Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free HashiCorp Certified: Terraform Associate (004) Terraform-Associate-004 Exam Questions

Page: 1 / 26 Total 385 questions

Want more questions? Get Premium Access.

Question 1

One cloud block always maps to a single HCP Terraform/Terraform Cloud workspace.

Correct Answer: A. True
Explanation:

Rationale for Correct Answer (True):

A cloud block in Terraform configuration specifies a single Terraform Cloud or HCP Terraform workspace. You cannot use one cloud block for multiple workspaces.

Analysis of Incorrect Option:

False: Incorrect because a cloud block is a one-to-one mapping with a single workspace.

Key Concept:

Cloud blocks manage remote operations and backend configuration tied to one workspace.


Terraform Exam Objective -- Manage Terraform Workspaces and Cloud.

Question 2

Which task does terraform init not perform?

Correct Answer: A. Validates all required variables are present
Explanation:

The terraform init command is used to initialize a working directory containing Terraform configuration files. This command performs several different initialization steps to prepare the current working directory for use with Terraform, which includes initializing the backend, installing provider plugins, and copying any modules referenced in the configuration. However, it does not validate whether all required variables are present; that is a task performed by terraform plan or terraform apply1.

Reference = This information can be verified from the official Terraform documentation on the terraform init command provided by HashiCorp Developer1.


Question 3

When should you use the force-unlock command?

Correct Answer: B. Automatic unlocking failed
Explanation:

You should use the force-unlock command when automatic unlocking failed. Terraform will lock your state for all operations that could write state, such as plan, apply, or destroy. This prevents others from acquiring the lock and potentially corrupting your state. State locking happens automatically on all operations that could write state and you won't see any message that it is happening. If state locking fails, Terraform will not continue. You can disable state locking for most commands with the -lock flag but it is not recommended. If acquiring the lock is taking longer than expected, Terraform will output a status message. If Terraform doesn't output a message, state locking is still occurring if your backend supports it. Terraform has a force-unlock command to manually unlock the state if unlocking failed. Be very careful with this command. If you unlock the state when someone else is holding the lock it could cause multiple writers. Force unlock should only be used to unlock your own lock in the situation where automatic unlocking failed. To protect you, the force-unlock command requires a unique lock ID. Terraform will output this lock ID if unlocking fails. This lock ID acts as a nonce, ensuring that locks and unlocks target the correct lock. The other situations are not valid reasons to use the force-unlock command. You should not use the force-unlock command if you have a high priority change, if apply failed due to a state lock, or if you see a status message that you cannot acquire the lock. These situations indicate that someone else is holding the lock and you should wait for them to finish theiroperation or contact them to resolve the issue. Using the force-unlock command in these cases could result in data loss or inconsistency.Reference= [State Locking], [Command: force-unlock]


Question 4

Your team adopts AWS CloudFormation as the standardized method for provisioning public cloud resources. Which scenario presents a challenge for your team?

Correct Answer: D. Deploying new infrastructure into Microsoft Azure.
Explanation:

Rationale for Correct Answer: AWS CloudFormation is AWS-specific. If your standardized

provisioning tool is CloudFormation, deploying infrastructure into Microsoft Azure becomes a challenge because CloudFormation does not natively provision Azure resources. This highlights a core IaC concept: tool/platform scope and portability across clouds.

Analysis of Incorrect Options (Distractors):

A (Reusable code base for any AWS region): CloudFormation templates are commonly reusable across AWS regions; region differences are typically handled via parameters, mappings, and region-specific resource availability---not a fundamental challenge.

B (Managing a new stack on AWS-native services): This is CloudFormation's strength: managing AWS-native services with declarative templates and stack updates.

C (Automating manual console provisioning): Another core use case for IaC---CloudFormation is designed to replace manual provisioning with repeatable automation.

Key Concept: IaC tool scope and portability---AWS CloudFormation is tightly coupled to AWS, limiting multi-cloud provisioning.


Question 5

A developer accidentally launched a VM (virtual machine) outside of the Terraform workflow and ended up with two servers with the same name. They don't know which VM Terraform manages but do have a list of all active VM IDs.

Which of the following methods could you use to discover which instance Terraform manages?

Correct Answer: A. Run terraform state list to find the names of all VMs, then run terraform state show for each of them to find which VM ID Terraform manages
Explanation:

The terraform state list command lists all resources that are managed by Terraform in the current state file1.The terraform state show command shows the attributes of a single resource in the state file2. By using these two commands, you can compare the VM IDs in your list with the ones in the state file and identify which one is managed by Terraform.


Question 6

A senior admin accidentally deleted some of your cloud instances. What will Terraform do when you run terraform apply?

Correct Answer: C. Rebuild only the instances that were deleted.
Explanation:

Terraform detects infrastructure drift by comparing thestate filewith the actual infrastructure.

When an instance ismanually deleted, Terraformsees it as missingand marks it for recreation.

Running terraform apply willonly recreate the missing instanceswhile leaving the rest of the infrastructure unchanged.

Explanation of incorrect answers:

A (Tear down everything and rebuild)-- Incorrect. Terraform does not destroy existing infrastructure unless explicitly told to.

B (Build a completely new set of infrastructure)-- Incorrect. Terraform does not create duplicates unless configuration changes.

D (Stop and error out)-- Incorrect. Terraform does not fail; itrebuilds missing resourcesautomatically.

Official Terraform Documentation Reference:

Handling Infrastructure Drift


Question 7

Your configuration contains a module block that references a module from the Terraform Registry and sets the version argument to 1.0. You just published a new version of the module and updated your configuration to point to version 1.1.

Which command must be run to install the new version?

Correct Answer: A. terraform init
Explanation:

Detailed

Rationale for Correct Answe r: terraform init installs and updates modules used by a Terraform configuration. After changing a module version constraint or version number, you must run terraform init so Terraform downloads the selected module version.

Analysis of Incorrect Options (Distractors):

B . terraform modules. Incorrect. There is no standard Terraform CLI command named terraform modules.

C . terraform plan. Incorrect. plan creates an execution plan but does not install updated module packages.

D . terraform apply. Incorrect. apply applies planned infrastructure changes, but module installation must be handled during initialization first.

Key Concept: Terraform modules are installed and updated during initialization.


Question 8

If a DevOps team adopts AWS CloudFormation as their standardized method for provisioning public cloud resoruces, which of the following scenarios poses a challenge for this team?

Correct Answer: B. The organization decides to expand into Azure wishes to deploy new infrastructure
Explanation:

This is the scenario that poses a challenge for this team, if they adopt AWS CloudFormation as their standardized method for provisioning public cloud resources, as CloudFormation only supports AWS services and resources, and cannot be used to provision infrastructure on other cloud platforms such as Azure.


Question 9

Which of the following does terraform apply change after you approve the execution plan? (Choose two.)

Correct Answer: A. Cloud infrastructure; D. State file
Explanation:

Theterraform applycommand changes both the cloud infrastructure and the state file after you approve the execution plan. The command creates, updates, or destroys the infrastructure resources to match theconfiguration. It also updates the state file to reflect the new state of the infrastructure. The.terraformdirectory, the execution plan, and the Terraform code are not changed by theterraform applycommand.Reference=Command: applyandPurpose of Terraform State


Question 10

You manage two workspaces in your HCP Terraform organization. The first workspace manages your network configuration. The second workspace manages your compute resources and retrieves values from the networking workspace.

What HCP Terraform feature lets you run an apply operation on the compute workspace every time you update the networking workspace?

Correct Answer: A. Run triggers
Explanation:

Detailed

Rationale for Correct Answe r:Run triggers in HCP Terraform allow you to automatically initiate runs in one workspace based on changes in another workspace. In this scenario, when the networking workspace is updated, a run trigger ensures that the compute workspace automatically runs plan and apply, keeping dependent infrastructure in sync.

Analysis of Incorrect Options (Distractors):

B . Policy --- Incorrect because policies (e.g., Sentinel) enforce rules and compliance but do not trigger runs between workspaces.

C . Run tasks --- Incorrect because run tasks integrate external tools into the Terraform workflow (e.g., security scanning), not for chaining workspace executions.

D . Projects --- Incorrect because projects are used for organizing workspaces, not for triggering operations.

Key Concept:Run triggersandIn in HCP Terraform.


Question 11

You corrected a typo in a resource name, changing it from aws_s3_bucket.photoes to aws_s3_bucket.photos. You want to update the Terraform state so that the existing resource is recognized under the new name, without destroying and recreating it. Which configuration should you use?

Correct Answer: D. Add a moved block to your configuration.
Explanation:

Rationale for Correct Answer: A moved block tells Terraform that an object's address in state has changed (renamed/refactored) and it should move the state from the old address to the new address. This preserves the existing real resource and prevents unnecessary destroy/recreate.

Analysis of Incorrect Options (Distractors):

A: Works but is unnecessarily risky/extra work; moved is the intended refactoring mechanism for renames.

B: Incorrect---refresh-only updates state to match real infrastructure, but it does not remap an object from one address to another.

C: Incorrect---Terraform will treat the new name as a new resource address and the old one as removed unless you explicitly move/rename state.

Key Concept: Refactoring addresses safely using moved blocks (state address migration).


Question 12

Which of the following does HCP Terraform perform during a health assessment for a workspace?

Pick the 2 correct responses below:

Correct Answer: C. Estimate infrastructure cost; D. Resource drift detection
Explanation:

Detailed

Rationale for Correct Answe r:HCP Terraform health assessments focus on evaluating the overall state and efficiency of infrastructure. Key components include:

C . Estimate infrastructure cost -- HCP Terraform integrates cost estimation (via Infracost) to provide visibility into infrastructure spending.

D . Resource drift detection -- It checks whether the real infrastructure has drifted from the Terraform state, which is critical for maintaining consistency and reliability.

These capabilities align with Terraform Cloud's goal of improving visibility, governance, and operational health of managed infrastructure.

Analysis of Incorrect Options (Distractors):

A . Terraform test execution Incorrect because terraform test is a CLI feature and not part of workspace health assessments.

B . Check block validation Incorrect because check blocks are evaluated during plan/apply runs, not specifically as part of health assessments.

E . Sentinel policy checks Incorrect because Sentinel policies are enforced during runs (plan/apply), not during health assessments.

Key Concept: HCP Terraform health assessments include cost estimation and drift detection to monitor infrastructure health.


Question 13

terraform init retrieves and caches the configuration for all remote modules.

Correct Answer: B. False
Explanation:

terraform initretrieves and caches providers and modules, butonly for explicitly declared modulesin the configuration.

If a module isadded or updated, terraform init needs to be re-run to download the new version.

Terraform does not automatically cache all remote modules unless they are explicitly referenced in the configuration.

Official Terraform Documentation Reference:

terraform init - HashiCorp Documentation


Question 14

Exhibit:

data "aws_ami" "web" {

most_recent = true

owners = ["self"]

tags = {

Name = "web-server"

}

}

A data source is shown in the exhibit. How do you reference the id attribute of this data source?

Correct Answer: C. data.aws_ami.web.id
Explanation:

Rationale for Correct Answer: Data sources are referenced using the address format:data.<DATA_SOURCE_TYPE>.<NAME>.<ATTRIBUTE>Here, the type is aws_ami, the name is web, and the attribute is id, so the correct reference is data.aws_ami.web.id.

Analysis of Incorrect Options (Distractors):

A (aws_ami.web.id): Incorrect because it omits the required data. prefix. This looks like a managed resource reference, not a data source.

B (web.id): Incorrect because Terraform references must include the full address (type and name); web alone is ambiguous.

D (data.web.id): Incorrect because it omits the data source type (aws_ami).

Key Concept: Terraform addressing and attribute references for data sources.


Question 15

As a developer, you want to ensure your plugins are up to date with the latest versions. Which Terraform command should you use?

Correct Answer: C. terraform init -upgrade
Explanation:

This command will upgrade the plugins to the latest acceptable version within the version constraints specified in the configuration. The other commands do not have an-upgradeoption.