View Full HashiCorp Terraform Associate 004 Exam Dumps and Practice Test Dumps.
Q41. Which Terraform command removes resources managed by the current configuration
- terraform validate
- terraform output
- terraform fmt
- terraform destroy
Correct Answer: 4. terraform destroy
Explanation
terraform destroy creates and executes a plan that removes infrastructure objects managed by the current Terraform configuration and state. terraform validate checks configuration syntax and consistency. terraform output displays declared output values. terraform fmt reformats configuration files into the standard style. terraform destroy is therefore the correct answer because it is specifically intended to remove managed infrastructure. Users should review destruction carefully because removing resources can cause permanent data loss or service interruption. In important environments appropriate approvals backups and dependency reviews should be completed before executing a destructive Terraform operation.
Q42. Which argument in a module block specifies where Terraform should obtain the module
- source
- type
- backend
- lifecycle
Correct Answer: 1. source
Explanation
The source argument tells Terraform where a child module configuration is located. The source can reference a local directory a registry module a version control repository or another supported module source. type is not the argument used to locate a module. backend configures state storage. lifecycle controls selected resource behavior. source is therefore the correct answer because Terraform must know where to retrieve the module before it can evaluate the module configuration. Remote modules may also support a version argument when the selected source type provides module versioning.
Q43. Which Terraform feature can enforce a condition on an input variable value
- provider alias
- state locking
- variable validation
- output sensitivity
Correct Answer: 3. variable validation
Explanation
Variable validation allows a Terraform input variable to define conditions that supplied values must satisfy. Provider aliases configure multiple instances of a provider. State locking protects state from concurrent modification. Output sensitivity affects display behavior for sensitive results. Variable validation is therefore the correct answer because modules can reject invalid inputs before those values are used to configure infrastructure. Validation rules can improve module reliability by enforcing requirements such as accepted regions naming formats ranges or allowed values. Clear error messages should also be provided so users understand why an input was rejected.
Q44. Which function returns the number of elements in a collection
- merge
- length
- lookup
- concat
Correct Answer: 2. length
Explanation
The length function returns the number of elements in a collection or the number of characters in a string. merge combines maps or objects. lookup retrieves a value from a map using a key. concat combines list values. length is therefore the correct answer because Terraform expressions often need to determine collection size for conditions calculations or resource configuration. Functions can be combined with variables local values and resource attributes to build flexible configurations. Users should ensure the input type is appropriate for the function being used so evaluation produces the expected result.
Q45. Which Terraform block can specify behavior such as preventing a resource from being destroyed
- output
- variable
- provider
- lifecycle
Correct Answer: 4. lifecycle
Explanation
A lifecycle block changes selected behavior for a managed resource and can include settings such as prevent_destroy create_before_destroy and ignore_changes. Output blocks expose values. Variable blocks define configurable inputs. Provider blocks configure communication with external platforms. lifecycle is therefore the correct answer because it provides controls over how Terraform handles resource changes and replacement. These settings should be used carefully because they can affect normal planning behavior. For example prevent_destroy can protect an important resource but can also block legitimate changes that require replacement until the setting is intentionally adjusted.
Q46. Which command removes a resource from Terraform state without destroying the actual infrastructure object
- terraform destroy
- terraform state rm
- terraform apply
- terraform fmt
Correct Answer: 2. terraform state rm
Explanation
terraform state rm removes the selected object from Terraform state while leaving the real infrastructure object unchanged. terraform destroy attempts to remove managed infrastructure. terraform apply performs planned infrastructure changes. terraform fmt only reformats configuration files. terraform state rm is therefore the correct answer when Terraform should stop tracking an object without deleting it. After removal Terraform no longer manages that object unless it is imported again. State operations should be performed carefully because removing the wrong address can cause Terraform to propose creating a replacement object during a later plan.
Q47. Which feature allows one module to call another module
- module block
- backend block
- moved block
- check block
Correct Answer: 1. module block
Explanation
A module block calls a child module from another Terraform module. Backend blocks configure state storage. Moved blocks describe resource or module address changes. Check blocks can verify infrastructure assumptions. module block is therefore the correct answer because reusable Terraform configuration is composed by calling child modules from a parent module. The module block supplies the source location and can pass input values expected by the child module. Outputs from the child module can then be referenced by the parent configuration to connect reusable infrastructure components together.
Q48. Which provider version constraint allows compatible updates within the specified version range
- Exact constraint only
- No version constraint
- Pessimistic constraint
- Backend constraint
Correct Answer: 3. Pessimistic constraint
Explanation
A pessimistic version constraint allows selected newer versions while limiting updates beyond an intended compatibility boundary. An exact constraint permits only one specified version. No constraint can allow a broader range than intended. Backend constraint is not a provider version constraint type. Pessimistic constraint is therefore the correct answer because it provides controlled flexibility when provider updates within a compatible range are acceptable. Teams should combine sensible version constraints with the dependency lock file so provider versions remain predictable while still allowing deliberate upgrades when tested and approved.
Q49. Which Terraform feature can reference attributes across all instances created with count
- Splat expression
- Backend block
- Provider alias
- Import block
Correct Answer: 1. Splat expression
Explanation
A splat expression provides a concise way to access the same attribute from multiple resource or module instances represented as a collection. Backend blocks configure state storage. Provider aliases create alternate provider configurations. Import blocks associate existing objects with Terraform addresses. Splat expression is therefore the correct answer because configurations sometimes need to collect values such as identifiers or addresses from several similar instances. Splat expressions can make simple collection access shorter, although for expressions may be clearer when more complex transformation or filtering logic is required.
Q50. Which command can force Terraform to replace a specific managed resource during the next apply
- terraform output
- terraform validate
- terraform fmt
- terraform apply with replace
Correct Answer: 4. terraform apply with replace
Explanation
Using terraform apply with the replace option instructs Terraform to plan replacement of a specified resource instance even when its current arguments might not otherwise require replacement. terraform output only displays outputs. terraform validate checks configuration. terraform fmt reformats files. terraform apply with replace is therefore the correct answer because it provides an explicit supported way to request recreation of a problematic managed object. The resulting plan should be reviewed carefully because replacement typically includes destroying the existing instance and creating another one according to resource lifecycle behavior.
Q51. Which Terraform expression transforms each element of a collection into a new value
- Conditional expression
- For expression
- Backend expression
- Provider expression
Correct Answer: 2. For expression
Explanation
A for expression transforms values from a collection into a new collection and can optionally filter elements using a condition. Conditional expressions select between two values. Backend and provider expressions are not Terraform expression categories for collection transformation. For expression is therefore the correct answer because it allows configurations to derive maps tuples and other values from existing collections. This is useful for generating names selecting attributes or restructuring input data before passing it to resources and modules. Clear expressions should be preferred over unnecessarily complex transformations so configuration remains maintainable.
Q52. Which command lists Terraform CLI workspaces available in the current configuration
- terraform providers
- terraform state list
- terraform workspace list
- terraform show
Correct Answer: 3. terraform workspace list
Explanation
terraform workspace list displays the CLI workspaces available for the current backend configuration and identifies the currently selected workspace. terraform providers displays provider information. terraform state list displays resource addresses in state. terraform show presents state or plan details. terraform workspace list is therefore the correct answer because CLI workspaces allow separate state instances to be associated with the same configuration. Users should understand that workspaces are not a complete isolation mechanism for every environment design and separate configurations may be more appropriate when infrastructure requires substantially different credentials permissions or architecture.
Q53. Which feature lets Terraform automatically discover dependencies between resources
- Resource references
- State removal
- Output formatting
- Provider installation
Correct Answer: 1. Resource references
Explanation
Resource references allow one configuration object to use attributes produced by another object. Terraform analyzes these references and automatically creates dependency relationships in its execution graph. State removal changes what Terraform tracks. Output formatting does not establish dependencies. Provider installation prepares plugins but does not describe resource ordering. Resource references is therefore the correct answer because Terraform generally infers dependencies from data flow rather than requiring explicit sequencing. depends_on should normally be reserved for real dependencies that cannot be expressed through ordinary references because unnecessary explicit dependencies can make plans more conservative.
Q54. Which lifecycle argument tells Terraform to ignore selected external changes to resource attributes
- prevent_destroy
- ignore_changes
- create_before_destroy
- replace_triggered_by
Correct Answer: 2. ignore_changes
Explanation
ignore_changes tells Terraform not to propose updates based on changes to selected resource attributes after the object has been created. prevent_destroy blocks destruction. create_before_destroy changes replacement ordering. replace_triggered_by can cause replacement when specified related values change. ignore_changes is therefore the correct answer when an attribute is intentionally managed partly or entirely outside Terraform after creation. It should be used carefully because ignoring too many attributes can reduce Terraform ability to maintain the desired configuration and can hide meaningful drift that administrators actually need to detect.
Q55. Which Terraform mechanism can check an infrastructure assumption without directly defining a managed resource
- output
- provider
- variable
- check block
Correct Answer: 4. check block
Explanation
A check block allows Terraform to evaluate assertions about infrastructure or configuration without directly representing a managed resource. Output blocks expose values. Provider blocks configure integrations with external services. Variable blocks define inputs. check block is therefore the correct answer because it can verify assumptions and report warnings when conditions are not satisfied. Checks can help confirm operational conditions or relationships after Terraform evaluates infrastructure. They are different from variable validation or resource preconditions because they provide independent continuous assertions rather than controlling whether a particular input or resource operation is permitted to proceed.
Q56. Which function combines multiple maps into a single map
- concat
- length
- merge
- lookup
Correct Answer: 3. merge
Explanation
The merge function combines multiple maps or objects into one resulting value. concat is used with lists. length returns the size of a collection or string. lookup retrieves a specific map value. merge is therefore the correct answer because Terraform configurations frequently need to combine default settings with environment specific or user supplied values. When multiple maps contain the same key later arguments can take precedence according to function behavior. Users should understand this precedence clearly because unintended overwrites can otherwise produce configuration values that differ from expectations.
Q57. Which feature allows a resource to use a provider configuration different from the default
- provider meta argument
- backend argument
- source argument
- sensitive argument
Correct Answer: 1. provider meta argument
Explanation
The provider meta argument allows a resource to explicitly select a particular provider configuration such as an aliased provider instance. The backend argument is related to state configuration. source identifies module or provider source locations depending on context. sensitive controls value display behavior. provider meta argument is therefore the correct answer because configurations may manage infrastructure across multiple regions accounts or endpoints using the same provider type. Resources that need a nondefault provider configuration can reference the appropriate alias so Terraform knows which provider settings should be used.
Q58. Which command switches the current Terraform CLI workspace
- terraform workspace list
- terraform workspace select
- terraform workspace show
- terraform workspace new
Correct Answer: 2. terraform workspace select
Explanation
terraform workspace select changes the currently active CLI workspace to an existing workspace. terraform workspace list displays available workspaces. terraform workspace show displays the name of the current workspace. terraform workspace new creates a new workspace and selects it. terraform workspace select is therefore the correct answer because Terraform operations then use the state associated with the selected workspace. Users should verify the active workspace before planning or applying changes because accidentally operating in the wrong workspace can affect a different set of managed infrastructure than intended.
Q59. Which block can verify a condition before Terraform creates or updates a resource
- output
- locals
- precondition
- moved
Correct Answer: 4. precondition
Explanation
A precondition can verify an assumption that must be true before Terraform proceeds with operations for the associated resource or other supported configuration object. Output blocks expose values. locals define reusable expressions. moved blocks document address changes. precondition is therefore the correct answer because it can prevent Terraform from continuing when required conditions are not satisfied. Preconditions are useful when relationships or constraints cannot be fully expressed through variable types alone. Clear error messages should explain the failed condition so users can correct the configuration or infrastructure assumption before trying the operation again.
Q60. Which HCP Terraform capability can store shared variables for multiple workspaces
- Dependency lock file
- Local values
- Variable sets
- Resource state
Correct Answer: 3. Variable sets
Explanation
Variable sets allow HCP Terraform users to define reusable Terraform or environment variables that can be applied across multiple workspaces or organizational scopes according to configuration. The dependency lock file records provider selections. Local values exist within Terraform configuration. Resource state records managed infrastructure information. Variable sets is therefore the correct answer because teams often need to share common credentials settings or organization wide values without entering the same variables independently in every workspace. Access to sensitive variable values should still be restricted carefully and variables should be scoped only to the workspaces that genuinely require them.