Cisco CCNA (200-301)Automation and ProgrammabilityHard

A network engineer must decide between using Ansible and Terraform for a new automation project. The project's primary goal is to provision new cloud-based virtual network infrastructure (VPCs, subnets, and virtual routers) and continuously track the desired end-state of that infrastructure across its full lifecycle. Which characteristic makes Terraform particularly well-suited for this specific goal compared to Ansible?

  1. ATerraform can only manage on-premises physical hardware, not cloud resources
  2. BTerraform playbooks are written exclusively in JSON instead of a declarative language
  3. CTerraform requires an agent to be installed on every managed resource
  4. DTerraform maintains a state file that tracks infrastructure resources and detects drift over time
Show answer & explanation

Correct answer: D. Terraform maintains a state file that tracks infrastructure resources and detects drift over time

Terraform is purpose-built for infrastructure provisioning and lifecycle management, using a state file to track the exact resources it created and detect drift from the desired configuration over time. While Ansible is excellent for configuration management and one-time provisioning tasks, it does not natively maintain a persistent state file for ongoing infrastructure lifecycle tracking the way Terraform does.

Why the other options are wrong

  • A. Terraform is widely used for cloud resource provisioning, not limited to on-premises hardware.
  • B. Terraform uses HashiCorp Configuration Language (HCL), a declarative language, not JSON exclusively.
  • C. Terraform is agentless, communicating with providers via APIs, not installed agents.

Terraform vs Ansible for Provisioning

Terraform excels at infrastructure provisioning and lifecycle management via a persistent state file that tracks resources and detects drift, while Ansible focuses on agentless configuration management and orchestration tasks.

  • Terraform: state file tracks infrastructure lifecycle
  • Ansible: agentless, playbook-driven configuration management
  • Both are declarative but serve different primary use cases

Memory trick: Terraform builds and remembers; Ansible configures and moves on.

More Automation and Programmability questions