HashiCorp Terraform Associate 004 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full HashiCorp Terraform Associate 004 Exam Dumps and Practice Test Dumps.


Q381. Which Terraform command initializes a changed backend and offers to move existing state

  1. terraform validate
  2. terraform state show
  3. terraform output
  4. terraform init with migrate state

Correct Answer: 4. terraform init with migrate state

Explanation

terraform init with migrate state is used when backend configuration changes and existing state should be moved to the newly configured backend. terraform validate checks configuration correctness. terraform state show displays recorded attributes for a selected resource. terraform output displays declared output values. terraform init with migrate state is therefore the correct answer because backend changes require initialization before normal Terraform operations continue. Migrating state should be performed carefully because the state represents Terraform knowledge of managed infrastructure. Users should confirm the old and new backend locations and protect state throughout the migration process.

Q382. Which Terraform workspace exists automatically before additional CLI workspaces are created

  1. default
  2. primary
  3. root
  4. local

Correct Answer: 1. default

Explanation

default is the initial Terraform CLI workspace that exists automatically for a backend that supports multiple workspaces. Users can create additional workspaces later when separate state instances are required for similar configurations. primary root and local are not the standard initial workspace names. default is therefore the correct answer because Terraform always has an active workspace and begins with this predefined workspace unless another is selected later. Users should understand that CLI workspaces separate state but do not automatically provide complete security credential or architectural isolation between environments.

Q383. Which Terraform setting lets a child module declare that it can receive an aliased provider configuration

  1. provider source
  2. backend alias
  3. configuration_aliases
  4. state lineage

Correct Answer: 3. configuration_aliases

Explanation

configuration_aliases lets a reusable module declare additional provider configuration aliases that callers may pass into the module. Provider source identifies where the provider package comes from. Backend alias is not the relevant Terraform setting. State lineage identifies a state history. configuration_aliases is therefore the correct answer because child modules that need nondefault provider configurations should declare those alias names in their provider requirements. The calling module can then map actual provider configurations into the child module. This design keeps provider authentication and environment specific configuration outside reusable module implementation where possible.

Q384. Which variable assignment source normally has lower precedence than command line variable values

  1. Resource arguments
  2. Variable definition files
  3. Provider aliases
  4. Output values

Correct Answer: 2. Variable definition files

Explanation

Variable definition files normally have lower precedence than explicit command line variable assignments when Terraform resolves input values. Resource arguments provider aliases and output values are not alternative input variable assignment sources in this comparison. Variable definition files is therefore the correct answer because Terraform uses a defined precedence order when the same variable receives values from several supported sources. Understanding precedence helps prevent confusion when a value in a file appears to be ignored. Teams should keep variable assignment methods consistent so operators can easily determine which value Terraform will ultimately use.

Q385. Which Terraform environment variable can specify an alternate CLI configuration file

  1. TF_CLI_CONFIG_FILE
  2. TF_LOG
  3. TF_INPUT
  4. TF_DATA_DIR

Correct Answer: 1. TF_CLI_CONFIG_FILE

Explanation

TF_CLI_CONFIG_FILE tells Terraform to use a specific CLI configuration file instead of the normal default location. TF_LOG controls diagnostic logging. TF_INPUT controls interactive input behavior. TF_DATA_DIR changes where Terraform stores working directory data. TF_CLI_CONFIG_FILE is therefore the correct answer because automation or specialized environments may need different provider installation credentials or CLI settings from the user default configuration. The selected file should be protected when it contains service credentials or other sensitive client settings.

Q386. Which Terraform module source type supports selecting published versions with the version argument

  1. Arbitrary local directory
  2. Plain file path
  3. Unversioned copied folder
  4. Registry module

Correct Answer: 4. Registry module

Explanation

A registry module supports published module versions that callers can constrain using the version argument. Arbitrary local directories and ordinary copied folders do not use registry version selection in the same way. Registry module is therefore the correct answer because module registries provide structured discovery versioning and distribution of reusable Terraform configuration. Consumers can choose an approved version range rather than automatically using whichever code happens to be present in a directory. Version constraints help teams adopt module updates deliberately after testing compatibility with their infrastructure.

Q387. Which Terraform state concept identifies one specific managed instance created with for_each

  1. Backend type
  2. Instance key
  3. Provider checksum
  4. State lineage

Correct Answer: 2. Instance key

Explanation

An instance key identifies a particular instance created from a resource or module using for_each. Backend type determines state storage behavior. Provider checksums verify installed provider packages. State lineage identifies a state history. Instance key is therefore the correct answer because for_each instances are addressed by meaningful keys derived from the input map or set. Stable keys help Terraform preserve resource identity when unrelated collection elements change. Changing an instance key effectively changes its Terraform address and can therefore cause Terraform to treat the old and new instances as different objects.

Q388. Which Terraform expression can reference attributes of the current resource inside lifecycle conditions

  1. each.key
  2. count.index
  3. self
  4. terraform.workspace

Correct Answer: 3. self

Explanation

self can refer to attributes of the current object in supported contexts such as resource lifecycle conditions and provisioner related expressions. each.key is associated with for_each instances. count.index belongs to resources or modules created with count. terraform.workspace returns the selected CLI workspace name. self is therefore the correct answer because conditions sometimes need to evaluate attributes of the object they are attached to without repeating the full resource address. Its availability depends on the expression context, so users should use it only where Terraform language rules explicitly support it.

Q389. Which backend characteristic is required for Terraform to protect shared state from simultaneous writes

  1. Output values
  2. Local variables
  3. Module versions
  4. Locking support

Correct Answer: 4. Locking support

Explanation

Locking support allows a backend to prevent multiple Terraform operations from modifying the same shared state at the same time. Output values local variables and module versions do not provide concurrent state protection. Locking support is therefore the correct answer because simultaneous state writes can produce conflicts or corrupt Terraform understanding of managed infrastructure. Backends differ in the features they provide, so teams should evaluate state locking access control durability and recovery behavior when selecting a backend for collaborative infrastructure management.

Q390. Which Terraform concept represents an infrastructure object before it has a known remote identifier

  1. Planned resource instance
  2. Backend workspace
  3. Provider package
  4. Variable set

Correct Answer: 2. Planned resource instance

Explanation

A planned resource instance can exist in Terraform planning even when some provider assigned attributes such as remote identifiers are not yet known. Backend workspaces represent separate state instances. Provider packages contain provider implementations. Variable sets are an HCP Terraform feature for shared values. Planned resource instance is therefore the correct answer because Terraform can reason about future objects and their dependencies before the provider actually creates them. Unknown attributes are represented during planning and become concrete after the provider completes the relevant operation.

Q391. Which Terraform practice keeps reusable child modules independent from one specific backend

  1. Configure the backend only in the root module
  2. Put backend blocks in every child module
  3. Embed state credentials in modules
  4. Copy state into module folders

Correct Answer: 1. Configure the backend only in the root module

Explanation

Backend configuration belongs to the root module because state storage applies to the complete Terraform configuration rather than independently to each reusable child module. Adding backend settings to child modules would reduce reuse and does not match Terraform backend behavior. Embedding state credentials or copying state files into modules also creates security and maintenance problems. Configure the backend only in the root module is therefore the correct answer because child modules should focus on reusable infrastructure logic while the root module controls environment specific execution and state management concerns.

Q392. Which Terraform provider address component identifies the provider type itself

  1. Hostname
  2. Namespace
  3. Type
  4. Workspace

Correct Answer: 3. Type

Explanation

The type component identifies the provider itself within a provider source address. The hostname identifies the registry host and the namespace identifies the organization or publisher. Workspace is unrelated to provider addressing. Type is therefore the correct answer because a full provider source address distinguishes the registry location publisher and provider package that Terraform should install. Modules should declare accurate source addresses so Terraform does not confuse providers with similar local names or packages published by different organizations.

Q393. Which HCP Terraform capability can restrict who is allowed to apply a completed plan

  1. Apply permissions
  2. Provider checksum
  3. Local state
  4. Module output

Correct Answer: 2. Apply permissions

Explanation

Apply permissions control which authorized users or teams can approve and execute infrastructure changes in managed HCP Terraform workflows. Provider checksums verify package integrity. Local state stores Terraform state on a workstation. Module outputs expose values. Apply permissions is therefore the correct answer because collaborative infrastructure workflows should separate visibility from authority to make production changes. Organizations can grant planning access more broadly while limiting apply privileges to appropriate operators or teams. This supports controlled review and reduces the risk of unauthorized infrastructure modification.

Q394. Which Terraform behavior occurs when a resource argument changes but the provider marks that argument as requiring recreation

  1. Refresh only
  2. No change
  3. Output update only
  4. Resource replacement

Correct Answer: 4. Resource replacement

Explanation

Resource replacement occurs when a changed argument cannot be modified in place according to provider behavior. Terraform then plans to create a replacement and destroy the existing instance according to applicable lifecycle settings. Refresh only does not intentionally modify infrastructure. No change means Terraform found nothing to do. Output update only affects exposed values. Resource replacement is therefore the correct answer because some remote platform attributes are immutable once an object has been created. Users should review replacement plans carefully when the resource stores data or provides a critical service.

Q395. Which Terraform language feature lets several configuration files in one directory act as one module

  1. Automatic file loading
  2. State migration
  3. Provider mirroring
  4. Workspace inheritance

Correct Answer: 3. Automatic file loading

Explanation

Terraform automatically reads eligible configuration files in the same module directory and evaluates them together as one module. State migration changes backend storage. Provider mirroring changes provider package distribution. Workspace inheritance is not the relevant behavior. Automatic file loading is therefore the correct answer because users can organize a module across several files for readability without changing Terraform evaluation based on filename order. Resource dependencies come from references and graph relationships rather than from which configuration file appears first alphabetically.

Q396. Which Terraform plan characteristic shows values that will only become available after resource creation

  1. Known constants
  2. Values known after apply
  3. Provider aliases
  4. Variable defaults

Correct Answer: 1. Values known after apply

Explanation

Values known after apply are attributes Terraform cannot determine during planning because the provider or remote platform will supply them only after creating or updating a resource. Known constants and variable defaults are usually available earlier. Provider aliases select configurations rather than represent delayed values. Values known after apply is therefore the correct answer because Terraform can still build dependencies around unknown information without inventing a temporary value. Once the apply completes successfully Terraform records the resulting concrete attributes in state for later operations.

Q397. Which Terraform design practice makes a reusable module easier to understand for callers

  1. Hide all variable descriptions
  2. Use clear input and output interfaces
  3. Embed provider credentials
  4. Depend on undocumented values

Correct Answer: 3. Use clear input and output interfaces

Explanation

Clear input and output interfaces make a Terraform module easier to understand reuse and maintain. Hiding descriptions or depending on undocumented values makes the module harder to consume. Embedded provider credentials create security and portability concerns. Use clear input and output interfaces is therefore the correct answer because callers should understand what values a module requires and what useful information it returns without needing to inspect every internal resource. Strong types descriptions validation and stable output meanings all contribute to a well designed module contract.

Q398. Which Terraform operation normally compares configuration state and refreshed remote data before showing proposed changes

  1. terraform output
  2. terraform fmt
  3. terraform plan
  4. terraform workspace show

Correct Answer: 2. terraform plan

Explanation

terraform plan evaluates the desired configuration against Terraform state and current remote information as applicable and then shows the actions Terraform proposes. terraform output displays declared outputs. terraform fmt reformats configuration. terraform workspace show prints the selected workspace name. terraform plan is therefore the correct answer because it provides the primary review step before infrastructure changes are applied. Plans can reveal creations updates replacements and destruction actions. Important environments should review plans carefully so unexpected changes are discovered before apply modifies real infrastructure.

Q399. Which HCP Terraform organizational object contains multiple projects and workspaces under one administrative boundary

  1. Provider
  2. Registry module
  3. Organization
  4. State resource

Correct Answer: 4. Organization

Explanation

An HCP Terraform organization provides a broad administrative boundary containing projects workspaces teams and other shared capabilities. Providers connect Terraform to external platforms. Registry modules contain reusable configuration. State resources represent infrastructure objects rather than administrative containers. Organization is therefore the correct answer because enterprises use organizations to manage access governance and shared Terraform services across multiple teams and infrastructure areas. Projects can then group related workspaces within that broader organizational structure.

Q400. Which practice best reduces the risk of unintended Terraform changes before production apply

  1. Review the execution plan
  2. Skip planning
  3. Edit state manually
  4. Disable validation

Correct Answer: 1. Review the execution plan

Explanation

Reviewing the execution plan allows users to inspect proposed infrastructure actions before Terraform applies them to production. Skipping planning reduces visibility into upcoming changes. Manual state editing introduces significant risk and should be reserved for exceptional advanced recovery scenarios. Disabling validation removes another useful safeguard. Review the execution plan is therefore the correct answer because Terraform plans clearly show intended resource creation modification replacement and destruction. Teams can combine plan review with version control testing policy checks and controlled apply permissions to create a safer infrastructure delivery workflow.