HashiCorp Terraform Associate 004 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full HashiCorp Terraform Associate 004 Exam Dumps and Practice Test Dumps.


Q61. Which Terraform command upgrades installed providers within configured version constraints

  1. terraform validate
  2. terraform init with upgrade
  3. terraform output
  4. terraform state list

Correct Answer: 2. terraform init with upgrade

Explanation

terraform init with upgrade tells Terraform to reconsider previously selected provider versions and install newer versions that still satisfy the version constraints declared in the configuration. terraform validate checks configuration correctness. terraform output displays declared output values. terraform state list shows resource addresses recorded in state. terraform init with upgrade is therefore the correct answer because ordinary initialization normally respects versions already recorded in the dependency lock file. Teams should review provider upgrades carefully because newer provider releases can change behavior even when they remain within an allowed version range.

Q62. Which expression returns the directory containing the module where it is used

  1. path.root
  2. path.cwd
  3. terraform.workspace
  4. path.module

Correct Answer: 4. path.module

Explanation

path.module returns the file system path of the module in which the expression appears. path.root identifies the root module directory. path.cwd returns the original working directory where Terraform was invoked. terraform.workspace returns the current CLI workspace name rather than a directory path. path.module is therefore the correct answer because modules sometimes need to reference files distributed with their own configuration. Users should avoid assumptions that module paths are unique writable locations because the same module can be instantiated multiple times and remote modules may be stored in managed directories.

Q63. Which command can retrieve the current state data and print it to standard output

  1. terraform state pull
  2. terraform fmt
  3. terraform providers
  4. terraform validate

Correct Answer: 1. terraform state pull

Explanation

terraform state pull retrieves the current state from the configured backend and writes it to standard output. terraform fmt reformats configuration files. terraform providers displays provider requirements. terraform validate checks configuration syntax and consistency. terraform state pull is therefore the correct answer because it can be useful when inspecting or backing up state information during troubleshooting. State output may contain sensitive values and infrastructure details, so it should be handled securely. Users should avoid manually editing pulled state unless they fully understand the risks associated with state manipulation.

Q64. Which Terraform function renders a template file using supplied variable values

  1. fileset
  2. fileexists
  3. templatefile
  4. basename

Correct Answer: 3. templatefile

Explanation

The templatefile function reads a template from disk and renders it using a supplied map of variables. fileset returns matching file names from a directory. fileexists checks whether a file exists. basename returns the final component of a path. templatefile is therefore the correct answer because Terraform configurations sometimes need to generate structured text such as configuration files or initialization scripts from reusable templates. Templates should remain simple and infrastructure focused. Complex application logic is usually better handled outside Terraform rather than embedded deeply inside template expressions.

Q65. Which block can run a local command after a resource is created

  1. provisioner
  2. output
  3. backend
  4. import

Correct Answer: 1. provisioner

Explanation

A provisioner block can execute additional actions associated with resource creation or destruction, including local commands through the local exec provisioner. Output blocks expose values. Backend blocks configure state storage. Import blocks associate existing infrastructure with Terraform resource addresses. provisioner is therefore the correct answer. However, HashiCorp recommends using provisioners only when other approaches are not practical because Terraform cannot model their behavior as reliably as normal provider managed resources. Native provider features cloud initialization or dedicated configuration management tools are generally preferred when available.

Q66. Which command unlocks Terraform state when a lock remains after a failed operation

  1. terraform state rm
  2. terraform workspace select
  3. terraform force-unlock
  4. terraform output

Correct Answer: 3. terraform force-unlock

Explanation

terraform force-unlock manually removes a Terraform state lock when the lock remains even though no active Terraform process is using it. terraform state rm removes an object from state. terraform workspace select changes the active workspace. terraform output displays output values. terraform force-unlock is therefore the correct answer. It should be used carefully because removing a lock while another Terraform operation is still running can allow concurrent state writes and damage state consistency. Users should first confirm that the original operation has definitely stopped before forcing a lock removal.

Q67. Which Terraform function returns a set of file names matching a pattern in a directory

  1. file
  2. basename
  3. dirname
  4. fileset

Correct Answer: 4. fileset

Explanation

The fileset function returns a set of file names matching a specified pattern within a directory. file reads the contents of a file. basename returns the final path component. dirname returns the directory portion of a path. fileset is therefore the correct answer because configurations can use it to discover a known collection of local files and then process those names with Terraform expressions. The returned paths use normalized separators and are relative to the supplied base path. Users should keep file discovery predictable so plans remain understandable and reproducible.

Q68. Which setting can make Terraform wait before giving up on acquiring a state lock

  1. required_version
  2. lock timeout
  3. prevent_destroy
  4. sensitive

Correct Answer: 2. lock timeout

Explanation

A lock timeout tells Terraform how long it should continue attempting to acquire a state lock before returning an error. required_version controls compatible Terraform CLI versions. prevent_destroy blocks resource destruction. sensitive marks values for reduced display. lock timeout is therefore the correct answer because shared remote state may temporarily be locked by another legitimate Terraform operation. Waiting for a limited period can avoid unnecessary failures when another run is nearly complete. The timeout should remain reasonable so automation does not wait indefinitely when a lock is stale or another operation is unexpectedly long.

Q69. Which Terraform feature is intended to represent local values that can participate in lifecycle operations without managing external infrastructure

  1. output
  2. data source
  3. terraform_data resource
  4. provider alias

Correct Answer: 3. terraform_data resource

Explanation

The terraform_data resource is built into Terraform and can store values or trigger lifecycle behavior without requiring an external provider managed infrastructure object. Output blocks expose values. Data sources read information from providers. Provider aliases configure alternate provider instances. terraform_data resource is therefore the correct answer because it can provide a managed lifecycle container for values or replacement triggers when no real infrastructure resource is required. It is often a clearer modern alternative to patterns that previously relied on provider specific placeholder resources for lifecycle coordination.

Q70. Which command option reconfigures backend settings without attempting to migrate existing state automatically

  1. terraform init with reconfigure
  2. terraform plan
  3. terraform show
  4. terraform workspace new

Correct Answer: 1. terraform init with reconfigure

Explanation

terraform init with reconfigure tells Terraform to disregard previously initialized backend settings and use the backend configuration currently declared. terraform plan previews infrastructure changes. terraform show displays state or plan information. terraform workspace new creates a workspace. terraform init with reconfigure is therefore the correct answer because backend settings sometimes change and the working directory must be initialized again using the new configuration. Users should understand where the existing state is stored before changing backends because incorrect backend reconfiguration can make Terraform appear to have no existing managed infrastructure.

Q71. Which data source allows one Terraform configuration to read output values from another Terraform state

  1. external
  2. terraform_remote_state
  3. local_file
  4. terraform_data

Correct Answer: 2. terraform_remote_state

Explanation

terraform_remote_state reads root module output values from another Terraform state location. external data sources run external programs when supported through the corresponding provider. local_file is associated with local file management. terraform_data is a built in managed resource rather than a remote state reader. terraform_remote_state is therefore the correct answer because separate Terraform configurations sometimes need to consume selected outputs from one another. Architects should expose only necessary outputs and secure access to the underlying state because permissions to read state may reveal more information than the individual exposed outputs suggest.

Q72. Which built in value returns the name of the currently selected CLI workspace

  1. path.module
  2. path.root
  3. terraform.workspace
  4. path.cwd

Correct Answer: 3. terraform.workspace

Explanation

terraform.workspace returns the name of the currently selected Terraform CLI workspace. path.module returns the current module directory. path.root refers to the root module directory. path.cwd represents the original working directory. terraform.workspace is therefore the correct answer because configurations can reference the workspace name when selecting values or naming resources. However, heavy reliance on workspace names for major environment differences can make configuration harder to understand. Separate configurations may be more appropriate when environments require substantially different infrastructure topology credentials or operational controls.

Q73. Which command replaces one provider source address in Terraform state with another

  1. terraform state replace-provider
  2. terraform state show
  3. terraform state pull
  4. terraform providers

Correct Answer: 1. terraform state replace-provider

Explanation

terraform state replace-provider updates the provider source address associated with resources in Terraform state. terraform state show displays state information for one object. terraform state pull retrieves the complete state. terraform providers displays provider requirements and relationships. terraform state replace-provider is therefore the correct answer because provider namespaces or source locations may change during migrations. The command modifies state metadata rather than recreating resources. Users should review provider compatibility carefully before performing this operation because the replacement provider must correctly understand and manage the existing resource types recorded in state.

Q74. Which argument on an output block prevents normal display of a confidential output value

  1. depends_on
  2. sensitive
  3. source
  4. count

Correct Answer: 2. sensitive

Explanation

The sensitive argument on an output block tells Terraform to hide the output value from normal CLI display. depends_on controls dependencies. source is used in contexts such as modules and provider requirements. count creates multiple instances. sensitive is therefore the correct answer because outputs can contain passwords tokens or other confidential information that should not appear casually in terminal output. This setting does not encrypt the value or remove it from state. Teams must still protect state storage and restrict access because users with state access may be able to retrieve sensitive information.

Q75. Which HCP Terraform feature can enforce policy rules on Terraform runs

  1. State list
  2. Provider alias
  3. Policy enforcement
  4. Local values

Correct Answer: 3. Policy enforcement

Explanation

Policy enforcement in HCP Terraform allows organizations to evaluate Terraform runs against centrally defined governance rules before infrastructure changes proceed. State list is a CLI state inspection operation. Provider aliases configure multiple provider instances. Local values simplify expressions inside configuration. Policy enforcement is therefore the correct answer because organizations may need to require security cost tagging or operational standards across many workspaces. Policies can provide consistent guardrails without embedding every governance rule directly into each module. Teams should design policies carefully so they protect important requirements without blocking legitimate infrastructure workflows unnecessarily.

Q76. Which HCP Terraform execution mode runs Terraform operations on HashiCorp managed infrastructure

  1. Local execution
  2. Agent only execution
  3. Manual execution
  4. Remote execution

Correct Answer: 4. Remote execution

Explanation

Remote execution allows HCP Terraform to run Terraform operations on HashiCorp managed infrastructure rather than requiring the Terraform CLI process to perform the full run locally. Local execution runs operations from the user environment while still potentially using HCP Terraform for state. Agent based execution uses customer managed agents. Manual execution is not the relevant execution mode. Remote execution is therefore the correct answer because it centralizes runs logs variables permissions and collaboration. Teams should still configure workspace variables provider credentials and network accessibility appropriately for the resources the remote run must reach.

Q77. Which function calculates a subnet address from a larger network prefix

  1. cidrsubnet
  2. merge
  3. lookup
  4. flatten

Correct Answer: 1. cidrsubnet

Explanation

The cidrsubnet function calculates a subnet network prefix from a larger CIDR network using additional prefix bits and a subnet number. merge combines maps or objects. lookup retrieves a map value. flatten reduces nested lists into a single list. cidrsubnet is therefore the correct answer because network infrastructure modules often need to derive predictable subnet ranges from a parent network block. Users should understand the available address space and chosen prefix sizes carefully because incorrect calculations can create overlapping networks or subnets that are too small for the intended infrastructure.

Q78. Which feature allows HCP Terraform workspaces to start runs when another workspace successfully updates

  1. Provider aliases
  2. Run triggers
  3. State removal
  4. Output sensitivity

Correct Answer: 2. Run triggers

Explanation

Run triggers allow an HCP Terraform workspace to queue a run when a connected source workspace completes an applicable run successfully. Provider aliases select alternate provider configurations. State removal stops Terraform from tracking selected objects. Output sensitivity controls display of confidential values. Run triggers is therefore the correct answer because separate workspaces can represent dependent infrastructure layers that should react when upstream infrastructure changes. Teams should avoid excessive chains of workspace dependencies because they can make execution order and troubleshooting difficult across a large infrastructure estate.

Q79. Which provisioner executes a command on the machine where Terraform itself is running

  1. remote exec
  2. file
  3. local exec
  4. backend

Correct Answer: 3. local exec

Explanation

The local exec provisioner runs a command on the machine where Terraform is executing. remote exec runs commands on a remote resource through a supported connection. The file provisioner copies files to a remote system. backend is not a provisioner. local exec is therefore the correct answer because some exceptional workflows require Terraform to invoke a local utility or script. Provisioners should generally be a last resort because their effects are difficult for Terraform to model declaratively. Native provider resources or separate automation tools are usually more reliable when they can satisfy the requirement.

Q80. Which file is commonly used to assign input variable values automatically in a Terraform working directory

  1. terraform.tfvars
  2. terraform.lock.hcl
  3. main.tfstate
  4. providers.lock

Correct Answer: 1. terraform.tfvars

Explanation

terraform.tfvars is a standard variable definition file that Terraform automatically loads when evaluating input variables in a working directory. terraform.lock.hcl records provider dependency selections. main.tfstate and providers.lock are not the standard automatic variable assignment file names. terraform.tfvars is therefore the correct answer because it provides a convenient way to define values separately from variable declarations. Sensitive values should not be committed to version control merely because they are stored in a tfvars file. Secure variable management is preferred for confidential credentials or secrets.