove sensitive outputs from Terraform and share secrets via email to teams.
CMark sensitive outputs as normal outputs and rely on team trust to not share them.
DMark sensitive outputs with <code>sensitive = true</code> and share the Terraform state file only with authorized teams.
Attempts:
2 left
💡 Hint

Think about controlling access to state files and output visibility.

❓ security
advanced
2:30remaining
What is a limitation of marking outputs as sensitive in Terraform?

Consider marking outputs as sensitive in Terraform. Which of the following is a true limitation?

ASensitive outputs cannot be referenced by other modules once marked sensitive.
BSensitive outputs are still stored in plain text inside the Terraform state file unless additional encryption is applied.
CSensitive outputs automatically encrypt data at rest in the cloud provider.
DSensitive outputs prevent Terraform from applying changes to resources.
Attempts:
2 left
💡 Hint

Think about where Terraform stores output values and what sensitive controls.

✅ Best Practice
expert
3:00remaining
Which practice best prevents accidental exposure of sensitive Terraform outputs in CI/CD pipelines?

You run Terraform in a CI/CD pipeline that outputs sensitive values. Which practice best prevents accidental exposure of these sensitive outputs?

AConfigure Terraform outputs as sensitive and avoid printing them in pipeline logs or environment variables.
BPrint all outputs in the pipeline logs but encrypt the logs after the run.
CDisable sensitive output marking and rely on pipeline access controls only.
DStore sensitive outputs in plain text files checked into the pipeline repository.
Attempts:
2 left
💡 Hint

Consider how outputs appear in logs and environment variables during pipeline runs.

Practice

(1/5)
1. What is the main purpose of marking an output as sensitive = true in Terraform?
easy
A. To hide the output value from the standard Terraform output display
B. To make the output value publicly accessible
C. To increase the output value size limit
D. To automatically encrypt the output value in the state file

Solution

  1. Step 1: Understand the role of sensitive outputs

    Marking an output as sensitive hides it from the normal Terraform output display to protect secrets.
  2. Step 2: Clarify what sensitive does not do

    Sensitive does not make outputs public, increase size, or encrypt state automatically.
  3. Final Answer:

    To hide the output value from the standard Terraform output display -> Option A
  4. Quick Check:

    sensitive output hides value [OK]
Hint: Sensitive outputs hide secrets from console output [OK]
Common Mistakes:
  • Thinking sensitive makes output public
  • Assuming sensitive encrypts state file
  • Believing sensitive increases output size
2. Which of the following is the correct syntax to declare a sensitive output in Terraform?
easy
A. output "db_password" { value = var.db_password sensitive = true }
B. output "db_password" { value = var.db_password sensitive = true }
C. output "db_password" { value = var.db_password; sensitive = true }
D. output "db_password" { value = var.db_password, sensitive = true }

Solution

  1. Step 1: Recall Terraform block syntax

    Terraform blocks use new lines or spaces between arguments without semicolons or commas.
  2. Step 2: Identify correct syntax for sensitive output

    The correct syntax places sensitive = true on a new line inside the output block without semicolons or commas.
  3. Final Answer:

    output "db_password" { value = var.db_password sensitive = true } -> Option A
  4. Quick Check:

    Terraform blocks use new lines, no semicolons [OK]
Hint: Terraform blocks use new lines, no semicolons or commas [OK]
Common Mistakes:
  • Using semicolons inside blocks
  • Using commas between arguments
  • Placing sensitive outside the output block
3. Given this Terraform output declaration:
output "api_key" {
  value     = var.api_key
  sensitive = true
}
What will Terraform display when you run terraform output?
medium
A. The actual API key value
B. An error saying output is sensitive
C. No output at all
D. <sensitive> placeholder instead of the value

Solution

  1. Step 1: Understand sensitive output display behavior

    Terraform replaces sensitive output values with <sensitive> to avoid showing secrets.
  2. Step 2: Confirm output command behavior

    Running terraform output shows <sensitive> for sensitive outputs, not the real value or errors.
  3. Final Answer:

    <sensitive> placeholder instead of the value -> Option D
  4. Quick Check:

    sensitive outputs show <sensitive> [OK]
Hint: Sensitive outputs show <sensitive> instead of real value [OK]
Common Mistakes:
  • Expecting actual secret value to display
  • Thinking terraform throws error for sensitive outputs
  • Assuming no output is shown at all
4. You wrote this output block:
output "admin_password" {
  value = var.admin_password
  sensitive = "true"
}
Terraform gives an error. What is the problem?
medium
A. The value attribute cannot reference variables
B. The sensitive attribute must be a boolean, not a string
C. The output name cannot be admin_password
D. Missing a comma between value and sensitive

Solution

  1. Step 1: Check the sensitive attribute type

    The sensitive attribute expects a boolean (true/false), not a string with quotes.
  2. Step 2: Identify the error cause

    Using quotes around true makes it a string, causing Terraform syntax error.
  3. Final Answer:

    The sensitive attribute must be a boolean, not a string -> Option B
  4. Quick Check:

    sensitive = true (no quotes) [OK]
Hint: Boolean values in Terraform have no quotes [OK]
Common Mistakes:
  • Putting quotes around boolean true/false
  • Adding commas inside blocks
  • Misnaming output blocks
5. You want to output a database password securely and also allow other Terraform configurations to access it without exposing it in the console. Which approach is best?
hard
A. Store the password in a public output without sensitive flag
B. Print the password normally in output and rely on user caution
C. Declare output with sensitive = true and use terraform output -json to pass value programmatically
D. Remove the output block and hardcode the password in other configs

Solution

  1. Step 1: Protect password in output

    Marking output as sensitive hides it from console output, preventing accidental exposure.
  2. Step 2: Enable programmatic access

    Using terraform output -json allows other configs or scripts to read the secret safely without showing it on screen.
  3. Final Answer:

    Declare output with sensitive = true and use terraform output -json to pass value programmatically -> Option C
  4. Quick Check:

    Use sensitive output + json output for safe secret sharing [OK]
Hint: Use sensitive output plus JSON output for safe secret sharing [OK]
Common Mistakes:
  • Printing secrets openly in outputs
  • Hardcoding secrets in configs
  • Ignoring sensitive flag for secrets