CertKeen

Terraform Associate (004) · Free practice question 8 of 12

Dynamic provider credentials with OIDC

Security policy at Kittering Bank forbids storing long-lived cloud access keys in HCP Terraform workspace variables. Which HCP Terraform capability lets runs authenticate to the cloud provider without static keys?

  1. A.Sensitive environment variables that store the access keys
  2. B.The cloud block's token argument
  3. C.Dynamic provider credentials, which use workload identity tokens to obtain short-lived credentials for each run
  4. D.Marking the provider block as sensitive
Show answer and explanation

Correct answer: C. Dynamic provider credentials, which use workload identity tokens to obtain short-lived credentials for each run

Why: Dynamic provider credentials use OpenID Connect workload identity tokens issued by HCP Terraform, which the cloud provider exchanges for temporary credentials scoped to each run. Sensitive variables still store long-lived keys, only hidden. The cloud block's token authenticates the CLI to HCP Terraform, not to a cloud provider, and provider blocks have no sensitive setting.

More free Terraform Associate (004) questions