Bird
Raised Fist0
Terraformcloud~20 mins

State file sensitivity and security in Terraform - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Terraform State Security Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
🧠 Conceptual
intermediate
2:00remaining
Why is Terraform state file considered sensitive?

Terraform state files contain information about your infrastructure. Why should you treat these files as sensitive?

ABecause they are encrypted by default and cannot be accessed by anyone.
BBecause they contain plain-text passwords and secrets used in your infrastructure.
CBecause they contain only the list of resource names without any details.
DBecause they store only the Terraform version used, which is sensitive information.
Attempts:
2 left
💡 Hint

Think about what details Terraform needs to track your resources.

❓ Architecture
intermediate
2:00remaining
Best practice for storing Terraform state securely

Which of the following is the best practice for securely storing Terraform state files in a team environment?

AUse a remote backend like AWS S3 with encryption and state locking enabled.
BCommit the state file to a public GitHub repository for easy access.
CStore the state file locally on each developer's machine and share via email when needed.
DStore the state file on an unsecured FTP server for quick access.
Attempts:
2 left
💡 Hint

Think about how to prevent conflicts and protect sensitive data in shared environments.

❓ security
advanced
2:00remaining
What happens if Terraform state file is leaked?

If a Terraform state file containing sensitive resource attributes is leaked publicly, what is the most likely risk?

ATerraform will automatically revoke all credentials in the leaked state file.
BThe leaked state file will cause Terraform to stop working permanently.
CThere is no risk because the state file contains only resource names.
DAttackers can use the leaked information to access or manipulate your cloud resources.
Attempts:
2 left
💡 Hint

Consider what sensitive data the state file might expose.

❓ Configuration
advanced
2:00remaining
Terraform backend configuration for secure state storage

Which Terraform backend configuration snippet correctly enables encryption and state locking for an AWS S3 backend?

A
terraform {
  backend "s3" {
    bucket = "my-terraform-state"
    key    = "state.tfstate"
    region = "us-east-1"
  }
}
B
terraform {
  backend "s3" {
    bucket = "my-terraform-state"
    key    = "state.tfstate"
    region = "us-east-1"
    encrypt = false
    dynamodb_table = "terraform-lock"
  }
}
C
terraform {
  backend "s3" {
    bucket = "my-terraform-state"
    key    = "state.tfstate"
    region = "us-east-1"
    encrypt = true
    dynamodb_table = "terraform-lock"
  }
}
D
terraform {
  backend "s3" {
    bucket = "my-terraform-state"
    key    = "state.tfstate"
    region = "us-east-1"
    encrypt = true
  }
}
Attempts:
2 left
💡 Hint

Encryption and locking require specific settings in the backend block.

❓ service_behavior
expert
2:00remaining
Effect of missing state locking on Terraform operations

What is the most likely outcome if multiple users run Terraform apply simultaneously on the same remote state backend without state locking enabled?

ATerraform operations may corrupt the state file leading to inconsistent infrastructure state.
BTerraform will automatically queue the operations to run one after another safely.
CTerraform will reject all operations except the first one automatically.
DTerraform will create separate state files for each user to avoid conflicts.
Attempts:
2 left
💡 Hint

Think about what happens when multiple people change the same file at the same time without coordination.

Practice

(1/5)
1. What is the main reason to keep the Terraform state file secure?
easy
A. It holds your Terraform installation files
B. It stores your Terraform version history
C. It contains sensitive information about your cloud resources
D. It contains your Terraform provider plugins

Solution

  1. Step 1: Understand the role of the state file

    The Terraform state file records details about your cloud resources, including IDs and configurations.
  2. Step 2: Identify sensitive content in the state file

    Because it stores resource details, it may include secrets or private data that must be protected.
  3. Final Answer:

    It contains sensitive information about your cloud resources -> Option C
  4. Quick Check:

    State file holds sensitive info = A [OK]
Hint: State file stores resource info, so protect it [OK]
Common Mistakes:
  • Thinking state file stores Terraform software files
  • Confusing state file with version control
  • Assuming state file only has public info
2. Which Terraform configuration snippet correctly marks a variable as sensitive?
easy
A. variable "password" { type = sensitive }
B. variable "password" { hidden = true }
C. variable "password" { secret = true }
D. variable "password" { sensitive = true }

Solution

  1. Step 1: Recall Terraform variable syntax for sensitivity

    Terraform uses the attribute sensitive = true inside variable blocks to mark secrets.
  2. Step 2: Check each option's correctness

    Only variable "password" { sensitive = true } uses the correct attribute sensitive = true. Others use invalid or unsupported attributes.
  3. Final Answer:

    variable "password" { sensitive = true } -> Option D
  4. Quick Check:

    sensitive = true marks secrets = B [OK]
Hint: Use sensitive = true inside variable block [OK]
Common Mistakes:
  • Using 'type = sensitive' instead of 'sensitive = true'
  • Using 'secret' or 'hidden' which are invalid
  • Omitting the sensitive attribute
3. Given this Terraform output block:
output "db_password" {
  value     = var.db_password
  sensitive = true
}
What will happen when you run terraform apply?
medium
A. The password will be hidden in the output and logs
B. The password will be shown in the output after apply
C. Terraform will throw a syntax error
D. The password will be stored in plain text in the state file

Solution

  1. Step 1: Understand the effect of sensitive output

    Marking an output as sensitive = true hides its value from CLI output and logs.
  2. Step 2: Check if syntax is correct and state file behavior

    The syntax is valid, so no error occurs. The value is still stored in the state file but hidden from output.
  3. Final Answer:

    The password will be hidden in the output and logs -> Option A
  4. Quick Check:

    sensitive output hides value in CLI = A [OK]
Hint: sensitive output hides value from CLI, not state file [OK]
Common Mistakes:
  • Thinking sensitive outputs cause syntax errors
  • Assuming sensitive outputs are not stored in state
  • Expecting sensitive outputs to show in CLI
4. You accidentally committed your Terraform state file with secrets to a public GitHub repo. What is the best immediate action to secure your infrastructure?
medium
A. Remove the state file from GitHub and continue as usual
B. Rotate all secrets and credentials stored in the state file
C. Change the Terraform version to encrypt the state file automatically
D. Delete the GitHub repo and do nothing else

Solution

  1. Step 1: Understand the risk of leaked secrets

    Once secrets are public, they can be compromised, so immediate rotation is needed.
  2. Step 2: Evaluate other options

    Deleting repo or removing files does not guarantee secrets are safe. Changing Terraform version does not fix leaked secrets.
  3. Final Answer:

    Rotate all secrets and credentials stored in the state file -> Option B
  4. Quick Check:

    Leaked secrets require rotation = D [OK]
Hint: Rotate secrets immediately if state file leaks [OK]
Common Mistakes:
  • Thinking deleting repo removes leaked secrets
  • Assuming Terraform version change encrypts old state
  • Ignoring secret rotation after leak
5. You want to securely store your Terraform state file remotely with encryption and access control. Which setup is the best practice?
hard
A. Use a remote backend like AWS S3 with server-side encryption and IAM policies
B. Store the state file locally and encrypt it manually with a password
C. Commit the state file to a private Git repository with limited access
D. Use Terraform Cloud free tier without enabling state encryption

Solution

  1. Step 1: Identify secure remote state storage options

    Using a remote backend like AWS S3 with encryption and access control protects the state file effectively.
  2. Step 2: Compare other options

    Local storage with manual encryption is error-prone. Private Git repos are not designed for state files. Terraform Cloud free tier may not encrypt state by default.
  3. Final Answer:

    Use a remote backend like AWS S3 with server-side encryption and IAM policies -> Option A
  4. Quick Check:

    Remote backend with encryption = C [OK]
Hint: Use remote backend with encryption and access control [OK]
Common Mistakes:
  • Relying on local manual encryption
  • Storing state in Git repos
  • Assuming free tiers always encrypt state