Terraform replaces sensitive output values with <sensitive> to avoid showing secrets.
Step 2: Confirm output command behavior
Running terraform output shows <sensitive> for sensitive outputs, not the real value or errors.
Final Answer:
<sensitive> placeholder instead of the value -> Option D
Quick Check:
sensitive outputs show <sensitive> [OK]
Hint: Sensitive outputs show <sensitive> instead of real value [OK]
Common Mistakes:
Expecting actual secret value to display
Thinking terraform throws error for sensitive outputs
Assuming no output is shown at all
4. You wrote this output block:
output "admin_password" {
value = var.admin_password
sensitive = "true"
}
Terraform gives an error. What is the problem?
medium
A. The value attribute cannot reference variables
B. The sensitive attribute must be a boolean, not a string
C. The output name cannot be admin_password
D. Missing a comma between value and sensitive
Solution
Step 1: Check the sensitive attribute type
The sensitive attribute expects a boolean (true/false), not a string with quotes.
Step 2: Identify the error cause
Using quotes around true makes it a string, causing Terraform syntax error.
Final Answer:
The sensitive attribute must be a boolean, not a string -> Option B
Quick Check:
sensitive = true (no quotes) [OK]
Hint: Boolean values in Terraform have no quotes [OK]
Common Mistakes:
Putting quotes around boolean true/false
Adding commas inside blocks
Misnaming output blocks
5. You want to output a database password securely and also allow other Terraform configurations to access it without exposing it in the console. Which approach is best?
hard
A. Store the password in a public output without sensitive flag
B. Print the password normally in output and rely on user caution
C. Declare output with sensitive = true and use terraform output -json to pass value programmatically
D. Remove the output block and hardcode the password in other configs
Solution
Step 1: Protect password in output
Marking output as sensitive hides it from console output, preventing accidental exposure.
Step 2: Enable programmatic access
Using terraform output -json allows other configs or scripts to read the secret safely without showing it on screen.
Final Answer:
Declare output with sensitive = true and use terraform output -json to pass value programmatically -> Option C
Quick Check:
Use sensitive output + json output for safe secret sharing [OK]
Hint: Use sensitive output plus JSON output for safe secret sharing [OK]