View Full HashiCorp Terraform Associate 004 Exam Dumps and Practice Test Dumps.
Q201. Which Terraform block can record that a resource should no longer be managed without immediately destroying it
- moved
- removed
- import
- lifecycle
Correct Answer: 2. removed
Explanation
A removed block can describe that a previously managed object should be removed from Terraform management and can control whether the underlying infrastructure object is destroyed. A moved block records address changes during refactoring. An import block brings existing infrastructure under Terraform management. A lifecycle block changes selected behavior for an actively managed resource. removed is therefore the correct answer because it provides a configuration driven approach for intentionally removing objects from management. This can make refactoring and infrastructure ownership changes easier to review than performing an undocumented manual state operation.
Q202. Which environment variable enables detailed Terraform diagnostic logging
- TF_VAR
- TF_INPUT
- TF_WORKSPACE
- TF_LOG
Correct Answer: 4. TF_LOG
Explanation
TF_LOG controls Terraform diagnostic logging and can be assigned supported log levels when troubleshooting Terraform behavior. TF_VAR prefixes are used to provide input variable values. TF_INPUT controls interactive input behavior. TF_WORKSPACE can influence workspace selection in suitable automation scenarios. TF_LOG is therefore the correct answer because it provides detailed runtime information that can help diagnose provider initialization planning and other Terraform operations. Diagnostic logs may contain sensitive configuration or infrastructure information, so users should protect log files and disable detailed logging when troubleshooting is complete.
Q203. Which command writes a local state file to the configured Terraform backend
- terraform state push
- terraform state pull
- terraform state show
- terraform state list
Correct Answer: 1. terraform state push
Explanation
terraform state push uploads a local state file to the currently configured backend. terraform state pull retrieves state from the backend. terraform state show displays attributes for one resource instance. terraform state list displays addresses recorded in state. terraform state push is therefore the correct answer because it directly replaces backend state with supplied local state data. This is a potentially dangerous administrative operation and should not be part of ordinary Terraform workflows. Users should confirm that no other operation is running and ensure the state being pushed is the correct version before proceeding.
Q204. Which Terraform function returns the base name of a file system path
- dirname
- abspath
- basename
- pathexpand
Correct Answer: 3. basename
Explanation
The basename function returns the final component of a file system path. dirname returns the directory portion of a path. abspath converts a relative path to an absolute path. pathexpand expands a home directory reference where applicable. basename is therefore the correct answer because Terraform expressions sometimes need only the file or directory name from a longer path. File system functions should be used carefully in reusable modules because execution environments can differ between developer machines automation systems and remote Terraform execution environments.
Q205. Which command option can generate Terraform configuration for resources referenced by import blocks
- generate config out
- auto approve
- detailed exit code
- compact warnings
Correct Answer: 1. generate config out
Explanation
The generate config out option can be used with Terraform planning to generate configuration for resources declared by import blocks when corresponding resource configuration does not already exist. auto approve applies changes without interactive confirmation. detailed exit code helps automation interpret plan results. compact warnings reduces warning detail. generate config out is therefore the correct answer because it can assist when bringing existing infrastructure under Terraform management. Generated configuration should be reviewed carefully because it may include arguments that should be simplified or adjusted before becoming the long term desired configuration.
Q206. Which Terraform function converts a file hash into Base64 encoded SHA256 output
- sha256
- filebase64
- base64sha256
- filebase64sha256
Correct Answer: 4. filebase64sha256
Explanation
The filebase64sha256 function calculates a SHA256 hash of a local file and returns the hash in Base64 form. sha256 hashes a supplied string and returns hexadecimal output. filebase64 returns the actual file contents encoded as Base64. base64sha256 hashes a string rather than reading a file directly. filebase64sha256 is therefore the correct answer because resource arguments sometimes require a fingerprint of file content to detect changes. The referenced file must already exist when Terraform evaluates the expression, and the resulting hash represents the contents rather than providing encryption.
Q207. Which Terraform CLI configuration file can define provider installation behavior
- terraform.tfvars
- Terraform CLI configuration file
- terraform.tfstate
- main.tf
Correct Answer: 2. Terraform CLI configuration file
Explanation
The Terraform CLI configuration file can define command line client behavior including provider installation methods credentials and other CLI specific settings. terraform.tfvars supplies input variable values. terraform.tfstate contains state when local state is used. main.tf is a conventional Terraform configuration filename. Terraform CLI configuration file is therefore the correct answer because provider mirrors and direct installation rules are client level concerns rather than settings normally declared inside resource configuration. Teams should manage this file carefully because it can contain credentials and settings that affect how Terraform obtains providers.
Q208. Which provider installation method can use an internal copy of provider packages
- Remote state
- Variable set
- Filesystem mirror
- Output value
Correct Answer: 3. Filesystem mirror
Explanation
A filesystem mirror allows Terraform to install provider packages from a local or internally managed directory instead of downloading them directly from the normal origin. Remote state stores Terraform state. Variable sets provide shared values in HCP Terraform. Output values expose selected configuration results. Filesystem mirror is therefore the correct answer because organizations with restricted internet access or controlled software distribution requirements may maintain approved provider packages internally. Administrators should keep mirrored provider versions and checksums managed carefully so Terraform can install trusted packages consistently.
Q209. Which environment variable can supply default command arguments to Terraform CLI commands
- TF_DATA_DIR
- TF_WORKSPACE
- TF_LOG
- TF_CLI_ARGS
Correct Answer: 4. TF_CLI_ARGS
Explanation
TF_CLI_ARGS allows users or automation systems to specify additional default command arguments that Terraform inserts into CLI commands. TF_DATA_DIR changes where Terraform stores certain working directory data. TF_WORKSPACE can identify a workspace for automation. TF_LOG controls diagnostic logging. TF_CLI_ARGS is therefore the correct answer because repeated command options can be supplied consistently without typing them every time. Users should document this environment setting carefully because hidden default arguments can make command behavior surprising when another operator is unaware that extra options are being inserted automatically.
Q210. Which environment variable changes the directory Terraform uses for working data normally stored under the Terraform directory
- TF_VAR
- TF_DATA_DIR
- TF_LOG
- TF_INPUT
Correct Answer: 2. TF_DATA_DIR
Explanation
TF_DATA_DIR changes the location Terraform uses for per working directory data that would normally be stored in the Terraform data directory. TF_VAR prefixes assign input variables. TF_LOG controls diagnostic logging. TF_INPUT influences interactive input behavior. TF_DATA_DIR is therefore the correct answer because automation or specialized directory layouts may need Terraform working data stored somewhere other than the default location. Users should ensure repeated commands for the same configuration use the same appropriate data directory so provider and module initialization information remains consistent.
Q211. Which provider installation strategy downloads providers directly from their declared origin when allowed
- Direct installation
- State locking
- Workspace selection
- Module output
Correct Answer: 1. Direct installation
Explanation
Direct installation allows Terraform to retrieve provider packages from their declared origin when no mirror rule intercepts the request and the provider is allowed by the installation configuration. State locking protects state from concurrent modification. Workspace selection changes the active state instance. Module outputs expose values. Direct installation is therefore the correct answer because it represents the normal provider retrieval path when packages are available from their origin. Organizations can combine direct installation with network or filesystem mirrors and exclusion rules when they require controlled provider distribution.
Q212. Which Terraform function creates a string by joining path components using system path rules
- concat
- format
- join
- path related expression handling
Correct Answer: 3. join
Explanation
The join function combines a collection of strings using a specified separator and can therefore be used when constructing simple path text from known components. concat combines lists rather than producing one string. format creates a formatted string from a pattern. path related expression handling is not a standalone Terraform function. join is therefore the correct answer among these choices because it can combine directory and file components when the separator is explicitly provided. Reusable modules should still minimize assumptions about local file system layouts because remote and local execution environments may differ.
Q213. Which environment variable can disable interactive input prompts in Terraform automation
- TF_LOG
- TF_INPUT
- TF_WORKSPACE
- TF_DATA_DIR
Correct Answer: 2. TF_INPUT
Explanation
TF_INPUT can disable interactive input when set appropriately, which is useful in automated Terraform workflows that cannot respond to prompts. TF_LOG controls diagnostic logging. TF_WORKSPACE can influence workspace selection. TF_DATA_DIR changes the working data directory. TF_INPUT is therefore the correct answer because automation should normally supply all required values and fail clearly rather than waiting indefinitely for human input. Disabling interactive prompts does not provide missing variables automatically, so pipelines must still supply all required configuration and credentials through suitable secure mechanisms.
Q214. Which Terraform concept describes resources Terraform can manage but that were originally created outside Terraform
- Imported resources
- Local values
- Output values
- Provider mirrors
Correct Answer: 1. Imported resources
Explanation
Imported resources are existing infrastructure objects that become associated with Terraform resource addresses and state so Terraform can manage them going forward. Local values are internal expressions. Output values expose selected information. Provider mirrors distribute provider packages. Imported resources is therefore the correct answer because organizations often adopt Terraform after infrastructure already exists. Importing does not automatically guarantee the written configuration matches the remote object, so users should review the next plan carefully and adjust the configuration until the desired state accurately represents the imported infrastructure.
Q215. Which Terraform CLI setting can configure credentials for a remote Terraform service host
- Variable declaration
- Resource block
- Output block
- Credentials configuration
Correct Answer: 4. Credentials configuration
Explanation
Credentials configuration in the Terraform CLI settings stores authentication information used to access supported remote Terraform service hosts. Variable declarations define module inputs. Resource blocks manage infrastructure objects. Output blocks expose selected values. Credentials configuration is therefore the correct answer because operations such as remote workspace access or private registry usage may require authenticated communication with a Terraform service. Tokens should be treated as sensitive information and stored securely. Users should revoke credentials that are no longer needed and avoid exposing them through repositories terminal history or unsecured automation logs.
Q216. Which Terraform function returns the current plan timestamp consistently throughout one plan
- timestamp
- timeadd
- plantimestamp
- formatdate
Correct Answer: 3. plantimestamp
Explanation
plantimestamp returns a timestamp associated with the current Terraform plan and remains consistent throughout that planning operation. timestamp returns the current time when evaluated and can produce changing values between executions. timeadd adjusts a timestamp by a duration. formatdate changes timestamp presentation. plantimestamp is therefore the correct answer because some configurations need one stable time value for calculations performed within the same plan. Time based resource arguments should still be used carefully because changing timestamps across future plans can result in recurring infrastructure differences.
Q217. Which backend behavior keeps Terraform state on the workstation by default
- Local backend behavior
- Remote execution
- Cloud workspace execution
- Agent execution
Correct Answer: 1. Local backend behavior
Explanation
Local backend behavior stores Terraform state on the machine where Terraform is being run unless another backend is configured. Remote execution runs Terraform operations through a remote service. Cloud workspace execution uses hosted workspace capabilities. Agent execution uses managed or customer controlled agents depending on the platform. Local backend behavior is therefore the correct answer because a basic Terraform configuration begins with local state unless configured otherwise. Teams generally move important shared infrastructure state to an appropriate remote backend so multiple operators can collaborate with stronger access and locking controls.
Q218. Which Terraform command accepts a saved plan file and performs exactly that planned set of actions
- terraform plan
- terraform apply
- terraform validate
- terraform graph
Correct Answer: 2. terraform apply
Explanation
terraform apply can accept a saved plan file and execute the actions recorded in that plan. terraform plan generates proposed changes. terraform validate checks configuration syntax and internal consistency. terraform graph generates dependency information. terraform apply is therefore the correct answer because controlled workflows often separate plan creation and review from final execution. Applying the saved plan ensures Terraform uses the previously reviewed actions rather than calculating a completely new plan at approval time. Saved plan files should be protected because they can include sensitive infrastructure information.
Q219. Which provider installation mechanism can retrieve providers from an internal network service
- Local state
- CLI workspace
- Variable set
- Network mirror
Correct Answer: 4. Network mirror
Explanation
A network mirror provides provider packages through an internally hosted service that Terraform can use instead of retrieving packages directly from their original registry locations. Local state stores infrastructure state. CLI workspaces separate state instances. Variable sets provide shared input or environment values. Network mirror is therefore the correct answer because organizations may need centralized provider distribution for security reliability or restricted network environments. Administrators should ensure the mirror contains approved provider versions and maintains package integrity information so Terraform can verify downloaded packages appropriately.
Q220. Which Terraform function formats a timestamp according to a specified date pattern
- timestamp
- timeadd
- formatdate
- plantimestamp
Correct Answer: 3. formatdate
Explanation
The formatdate function converts a timestamp into a string using a specified date and time formatting pattern. timestamp produces the current timestamp. timeadd adds a duration to an existing timestamp. plantimestamp returns a stable timestamp associated with the current plan. formatdate is therefore the correct answer because configurations may need timestamps represented in a specific format for tags names or provider arguments. Formatting does not change the underlying moment in time. Users should also consider time zone expectations when external platforms interpret formatted date strings.