Your team manages GCP resources with Terraform Cloud and wants the most secure authentication with minimal config changes. How should Terraform authenticate to Google Cloud APIs?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Terraform Cloud to use Workload Identity Federation to authenticate to Google Cloud APIs..
Why this is the answer
Workload Identity Federation is the most secure and recommended method for Terraform Cloud to authenticate to Google Cloud. It allows Terraform Cloud to directly impersonate a Google service account without needing to download or manage service account keys, which significantly reduces security risks. This approach aligns with the principle of least privilege and eliminates the need for long-lived credentials. Running Terraform on GKE or a Compute Engine VM would involve managing additional infrastructure, which isn't the most direct or minimal configuration change for Terraform Cloud itself. Uploading a JSON key is less secure because it involves managing a long-lived credential that could be compromised.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed