CompTIA Cloud+ (CV0-004)DevOps FundamentalsHard
Six months after deploying infrastructure using an infrastructure-as-code tool, an administrator suspects that engineers made manual changes directly in the cloud console outside of the normal workflow. Which action should the administrator take first to identify discrepancies between the deployed resources and the code definitions?
- ARun a plan or drift detection command to compare live state
- BRoll back to the previous Git branch immediately
- CRebuild the entire pipeline from scratch
- DRe-clone the version control repository to a new directory
Show answer & explanationAnswer & explanation
Correct answer: A. Run a plan or drift detection command to compare live state
Infrastructure-as-code tools like Terraform offer plan or drift detection commands that compare the actual deployed state against the code definitions, revealing exactly what has diverged before any remediation is attempted. Re-cloning, rolling back, or rebuilding the pipeline are premature actions taken without first confirming what actually changed.
Why the other options are wrong
- B. Rolling back a branch changes code history but doesn't first confirm what drifted in the live environment.
- C. Rebuilding the entire pipeline is an extreme, disruptive step that skips proper diagnosis of the actual drift.
- D. Re-cloning the repository does not reveal anything about the live infrastructure's actual state.
Configuration Drift Detection
The process of comparing the live, running state of infrastructure against its intended definition in code to identify unauthorized or unintended changes.
- Terraform 'plan' command detects drift without applying changes
- Manual console changes are a common cause of drift
- Drift undermines the reliability of infrastructure-as-code
Memory trick: Before fixing anything, play detective and compare the blueprint to the actual building.