Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is a Terraform state file?
A Terraform state file is a file that keeps track of the resources Terraform manages. It stores information about the infrastructure's current state so Terraform knows what to create, update, or delete.
Click to reveal answer
beginner
Why is the Terraform state file sensitive?
The state file contains detailed information about your infrastructure, including resource IDs, IP addresses, and sometimes secrets or passwords. If exposed, it can lead to security risks.
Click to reveal answer
intermediate
Name one best practice to secure Terraform state files.
Store the state file remotely in a secure backend like AWS S3 with encryption and access controls, instead of keeping it locally on your computer.
Click to reveal answer
intermediate
What is Terraform remote state locking and why is it important?
Remote state locking prevents multiple people from changing the state file at the same time. This avoids conflicts and corruption of the state file.
Click to reveal answer
advanced
How can you avoid storing sensitive data in the Terraform state file?
Use Terraform's sensitive variables feature and avoid outputting secrets. Also, use external secret managers to keep secrets outside the state file.
Click to reveal answer
What does the Terraform state file primarily store?
ACurrent infrastructure resource information
BTerraform source code
CUser login credentials
DCloud provider billing details
✗ Incorrect
The state file stores information about the current infrastructure resources Terraform manages.
Why should Terraform state files be stored securely?
AThey are very large files
BThey contain Terraform version info
CThey contain sensitive infrastructure details
DThey are only used for logging
✗ Incorrect
State files contain sensitive details like resource IDs and sometimes secrets, so securing them is important.
Which backend is recommended for storing Terraform state securely?
ALocal disk without encryption
BRemote backend with encryption and access control
CPublic GitHub repository
DTemporary cloud storage without access control
✗ Incorrect
Using a remote backend with encryption and access control protects the state file from unauthorized access.
What problem does remote state locking solve?
APrevents multiple users from editing state simultaneously
BEncrypts the state file
CBacks up the state file automatically
DImproves Terraform execution speed
✗ Incorrect
Remote state locking prevents concurrent edits that could corrupt the state file.
How can you keep secrets out of the Terraform state file?
AIgnore the state file in version control
BStore secrets in plain text variables
COutput secrets in Terraform outputs
DUse sensitive variables and external secret managers
✗ Incorrect
Using sensitive variables and external secret managers keeps secrets out of the state file.
Explain why Terraform state files are sensitive and how you can protect them.
Think about what info the state file holds and how to keep it safe.
You got /5 concepts.
Describe best practices to avoid exposing sensitive data in Terraform state files.
Focus on how to handle secrets and state storage.
You got /5 concepts.
Practice
(1/5)
1. What is the main reason to keep the Terraform state file secure?
easy
A. It holds your Terraform installation files
B. It stores your Terraform version history
C. It contains sensitive information about your cloud resources
D. It contains your Terraform provider plugins
Solution
Step 1: Understand the role of the state file
The Terraform state file records details about your cloud resources, including IDs and configurations.
Step 2: Identify sensitive content in the state file
Because it stores resource details, it may include secrets or private data that must be protected.
Final Answer:
It contains sensitive information about your cloud resources -> Option C
Quick Check:
State file holds sensitive info = A [OK]
Hint: State file stores resource info, so protect it [OK]
Common Mistakes:
Thinking state file stores Terraform software files
Confusing state file with version control
Assuming state file only has public info
2. Which Terraform configuration snippet correctly marks a variable as sensitive?
easy
A. variable "password" { type = sensitive }
B. variable "password" { hidden = true }
C. variable "password" { secret = true }
D. variable "password" { sensitive = true }
Solution
Step 1: Recall Terraform variable syntax for sensitivity
Terraform uses the attribute sensitive = true inside variable blocks to mark secrets.
Step 2: Check each option's correctness
Only variable "password" { sensitive = true } uses the correct attribute sensitive = true. Others use invalid or unsupported attributes.
Final Answer:
variable "password" { sensitive = true } -> Option D
Quick Check:
sensitive = true marks secrets = B [OK]
Hint: Use sensitive = true inside variable block [OK]
Common Mistakes:
Using 'type = sensitive' instead of 'sensitive = true'
Using 'secret' or 'hidden' which are invalid
Omitting the sensitive attribute
3. Given this Terraform output block:
output "db_password" {
value = var.db_password
sensitive = true
}
What will happen when you run terraform apply?
medium
A. The password will be hidden in the output and logs
B. The password will be shown in the output after apply
C. Terraform will throw a syntax error
D. The password will be stored in plain text in the state file
Solution
Step 1: Understand the effect of sensitive output
Marking an output as sensitive = true hides its value from CLI output and logs.
Step 2: Check if syntax is correct and state file behavior
The syntax is valid, so no error occurs. The value is still stored in the state file but hidden from output.
Final Answer:
The password will be hidden in the output and logs -> Option A
Quick Check:
sensitive output hides value in CLI = A [OK]
Hint: sensitive output hides value from CLI, not state file [OK]
Common Mistakes:
Thinking sensitive outputs cause syntax errors
Assuming sensitive outputs are not stored in state
Expecting sensitive outputs to show in CLI
4. You accidentally committed your Terraform state file with secrets to a public GitHub repo. What is the best immediate action to secure your infrastructure?
medium
A. Remove the state file from GitHub and continue as usual
B. Rotate all secrets and credentials stored in the state file
C. Change the Terraform version to encrypt the state file automatically
D. Delete the GitHub repo and do nothing else
Solution
Step 1: Understand the risk of leaked secrets
Once secrets are public, they can be compromised, so immediate rotation is needed.
Step 2: Evaluate other options
Deleting repo or removing files does not guarantee secrets are safe. Changing Terraform version does not fix leaked secrets.
Final Answer:
Rotate all secrets and credentials stored in the state file -> Option B
Quick Check:
Leaked secrets require rotation = D [OK]
Hint: Rotate secrets immediately if state file leaks [OK]
Common Mistakes:
Thinking deleting repo removes leaked secrets
Assuming Terraform version change encrypts old state
Ignoring secret rotation after leak
5. You want to securely store your Terraform state file remotely with encryption and access control. Which setup is the best practice?
hard
A. Use a remote backend like AWS S3 with server-side encryption and IAM policies
B. Store the state file locally and encrypt it manually with a password
C. Commit the state file to a private Git repository with limited access
D. Use Terraform Cloud free tier without enabling state encryption
Solution
Step 1: Identify secure remote state storage options
Using a remote backend like AWS S3 with encryption and access control protects the state file effectively.
Step 2: Compare other options
Local storage with manual encryption is error-prone. Private Git repos are not designed for state files. Terraform Cloud free tier may not encrypt state by default.
Final Answer:
Use a remote backend like AWS S3 with server-side encryption and IAM policies -> Option A
Quick Check:
Remote backend with encryption = C [OK]
Hint: Use remote backend with encryption and access control [OK]