🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your company is moving its Terraform workflows to Google Cloud. Several engineers in different regions will run terraform apply against the same infrastructure code. Security mandates that the state file must be encrypted at rest, previous versions must be recoverable if someone deletes or corrupts the file, and simultaneous runs must not corrupt the state. Which approach best satisfies all requirements with minimal operational overhead?

  • Store the state file as a secret in Secret Manager, keep using the local backend, and grant engineers Secret Manager access via IAM.

  • Create a regional Cloud Storage bucket dedicated to Terraform state, enable object versioning and a locked retention policy, enforce uniform bucket-level access, and configure the Terraform gcs backend to use this bucket.

  • Keep the local backend and commit the state file to Cloud Source Repositories after every apply so that Git history preserves older versions.

  • Provision a Filestore share mounted over VPN from engineer laptops and point the Terraform local backend path to that shared directory.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot