Terraform Associate (004) · Free practice question 5 of 12
Self-hosted agents for private networks
Infrastructure at Moravia Grain sits in a private data center that HCP Terraform's hosted workers cannot reach. The team still wants runs managed by HCP Terraform. What should they use?
- A.HCP Terraform agents installed inside the private network, with the workspace set to agent execution mode
- B.Local execution mode with the state stored in the data center
- C.A public IP address on every private server
- D.The terraform_remote_state data source pointing at the data center
Show answer and explanation
Correct answer: A. HCP Terraform agents installed inside the private network, with the workspace set to agent execution mode
Why: HCP Terraform agents run inside the private network and make outbound connections to HCP Terraform to pick up work, so runs can reach private infrastructure without opening inbound access. Local execution moves runs off HCP Terraform entirely. Exposing servers publicly is a security risk, and remote state data sources only read outputs.
More free Terraform Associate (004) questions
- Skipping refresh during plan
- Local state backup file
- Default CLI workspace cannot be deleted
- Local execution mode in HCP Terraform
- Run triggers between workspaces
- Health assessments for drift detection
- Dynamic provider credentials with OIDC
- terraform_data triggers_replace argument
- Provisioners as a last resort
- Running tests with terraform test
- Lock file hashes for multiple platforms