Terraform Associate (004) · Free practice question 8 of 12
Dynamic provider credentials with OIDC
Security policy at Kittering Bank forbids storing long-lived cloud access keys in HCP Terraform workspace variables. Which HCP Terraform capability lets runs authenticate to the cloud provider without static keys?
- A.Sensitive environment variables that store the access keys
- B.The cloud block's token argument
- C.Dynamic provider credentials, which use workload identity tokens to obtain short-lived credentials for each run
- D.Marking the provider block as sensitive
Show answer and explanation
Correct answer: C. Dynamic provider credentials, which use workload identity tokens to obtain short-lived credentials for each run
Why: Dynamic provider credentials use OpenID Connect workload identity tokens issued by HCP Terraform, which the cloud provider exchanges for temporary credentials scoped to each run. Sensitive variables still store long-lived keys, only hidden. The cloud block's token authenticates the CLI to HCP Terraform, not to a cloud provider, and provider blocks have no sensitive setting.
More free Terraform Associate (004) questions
- Skipping refresh during plan
- Local state backup file
- Default CLI workspace cannot be deleted
- Local execution mode in HCP Terraform
- Self-hosted agents for private networks
- Run triggers between workspaces
- Health assessments for drift detection
- terraform_data triggers_replace argument
- Provisioners as a last resort
- Running tests with terraform test
- Lock file hashes for multiple platforms