HashiCorp Terraform Associate 004 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full HashiCorp Terraform Associate 004 Exam Dumps and Practice Test Dumps.


Q361. Which Terraform function checks whether a local file exists

  1. file
  2. fileexists
  3. fileset
  4. basename

Correct Answer: 2. fileexists

Explanation

The fileexists function checks whether a specified local file exists and returns a boolean result. file reads the contents of an existing file. fileset returns file names matching a pattern inside a directory. basename returns the final portion of a path. fileexists is therefore the correct answer because Terraform expressions can use it when behavior depends on whether a known local file is present. File based logic should be used carefully in reusable modules because local execution remote execution and automation environments may contain different files or directory layouts.

Q362. Which Terraform concept means configuration describes the desired infrastructure outcome rather than every execution step

  1. Imperative execution
  2. Manual provisioning
  3. Procedural scripting
  4. Declarative configuration

Correct Answer: 4. Declarative configuration

Explanation

Declarative configuration describes the desired end state of infrastructure while Terraform determines the operations required to reach that state. Imperative and procedural approaches focus more directly on specifying individual execution steps. Manual provisioning requires human actions rather than configuration driven automation. Declarative configuration is therefore the correct answer because Terraform users define resources relationships and settings rather than writing every API operation in sequence. Terraform compares configuration state and remote infrastructure to determine which create update replace or destroy actions are required.

Q363. Which Terraform file normally stores local state when no remote backend is configured

  1. terraform.tfstate
  2. terraform.tfvars
  3. terraform.lock.hcl
  4. providers.tf

Correct Answer: 1. terraform.tfstate

Explanation

terraform.tfstate is the conventional local state file Terraform uses when state is stored locally. terraform.tfvars contains input variable assignments. terraform.lock.hcl records selected provider dependencies and checksums. providers.tf is only a conventional configuration filename and does not store state automatically. terraform.tfstate is therefore the correct answer because Terraform needs state to map configuration addresses to real managed infrastructure objects. State can contain sensitive attributes and should be protected carefully. Teams commonly use secure remote state rather than individual local files for shared production infrastructure.

Q364. Which Terraform concept describes infrastructure changes made outside Terraform that differ from recorded state

  1. Module inheritance
  2. Provider upgrade
  3. Configuration drift
  4. Workspace selection

Correct Answer: 3. Configuration drift

Explanation

Configuration drift occurs when real infrastructure changes outside the normal Terraform workflow and no longer matches what Terraform state and configuration expect. Module inheritance and provider upgrades describe different Terraform behaviors. Workspace selection determines which state instance is active. Configuration drift is therefore the correct answer because cloud consoles scripts or other automation can modify objects after Terraform creates them. A normal plan usually refreshes relevant remote information and can expose these differences. Teams should decide whether Terraform should restore the declared configuration or whether configuration should be updated to accept the intentional external change.

Q365. What is the main reason to commit the Terraform dependency lock file to version control

  1. Keep provider selections consistent
  2. Store infrastructure state
  3. Save variable secrets
  4. Replace provider constraints

Correct Answer: 1. Keep provider selections consistent

Explanation

Committing the dependency lock file helps collaborators and automation use the same selected provider versions and verified package checksums. It does not store infrastructure state or serve as a secret storage mechanism. It also does not replace provider version constraints because constraints describe allowed versions while the lock file records actual selections. Keep provider selections consistent is therefore the correct answer because reproducible provider installation reduces unexpected differences between environments. Provider upgrades can still be performed deliberately when teams are ready to test and review a newer compatible release.

Q366. Which Terraform behavior updates state with provider returned resource attributes after a successful apply

  1. Variable validation
  2. Workspace deletion
  3. Formatting
  4. State persistence

Correct Answer: 4. State persistence

Explanation

State persistence records updated resource information after Terraform successfully performs provider operations. Variable validation checks input values. Workspace deletion removes a CLI workspace. Formatting changes configuration presentation. State persistence is therefore the correct answer because Terraform needs to remember identifiers attributes and relationships returned by providers so later plans can compare real infrastructure with configuration. This state information becomes the basis for subsequent management operations. Because state can contain sensitive values and important resource identifiers it should be stored securely and protected from unauthorized changes.

Q367. Which Terraform module characteristic makes a module easier to reuse across environments

  1. Hard coded environment values
  2. Input variables
  3. Embedded state files
  4. Fixed credentials

Correct Answer: 2. Input variables

Explanation

Input variables allow a module to accept values supplied by different callers instead of embedding environment specific information directly in the module. Hard coded settings reduce flexibility. Embedded state files should not be part of reusable modules. Fixed credentials create security and portability problems. Input variables is therefore the correct answer because the same infrastructure logic can be reused with different regions names sizes or other settings. Strong types descriptions defaults where appropriate and validation rules make module interfaces clearer and safer for users across multiple environments.

Q368. Which Terraform plan action means an existing object will be deleted and a new object created in its place

  1. Refresh
  2. Read
  3. Replace
  4. No change

Correct Answer: 3. Replace

Explanation

A replace action means Terraform must destroy an existing managed object and create a new instance because the required change cannot be performed in place or replacement was explicitly requested. Refresh only updates Terraform knowledge of remote values. Read retrieves information without creating a managed object. No change means the existing infrastructure already matches the desired configuration. Replace is therefore the correct answer because some resource attributes are immutable according to provider or platform behavior. Users should review replacements carefully because they can affect service availability persistent data or dependent infrastructure.

Q369. Which Terraform function adds indentation to every line except the first line of a string

  1. indent
  2. format
  3. chomp
  4. trimspace

Correct Answer: 4. indent

Explanation

The indent function adds a specified number of spaces to lines in a multiline string after the first line. format creates formatted strings. chomp removes newline characters from the end of a string. trimspace removes surrounding whitespace. indent is therefore the correct answer because generated configuration text or scripts may need consistent indentation when inserted into larger templates. Users should avoid making templates unnecessarily complex inside Terraform because dedicated configuration tools or simpler structured values may be easier to maintain for extensive application configuration.

Q370. Which Terraform object contains provider configuration such as region or service endpoint settings

  1. Provider block
  2. Output block
  3. Import block
  4. Moved block

Correct Answer: 1. Provider block

Explanation

A provider block configures how Terraform communicates with a particular provider instance and can include settings such as region endpoint or other provider specific options. Output blocks expose values. Import blocks associate existing infrastructure with Terraform resources. Moved blocks record address changes. Provider block is therefore the correct answer because provider configuration establishes the context used when Terraform manages or reads external objects. Credentials are often supplied through secure environment or platform mechanisms rather than being hard coded directly into provider configuration.

Q371. Which Terraform principle means repeated apply operations should produce no changes after infrastructure reaches the desired state

  1. Encapsulation
  2. Serialization
  3. Idempotent convergence
  4. Provider aliasing

Correct Answer: 3. Idempotent convergence

Explanation

Idempotent convergence means that after managed infrastructure matches the declared Terraform configuration another normal plan and apply should not continually make unnecessary changes. Encapsulation is a broader design concept. Serialization refers to representation or ordered execution depending on context. Provider aliasing creates multiple provider configurations. Idempotent convergence is therefore the correct answer because declarative infrastructure management should settle into a stable desired state. Persistent changes on every plan can indicate nondeterministic input external modification provider behavior or configuration that generates changing values such as timestamps.

Q372. Which Terraform configuration practice best protects reusable modules from provider credential exposure

  1. Store credentials in module source
  2. Configure credentials outside the module
  3. Put credentials in outputs
  4. Add credentials to state comments

Correct Answer: 2. Configure credentials outside the module

Explanation

Reusable child modules should generally declare provider requirements while provider authentication and environment specific configuration remain outside the module, commonly in the root module or execution environment. Storing credentials in module source risks disclosure through version control. Outputs can also expose secrets. State comments are not a credential management mechanism. Configure credentials outside the module is therefore the correct answer because separating reusable logic from authentication improves security and portability. It also allows the same module to operate in different accounts or environments using appropriately scoped provider configurations.

Q373. Which Terraform concept represents the actual provider plugin implementation selected for use

  1. Provider configuration
  2. Resource address
  3. Provider package
  4. Backend state

Correct Answer: 3. Provider package

Explanation

A provider package contains the provider plugin implementation Terraform installs and executes to communicate with an external platform. Provider configuration supplies settings to an installed provider instance. Resource addresses identify managed objects. Backend state stores Terraform state information. Provider package is therefore the correct answer because required_providers identifies where a provider comes from and compatible versions while initialization installs the selected package. Dependency lock information and package checksums help keep provider installation consistent and verify that expected packages are being used.

Q374. Which Terraform feature lets a module expose a stable interface while hiding its internal resource structure

  1. Outputs
  2. Backend migration
  3. State serial
  4. Provider checksum

Correct Answer: 1. Outputs

Explanation

Outputs allow a Terraform module to expose selected values such as identifiers addresses or names without requiring callers to reference the module internal resources directly. Backend migration moves state storage. State serial identifies state revisions. Provider checksums verify package integrity. Outputs is therefore the correct answer because clear module interfaces reduce coupling between the caller and the implementation details inside a reusable module. Internal resources can then be reorganized more safely as long as the module inputs and outputs remain compatible with existing callers.

Q375. Which Terraform planning behavior normally reads current remote object attributes before calculating differences

  1. Provider refresh
  2. Workspace creation
  3. Output formatting
  4. Module download

Correct Answer: 2. Provider refresh

Explanation

Provider refresh reads current remote infrastructure information so Terraform can compare real object attributes with configuration and recorded state before proposing changes. Workspace creation creates a separate state instance. Output formatting changes how values are displayed. Module download retrieves reusable configuration. Provider refresh is therefore the correct answer because infrastructure may have changed since the previous apply. Normal planning typically includes refreshing relevant managed objects unless that behavior is intentionally disabled. Accurate refresh information helps Terraform identify drift and determine the actions required to converge on the desired configuration.

Q376. Which Terraform module design choice best reduces duplication across several similar environments

  1. Copy the full configuration for every environment
  2. Hard code all values
  3. Reusable child module
  4. Separate provider source for each resource

Correct Answer: 3. Reusable child module

Explanation

A reusable child module packages common infrastructure logic so several environments can call the same implementation with different input values. Copying full configuration creates duplication and makes future updates harder to keep consistent. Hard coded values reduce portability. Separate provider sources for every resource do not solve configuration duplication. Reusable child module is therefore the correct answer because shared infrastructure patterns can be defined once and versioned deliberately. Root modules can then supply environment specific variables and provider configurations while consuming the common module interface.

Q377. Which Terraform behavior prevents configuration from directly managing an object declared only through a data source

  1. Data sources are read only
  2. Data sources create resources automatically
  3. Data sources replace providers
  4. Data sources store credentials

Correct Answer: 4. Data sources are read only

Explanation

Data sources are designed to read information from providers rather than declare ownership of creating updating or destroying the referenced remote object. They do not automatically create resources replace providers or act as credential storage. Data sources are read only is therefore the correct answer because Terraform uses them to discover existing information that can influence managed resources. A separate resource block is required when Terraform should manage the lifecycle of an infrastructure object. Users should choose between a resource and data source according to ownership responsibility.

Q378. Which Terraform command behavior determines whether a saved plan can be applied safely after state has changed

  1. Plan freshness validation
  2. Output sensitivity
  3. Module formatting
  4. Variable description

Correct Answer: 2. Plan freshness validation

Explanation

When applying a saved plan Terraform verifies that the plan remains applicable to the current state rather than blindly executing actions based on outdated state information. Output sensitivity affects display. Module formatting changes style. Variable descriptions provide documentation. Plan freshness validation is therefore the correct answer because infrastructure may have changed after a plan was created. Terraform needs to protect against applying a plan that was based on an older state snapshot. Controlled workflows should minimize long delays between plan creation review and application when infrastructure is changing frequently.

Q379. Which Terraform configuration characteristic makes resource dependencies implicit

  1. File ordering
  2. Comment ordering
  3. Attribute references
  4. Resource declaration position

Correct Answer: 3. Attribute references

Explanation

Attribute references create implicit dependencies when one Terraform object uses data produced by another object. File ordering comment ordering and the physical position of resource blocks do not determine infrastructure execution order. Attribute references is therefore the correct answer because Terraform analyzes data relationships to build its dependency graph automatically. This means resources can be organized across several configuration files without requiring procedural ordering. Explicit depends_on should be reserved for dependencies that genuinely exist but cannot be represented through normal references.

Q380. Which practice best protects Terraform state stored remotely

  1. Public read access
  2. Disable authentication
  3. Store copies in source repositories
  4. Restrict backend access

Correct Answer: 4. Restrict backend access

Explanation

Restricting backend access ensures that only authorized users and automation systems can read or modify remote Terraform state. Public access and disabled authentication expose infrastructure details and potentially sensitive values. Storing state copies in ordinary source repositories can also create unnecessary disclosure risk. Restrict backend access is therefore the correct answer because Terraform state can contain resource identifiers network information passwords or other sensitive attributes depending on providers and configuration. Secure remote backends should use appropriate authentication authorization encryption and operational controls to protect both confidentiality and state integrity.