View Full HashiCorp Terraform Associate 004 Exam Dumps and Practice Test Dumps.
Q21. Which Terraform block configures where state is stored
- variable
- backend
- output
- resource
Correct Answer: 2. backend
Explanation
A backend block configures how Terraform stores state and performs certain state related operations. Depending on the backend, state may be stored locally or in a remote system. Variable blocks define input values. Output blocks expose selected results. Resource blocks define infrastructure objects managed by Terraform. backend is therefore the correct answer because state storage configuration is an important part of Terraform collaboration and operational design. Remote backends can provide centralized state access and may also support capabilities such as locking. Backend configuration should be protected and managed carefully because state can contain sensitive infrastructure information.
Q22. Which Terraform command displays information from a state file or saved plan
- terraform fmt
- terraform init
- terraform validate
- terraform show
Correct Answer: 4. terraform show
Explanation
terraform show displays human readable information from Terraform state or from a saved plan file. terraform fmt reformats configuration files. terraform init prepares a working directory and installs dependencies. terraform validate checks configuration syntax and internal consistency. terraform show is therefore the correct answer because it allows users to inspect recorded infrastructure information or review a previously generated plan. The command can also produce machine readable output when supported options are used. Users should handle displayed state carefully because state information can contain sensitive resource attributes even when those values are not normally shown in ordinary application interfaces.
Q23. Which meta argument creates a specified number of resource instances
- count
- depends_on
- provider
- lifecycle
Correct Answer: 1. count
Explanation
The count meta argument creates multiple instances of a resource or module based on a numeric value. Each instance receives an index that can be referenced when configuring instance specific values. depends_on declares explicit dependencies. provider can select a provider configuration. lifecycle changes selected resource lifecycle behavior. count is therefore the correct answer when the desired number of similar instances can be represented as an integer. Architects should understand that changing instance positions can affect resource addresses, so for_each may be preferable when stable named keys are more appropriate than numeric indexes.
Q24. Which block defines reusable local values within a Terraform module
- output
- backend
- locals
- terraform
Correct Answer: 3. locals
Explanation
A locals block defines named local values that can simplify expressions and reduce repetition within a Terraform module. Output blocks expose values outside the module. Backend configuration controls state storage. The terraform block contains Terraform settings such as version and provider requirements. locals is therefore the correct answer because repeated expressions can be calculated once and referenced using local names throughout the module. Local values are not supplied by users like input variables. They are derived inside the configuration and are useful for naming conventions computed settings and shared expressions that improve readability.
Q25. Which setting can restrict the Terraform CLI versions allowed by a configuration
- provider alias
- state lock
- output type
- required_version
Correct Answer: 4. required_version
Explanation
required_version specifies which Terraform CLI versions are compatible with a configuration. Provider aliases configure alternate provider instances. State locking protects state from concurrent modification. Output types describe output value expectations rather than Terraform executable compatibility. required_version is therefore the correct answer because teams can define supported Terraform versions and reduce unexpected behavior caused by running configurations with incompatible releases. Version constraints should be selected deliberately so users and automation systems know which Terraform releases are acceptable. The setting belongs in the terraform configuration block and applies to the Terraform CLI itself rather than provider plugin versions.
Q26. Which command opens an interactive console for evaluating Terraform expressions
- terraform output
- terraform console
- terraform apply
- terraform providers
Correct Answer: 2. terraform console
Explanation
terraform console opens an interactive environment where users can evaluate Terraform expressions and inspect values available to the configuration. terraform output displays declared output values. terraform apply changes infrastructure. terraform providers displays provider requirements and relationships. terraform console is therefore the correct answer because it is useful for experimenting with functions expressions collections and references without repeatedly modifying configuration files. It can help users understand how Terraform expressions evaluate before those expressions are added to production configuration. The console is a diagnostic and learning tool and does not itself provision new infrastructure resources.
Q27. Which Terraform construct can mark an input value so normal CLI output hides it
- sensitive
- count
- depends_on
- source
Correct Answer: 1. sensitive
Explanation
The sensitive setting marks a variable or output value as sensitive so Terraform suppresses the value in many normal CLI displays. count controls the number of instances. depends_on declares dependencies. source identifies locations such as module sources. sensitive is therefore the correct answer because passwords tokens and similar values should not be displayed casually in terminal output or logs. However, marking a value sensitive does not automatically remove it from Terraform state. State must still be secured because sensitive values can remain stored there. Access controls and secure backends remain important for protecting confidential information.
Q28. Which function combines multiple list values into one list
- lookup
- length
- concat
- merge
Correct Answer: 3. concat
Explanation
The concat function combines two or more list values into a single list. lookup retrieves a value from a map. length returns the number of elements or characters in a value. merge combines maps or objects rather than lists. concat is therefore the correct answer because Terraform expressions frequently need to combine several lists before passing the result to a resource or module. Functions are evaluated as part of Terraform configuration expressions and help users transform values without external scripting. Understanding common collection functions is useful when building reusable modules and dynamic infrastructure definitions.
Q29. Which Terraform command lists resources recorded in the current state
- terraform show
- terraform state list
- terraform providers
- terraform validate
Correct Answer: 2. terraform state list
Explanation
terraform state list displays resource addresses currently recorded in Terraform state. terraform show displays detailed state or plan information. terraform providers shows provider requirements. terraform validate checks configuration validity. terraform state list is therefore the correct answer because it provides a quick inventory of the objects Terraform currently tracks in state. This can be useful during troubleshooting migrations or state management operations. State commands should be used carefully because incorrect state manipulation can break Terraform understanding of real infrastructure even when no cloud resource is immediately modified.
Q30. Which block records that a resource address changed during configuration refactoring
- moved
- import
- output
- check
Correct Answer: 1. moved
Explanation
A moved block tells Terraform that an existing resource or module instance has moved from one address to another. This allows configuration to be refactored without Terraform interpreting the new address as a completely new infrastructure object that requires recreation. An import block associates existing infrastructure with Terraform management. Output blocks expose values. Check blocks can validate assumptions. moved is therefore the correct answer because resource address changes are common when reorganizing modules or renaming resource labels. Using a moved block preserves the relationship between the existing object and its new configuration address.
Q31. Which block can declaratively associate an existing infrastructure object with a Terraform resource
- locals
- lifecycle
- backend
- import
Correct Answer: 4. import
Explanation
An import block can declaratively instruct Terraform to associate an existing infrastructure object with a resource address in configuration. locals defines reusable values. lifecycle controls selected resource behavior. backend configures state storage. import is therefore the correct answer because infrastructure created outside Terraform can be brought under Terraform management without recreating it. The configuration must still accurately describe the imported object after import. Architects should review the subsequent plan carefully because differences between configuration and the actual imported resource may cause Terraform to propose modifications.
Q32. Which provider configuration feature allows multiple configurations of the same provider
- count
- required_version
- alias
- state lock
Correct Answer: 3. alias
Explanation
The alias argument allows a configuration to define multiple instances of the same provider with different settings. This is useful when managing resources across multiple regions accounts or other provider specific contexts. count creates multiple resource or module instances. required_version constrains Terraform CLI versions. State locking protects shared state. alias is therefore the correct answer because resources or modules can explicitly select the appropriate alternate provider configuration when more than one is available. Provider aliases should be named clearly so users understand which account region or environment each configuration represents.
Q33. Which source value references a module located in the local file system
- A relative directory path
- A provider version number
- A state serial number
- A workspace name only
Correct Answer: 1. A relative directory path
Explanation
A relative directory path can be used as the source for a local Terraform module. Provider version numbers identify provider releases rather than module locations. State serial numbers are related to state versions. Workspace names do not identify module source code. A relative directory path is therefore the correct answer because modules can be stored within the same repository and referenced directly from another module. Terraform also supports various remote module sources. Teams should choose module sources that make versioning ownership and reuse clear for the environment in which Terraform is being used.
Q34. Which command shows detailed attributes for one resource recorded in Terraform state
- terraform fmt
- terraform state show
- terraform init
- terraform workspace list
Correct Answer: 2. terraform state show
Explanation
terraform state show displays the attributes Terraform currently records for a specified resource instance in state. terraform fmt reformats configuration files. terraform init prepares the working directory. terraform workspace list displays available CLI workspaces. terraform state show is therefore the correct answer because it is useful when troubleshooting resource values or confirming what Terraform currently knows about an infrastructure object. Users should remember that state may include sensitive values. Output from state inspection commands should therefore be handled carefully and not copied into unsecured logs or documents.
Q35. Which expression selects one of two values based on a boolean condition
- splat expression
- for expression
- conditional expression
- dynamic block
Correct Answer: 3. conditional expression
Explanation
A conditional expression chooses between two values according to whether a condition evaluates to true or false. Splat expressions retrieve attributes from multiple values. For expressions transform collections. Dynamic blocks generate repeated nested configuration blocks. conditional expression is therefore the correct answer because Terraform configurations often need to select environment specific or condition dependent values without duplicating entire resource definitions. Both possible result expressions should be compatible in type so Terraform can determine the resulting value correctly. Conditional expressions are useful but should remain readable rather than embedding excessive business logic into infrastructure configuration.
Q36. Which command changes the Terraform state address of an existing managed object
- terraform output
- terraform plan
- terraform providers
- terraform state mv
Correct Answer: 4. terraform state mv
Explanation
terraform state mv changes the state address associated with an existing managed object. terraform output displays output values. terraform plan previews proposed infrastructure changes. terraform providers displays provider information. terraform state mv is therefore the correct answer because it can support selected refactoring or state organization tasks without recreating the underlying infrastructure. State manipulation should be performed carefully because an incorrect source or destination address can cause Terraform to lose the intended relationship between configuration and real resources. Modern configuration refactoring may also use moved blocks where appropriate.
Q37. Which block specifies provider source addresses and version requirements
- required_providers
- output
- locals
- resource
Correct Answer: 1. required_providers
Explanation
required_providers declares the providers a Terraform module requires and can specify source addresses and compatible version constraints. Output blocks expose values. locals defines reusable local expressions. Resource blocks declare managed infrastructure objects. required_providers is therefore the correct answer because Terraform must know where provider plugins come from and which versions satisfy configuration requirements. These requirements belong in the terraform block. Teams should use clear version constraints and maintain the dependency lock file so provider selection remains predictable across users and automated execution environments.
Q38. Which Terraform feature can generate repeated nested blocks from collection values
- backend block
- dynamic block
- output block
- import block
Correct Answer: 2. dynamic block
Explanation
A dynamic block generates repeated nested blocks inside supported resource data source provider or provisioner configurations using collection values. Backend blocks configure state storage. Output blocks expose values. Import blocks associate existing infrastructure with Terraform resource addresses. dynamic block is therefore the correct answer because some resources contain repeatable nested structures that cannot be created directly with count or for_each at the nested block level. Dynamic blocks should be used when they improve maintainability, but excessive use can make configuration difficult to read. Simple static blocks are usually clearer when only a few known nested blocks are required.
Q39. Which planning option focuses on updating Terraform state to match remote objects without proposing normal configuration changes
- destroy mode
- target mode
- refresh only mode
- replace mode
Correct Answer: 3. refresh only mode
Explanation
Refresh only mode updates Terraform state and root module output values to reflect changes that occurred outside Terraform without planning the normal configuration driven infrastructure changes. Destroy mode plans resource destruction. Targeting limits planning to selected objects and dependencies. Replacement options request recreation of particular resources. refresh only mode is therefore the correct answer when users want Terraform state to acknowledge external changes without immediately applying the configured desired state. The resulting plan should still be reviewed because accepting externally introduced changes into state can affect future Terraform plans and infrastructure management decisions.
Q40. Which HCP Terraform feature can show proposed changes for a pull request without applying them
- Speculative plan
- State removal
- Provider alias
- Import block
Correct Answer: 1. Speculative plan
Explanation
A speculative plan shows the changes Terraform would propose without allowing that plan to be applied as a normal infrastructure change. State removal changes Terraform tracking and is unrelated to pull request review. Provider aliases configure multiple provider instances. Import blocks bring existing infrastructure under Terraform management. Speculative plan is therefore the correct answer because teams can review infrastructure effects during code review before configuration is merged into the primary workflow. This supports safer collaboration by allowing reviewers to evaluate likely resource changes alongside the configuration changes that produced them.