Which two statements accurately describe the difference between declarative and imperative IaC approaches? (Choose two.)
Declarative IaC defines the target end state and lets the tool determine execution, whereas imperative IaC encodes explicit sequential commands. This outcome-versus-steps axis is the defining distinction between the two approaches, directly matching the question's requirement.
Why this answer
Option C is correct because declarative IaC (e.g., Terraform HCL, CloudFormation templates) defines the desired end state of the infrastructure and lets the tool determine the execution path, whereas imperative IaC (e.g., shell scripts, AWS CLI command sequences) explicitly lists the ordered commands needed to reach that state. Option D is correct because imperative approaches execute fixed steps without inherently reconciling actual versus desired state, so re-running or partially failing scripts can leave resources in unintended configurations, producing configuration drift. Option A is wrong because imperative techniques are widely used in IaC, such as provisioning with AWS CLI or Ansible ad-hoc commands.
Option B is wrong because speed depends on implementation, provider APIs, and parallelism, not on whether the approach is declarative or imperative. Option E is wrong because declarative tools still rely on idempotency mechanisms (state files, resource providers, or reconciliation loops) to avoid duplicate changes; declarative syntax alone does not eliminate the need for idempotent behavior.
Exam trap
HashiCorp often tests the misconception that declarative IaC eliminates the need for idempotency, but in reality, declarative tools enforce idempotency through state management and plan generation, making it a key feature rather than an omission.