View Full HashiCorp Terraform Associate 004 Exam Dumps and Practice Test Dumps.
Q341. Which Terraform command can apply only state refresh changes without modifying managed infrastructure
- terraform apply with destroy
- terraform apply with refresh only
- terraform apply with target
- terraform apply with replace
Correct Answer: 2. terraform apply with refresh only
Explanation
terraform apply with refresh only updates Terraform state and root output values to reflect changes already made to remote infrastructure without applying the normal configuration driven changes. Destroy mode removes managed resources. Target limits an operation to selected objects. Replace requests recreation of a particular resource. terraform apply with refresh only is therefore the correct answer because it accepts detected external changes into state without attempting to restore the configured infrastructure at the same time. Users should review the refresh only plan carefully before applying it because accepting drift can influence the behavior of future normal Terraform plans.
Q342. Which function returns the MD5 hash of a local file
- md5
- filebase64
- filesha256
- filemd5
Correct Answer: 4. filemd5
Explanation
The filemd5 function reads a local file and calculates its MD5 hash. md5 hashes a supplied string rather than reading file contents directly. filebase64 returns the encoded contents of a file rather than its hash. filesha256 calculates a SHA256 file hash. filemd5 is therefore the correct answer because some external systems or provider arguments may require an MD5 checksum for compatibility or change detection. MD5 should not be chosen for new security sensitive cryptographic purposes because stronger algorithms are available. It remains useful where a remote API specifically expects an MD5 based fingerprint.
Q343. Which argument can describe the purpose of a Terraform output value
- description
- nullable
- default
- source
Correct Answer: 1. description
Explanation
The description argument documents the purpose of an output value and helps users understand what the module exposes. nullable is associated with whether an input variable can accept null. default is used primarily with input variables to provide fallback values. source identifies locations such as modules or providers in other contexts. description is therefore the correct answer because reusable modules should explain the meaning of important outputs such as resource identifiers addresses or connection information. Clear descriptions improve module usability and generated documentation while keeping the output interface understandable to callers.
Q344. Which Terraform function returns the first matching regular expression result from a string
- regexall
- strcontains
- regex
- replace
Correct Answer: 3. regex
Explanation
The regex function applies a regular expression to a string and returns the matching result according to the pattern. regexall returns all matches rather than the single match behavior expected here. strcontains performs literal substring detection. replace performs string substitution. regex is therefore the correct answer because Terraform validation and transformation expressions may need pattern based extraction or matching. Users should prefer simpler functions when regular expressions are unnecessary because they are easier to read. When a match may legitimately be absent, can can be combined with regex to avoid an unhandled evaluation error.
Q345. Which HCP Terraform feature can provide temporary cloud credentials during a run without storing long lived secrets
- Local state
- Static environment secrets
- CLI workspaces
- Dynamic provider credentials
Correct Answer: 4. Dynamic provider credentials
Explanation
Dynamic provider credentials allow HCP Terraform to obtain temporary cloud credentials for a run rather than depending on long lived static secrets stored permanently in workspace variables. Local state and CLI workspaces do not provide cloud authentication. Static environment secrets are the opposite approach because the credentials remain stored until rotated. Dynamic provider credentials is therefore the correct answer because short lived credentials reduce exposure and can be scoped specifically for Terraform operations. Organizations should configure the trust relationship and permissions carefully so generated credentials receive only the access required by the relevant workspace.
Q346. Which Terraform command can update provider dependency selections while keeping configuration constraints in effect
- terraform validate
- terraform init with upgrade
- terraform output
- terraform state show
Correct Answer: 2. terraform init with upgrade
Explanation
terraform init with upgrade instructs Terraform to reconsider previously selected provider versions and choose newer versions that still satisfy the configured version constraints. terraform validate checks configuration validity. terraform output displays output values. terraform state show inspects one object in state. terraform init with upgrade is therefore the correct answer because the dependency lock file normally keeps existing provider selections stable until an intentional upgrade occurs. Teams should review provider release notes and resulting plans before using newer versions in important environments because provider changes can alter resource behavior.
Q347. Which type constraint allows a module to accept named attributes with different individual types
- list
- set
- object
- string
Correct Answer: 3. object
Explanation
An object type describes a structured value containing named attributes where each attribute can have its own declared type. A list contains ordered elements that share a compatible type. A set stores unique unordered elements. A string stores text. object is therefore the correct answer because modules often need related settings such as a name numeric size and boolean option supplied together in one structured input. Object constraints improve validation and documentation by making the expected structure explicit. Optional attributes can also be used when some settings are not required for every caller.
Q348. Which Terraform command shows the current workspace name only
- terraform workspace show
- terraform workspace list
- terraform workspace select
- terraform workspace new
Correct Answer: 1. terraform workspace show
Explanation
terraform workspace show displays only the name of the currently selected CLI workspace. terraform workspace list displays all available workspaces. terraform workspace select changes to an existing workspace. terraform workspace new creates and selects a new workspace. terraform workspace show is therefore the correct answer because automation or operators may need to confirm which state instance is active before planning or applying changes. Verifying the active workspace helps reduce the risk of operating against the wrong environment when one configuration is used with several workspace states.
Q349. Which Terraform feature can define a custom condition that an output value must satisfy
- variable validation
- output precondition
- provider alias
- backend lock
Correct Answer: 2. output precondition
Explanation
An output precondition can verify a condition before Terraform exposes the output value and can report a custom error when the condition is not satisfied. Variable validation checks input variables rather than outputs. Provider aliases configure alternate provider instances. Backend locking protects state from concurrent modification. output precondition is therefore the correct answer because module authors can enforce assumptions about values they intend to expose. Preconditions should express meaningful requirements rather than duplicate checks already guaranteed by resource arguments or provider behavior. Clear error messages make failed conditions easier for module users to understand.
Q350. Which Terraform function converts a compatible value to a string
- tonumber
- tolist
- tostring
- tomap
Correct Answer: 3. tostring
Explanation
The tostring function converts a compatible Terraform value into string form. tonumber converts compatible values into numbers. tolist converts compatible collections into lists. tomap converts compatible values into maps. tostring is therefore the correct answer because modules sometimes receive values that need explicit text representation before being used in names labels or string based provider arguments. Terraform performs some automatic conversions, but explicit conversion can make configuration intent clearer. Invalid conversions still produce errors, so module inputs should use strong type constraints whenever the expected value type is known.
Q351. Which Terraform meta argument explicitly selects an aliased provider for a resource
- provider
- source
- version
- backend
Correct Answer: 1. provider
Explanation
The provider meta argument allows a resource to select a specific provider configuration, including an aliased provider instance. source identifies provider or module locations in other contexts. version constrains releases where supported. backend configures Terraform state storage. provider is therefore the correct answer because configurations may manage resources across several accounts regions or endpoints using multiple configurations of the same provider. Resources that should use a nondefault provider can reference the appropriate alias directly. Clear alias names help users understand which provider context each resource uses.
Q352. Which command can inspect provider plugin requirements without applying infrastructure changes
- terraform apply
- terraform destroy
- terraform import
- terraform providers
Correct Answer: 4. terraform providers
Explanation
terraform providers displays the provider requirements detected across the current configuration and its modules without applying infrastructure changes. terraform apply changes managed infrastructure. terraform destroy removes resources. terraform import associates existing infrastructure with Terraform state. terraform providers is therefore the correct answer because it helps users understand which modules require particular providers and can assist with troubleshooting inheritance or alias configuration. The command is especially useful in larger configurations where provider dependencies originate from several child modules and may not be obvious from the root module alone.
Q353. Which Terraform function converts a value into an unordered collection of unique elements
- tolist
- tomap
- toset
- tuple
Correct Answer: 3. toset
Explanation
The toset function converts a compatible collection into a Terraform set containing unique unordered elements. tolist creates an ordered list. tomap converts compatible values into a map. tuple is a type concept rather than the conversion function required here. toset is therefore the correct answer because duplicate values are removed and the resulting set can be used effectively with for_each when elements should identify instances directly. Users should not depend on element positions after conversion because sets intentionally have no meaningful numeric ordering.
Q354. Which HCP Terraform capability allows a workspace to use values supplied through another workspace relationship
- Variable sharing through workspace outputs
- Provider checksum
- Local backend
- State serial
Correct Answer: 1. Variable sharing through workspace outputs
Explanation
Workspace output sharing allows selected outputs from one HCP Terraform workspace to be consumed by another permitted workspace when the organization design supports that relationship. Provider checksums verify provider packages. Local backend stores state locally. State serial identifies a state revision. Variable sharing through workspace outputs is therefore the correct answer because separate workspaces may manage different infrastructure layers while still needing controlled access to selected results such as network identifiers. Organizations should expose only necessary outputs and avoid creating excessive workspace dependencies that make infrastructure ordering difficult to understand.
Q355. Which command can move from one existing CLI workspace to another
- terraform workspace show
- terraform workspace list
- terraform workspace new
- terraform workspace select
Correct Answer: 4. terraform workspace select
Explanation
terraform workspace select changes the active CLI workspace to an existing workspace. terraform workspace show displays the current workspace. terraform workspace list lists available workspaces. terraform workspace new creates a new workspace and selects it. terraform workspace select is therefore the correct answer because users may need to switch between separate state instances associated with the same configuration. The active workspace should always be checked before plan or apply operations because selecting the wrong workspace can direct Terraform toward an unintended set of managed infrastructure.
Q356. Which Terraform expression references the numeric index for a resource created with count
- each.key
- count.index
- each.value
- self.index
Correct Answer: 2. count.index
Explanation
count.index returns the numeric index of the current resource or module instance created with count. each.key and each.value are available with for_each rather than count. self.index is not the standard Terraform reference for counted instances. count.index is therefore the correct answer because configurations can use the index to derive names addresses or other per instance settings. Users should remember that numeric indexing can make resource addresses sensitive to changes in collection order. for_each is often preferable when instances have stable meaningful keys.
Q357. Which Terraform function returns the first non null and nonempty string from several candidates
- coalesce
- coalescelist
- one
- compact
Correct Answer: 1. coalesce
Explanation
The coalesce function returns the first argument that is not null and not an empty string. coalescelist performs similar fallback selection for lists. one extracts the only element from a collection containing zero or one value. compact removes null and empty string values from a string list. coalesce is therefore the correct answer because configurations can select a preferred value and fall back to alternatives without writing a longer conditional expression. All candidate values should have compatible types so Terraform can determine a valid common result type.
Q358. Which Terraform command can remove a resource address from state while leaving the remote object intact
- terraform destroy
- terraform state mv
- terraform state rm
- terraform import
Correct Answer: 3. terraform state rm
Explanation
terraform state rm removes a selected object from Terraform state without requesting destruction of the actual remote infrastructure. terraform destroy removes managed infrastructure. terraform state mv changes a state address. terraform import brings an existing object under Terraform management. terraform state rm is therefore the correct answer because there are situations where Terraform should stop managing an object while the infrastructure remains in place. The command should be used carefully because a later plan may propose creating a new object if the corresponding resource configuration still exists after state removal.
Q359. Which Terraform function returns a collection with empty string elements removed
- distinct
- compact
- reverse
- flatten
Correct Answer: 2. compact
Explanation
The compact function removes empty strings and null values from a list of strings. distinct removes duplicate elements. reverse changes list order. flatten combines nested lists into one list. compact is therefore the correct answer because conditional expressions sometimes produce blank string entries that should not be passed to a resource or module. The function is intended specifically for string collections. When filtering complex objects or applying arbitrary conditions, a for expression with a filtering clause usually provides more control and makes the intended selection rule explicit.
Q360. Which HCP Terraform feature records historical information about completed workspace executions
- Provider mirror
- State lineage
- Variable set
- Run history
Correct Answer: 4. Run history
Explanation
Run history records previous HCP Terraform workspace runs and provides information about their plans applies results and associated execution details. Provider mirrors distribute provider packages. State lineage identifies related state versions. Variable sets distribute shared variables. Run history is therefore the correct answer because teams need an operational record of how infrastructure changed over time and which runs succeeded failed or were canceled. Historical run information supports troubleshooting auditing and collaboration by allowing users to review earlier plans and execution outcomes within the managed Terraform workflow.