Get Oct-2026 Download Latest & Valid Questions For HashiCorp Terraform-Associate-004 exam
Ensure Success With Updated Verified Terraform-Associate-004 Exam Dumps
HashiCorp Terraform-Associate-004 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
NEW QUESTION # 14
Which command generates DOT (Document Template) formatted data to visualize Terraform dependencies?
- A. terraform output
- B. terraform graph
- C. terraform refresh
- D. terraform show
Answer: B
Explanation:
Rationale for Correct Answer: terraform graph outputs a Graphviz DOT representation of Terraform's dependency graph, which you can pipe into Graphviz tools (e.g., dot) to visualize resource/module dependencies.
Analysis of Incorrect Options (Distractors):
B: terraform show displays state or a plan file in human-readable form (or JSON with -json), not DOT.
C: terraform refresh (deprecated as a standalone command in newer workflows) refreshes state, not graph output.
D: terraform output prints root module outputs, not dependency graphs.
Key Concept: Visualizing Terraform's dependency graph using terraform graph.
Reference: Terraform Objectives - Understand Terraform Basics and CLI (CLI commands and troubleshooting/visualization).
NEW QUESTION # 15
Which two steps are required to provision new infrastructure in the Terraform workflow? Choose two correct answers.
- A. Alidate
- B. apply
- C. Import
- D. Plan
- E. Init
Answer: B,E
Explanation:
The two steps that are required to provision new infrastructure in the Terraform workflow are init and apply. The terraform init command initializes a working directory containing Terraform configuration files. It downloads and installs the provider plugins that are needed for the configuration, and prepares the backend for storing the state. The terraform apply command applies the changes required to reach the desired state of the configuration, as described by the resource definitions in the configuration files. It shows a plan of the proposed changes and asks for confirmation before making any changes to the infrastructure. Reference = [The Core Terraform Workflow], [Initialize a Terraform working directory with init], [Apply Terraform Configuration with apply]
NEW QUESTION # 16
Why would you use the -replace flag for terraform apply?
- A. You want Terraform to ignore a resource on the next apply
- B. You want to force Terraform to destroy and recreate a resource on the next apply
- C. You want to force Terraform to destroy a resource on the next apply
- D. You want Terraform to destroy all the infrastructure in your workspace
Answer: B
Explanation:
The -replace flag is used with the terraform apply command when there is a need to explicitly force Terraform to destroy and then recreate a specific resource during the next apply. This can be necessary in situations where a simple update is insufficient or when a resource must be re-provisioned to pick up certain changes.
NEW QUESTION # 17
What is the name of the default file where Terraform stores the state?
Type your answer in the field provided. The text field is not case-sensitive and all variations of the correct answer are accepted.
Answer:
Explanation:
Terraform.tfstate
Explanation:
The name of the default file where Terraform stores the state is terraform.tfstate. This file contains a JSON representation of the current state of the infrastructure managed by Terraform. Terraform uses this file to track the metadata and attributes of the resources, and to plan and apply changes. By default, Terraform stores the state file locally in the same directory as the configuration files, but it can also be configured to store the state remotely in a backend. References = [Terraform State], [State File Format]
NEW QUESTION # 18
Terraform can only manage resource dependencies if you set them explicitly with the depends_on argument.
- A. False
- B. True
Answer: A
Explanation:
Terraform can manage resource dependencies implicitly or explicitly. Implicit dependencies are created when a resource references another resource or data source in its arguments. Terraform can infer the dependency from the reference and create or destroy the resources in the correct order. Explicit dependencies are created when you use the depends_on argument to specify that a resource depends on another resource or module.
This is useful when Terraform cannot infer the dependency from the configuration or when you need to create a dependency for some reason outside of Terraform's scope. References = : Create resource dependencies : Terraform Resource Dependencies Explained
NEW QUESTION # 19
You have a simple Terraform configuration containing one virtual machine (VM) in a cloud provider. You run terraform apply and the VM is created successfully. What will happen if you terraform apply again immediately afterward without changing any Terraform code?
- A. Terraform will terminate and recreate the VM.
- B. Terraform will create another duplicate VM.
- C. Terraform will apply the VM to the state file.
- D. Nothing
Answer: D
Explanation:
Terraform follows adeclarativeapproach, meaning it ensures the infrastructure matches the configuration.
If you run terraform apply againwithout any changes, Terraform willdetect that the infrastructure is already up to dateand willdo nothing.
The command will complete successfully with the message"No changes. Your infrastructure matches the configuration." Official Terraform Documentation Reference:
Terraform Apply - HashiCorp Documentation
NEW QUESTION # 20
You can define multiple backend blocks in your Terraform configuration to store your state in multiple locations.
- A. False
- B. True
Answer: A
Explanation:
Rationale for Correct Answer: A Terraform configuration supports only one backend at a time. The backend determines where state is stored and how locking works. Terraform does not support writing the same state to multiple backends simultaneously via multiple backend blocks.
Analysis of Incorrect Options (Distractors):
A (True): Incorrect-Terraform allows only a single backend configuration for a given working directory/root module.
Key Concept: Single-backend design: one state location per configuration/workspace.
Reference: Terraform Objectives - Navigate Terraform State and Backends (backend configuration and limitations).
NEW QUESTION # 21
Which of the following is not a way to trigger terraform destroy?
- A. All of these will trigger terraform destroy
- B. terraform destroy -auto-approve
- C. terraform plan -destroy
- D. terraform destroy
Answer: C
Explanation:
Rationale for Correct Answer: terraform plan -destroy does not destroy anything. It only creates a plan that proposes destroying all managed resources. Actual destruction happens only when you run terraform destroy or terraform apply with an approved destroy plan.
Analysis of Incorrect Options (Distractors):
A: Does trigger destruction (interactive approval by default).
B: Incorrect because terraform plan -destroy does not perform destruction.
D: Does trigger destruction and skips the interactive approval prompt.
Key Concept: Difference between planning a destroy and executing a destroy.
Reference: Terraform Objectives - Understand Terraform Basics and CLI (plan vs apply/destroy behaviors).
NEW QUESTION # 22
You can access state stored with the local backend by using terraform_remote_state data source.
- A. False
- B. True
Answer: A
Explanation:
You cannot access state stored with the local backend by using the terraform_remote_state data source. The terraform_remote_state data source is used to retrieve the root module output values from some other Terraform configuration using the latest state snapshot from the remote backend. It requires a backend that supports remote state storage, such as S3, Consul, AzureRM, or GCS. The local backend stores the state file locally on the filesystem, which terraform_remote_state cannot access.
Reference:
Terraform documentation on terraform_remote_state data source: Terraform Remote State Data Source Example usage of remote state: Example Usage (remote Backend)
NEW QUESTION # 23
The Terraform binary version and provider versions must match each other in a single configuration.
- A. False
- B. True
Answer: A
Explanation:
The Terraform binary version and provider versions do not have to match each other in a single configuration. Terraform allows you to specify provider version constraints in the configuration's terraform block, which can be different from the Terraform binary version1. Terraform will use the newest version of the provider that meets the configuration's version constraints2. You can also use the dependency lock file to ensure Terraform is using the correct provider version3. Reference =
* 1: Providers - Configuration Language | Terraform | HashiCorp Developer
* 2: Multiple provider versions with Terraform - Stack Overflow
* 3: Lock and upgrade provider versions | Terraform - HashiCorp Developer
NEW QUESTION # 24
Where in your Terraform configuration do you specify remote state storage settings?
- A. The terraform block
- B. The data block
- C. The provider block
- D. The resource block
Answer: A
Explanation:
Rationale for Correct Answer: Remote state storage is configured using a backend block, which lives inside the top-level terraform block (for example, terraform { backend " s3 " { ... } }). Backends control where Terraform stores state (local vs remote), locking, and related settings-this is squarely in the Terraform configuration's global settings area, not in resources or providers.
Analysis of Incorrect Options (Distractors):
A (The resource block): Resources define infrastructure objects (e.g., servers, buckets). They do not configure where Terraform stores state.
B (The provider block): Providers configure how Terraform talks to an API (credentials/regions/features).
They don't define state storage.
C (The data block): Data sources read existing infrastructure; they are unrelated to backend/state storage configuration.
Key Concept: Backends and remote state configuration using terraform { backend ... }.
Reference: Terraform Objectives - Navigate Terraform State and Backends (backends/remote state), Implement and Maintain State (state storage and locking).
NEW QUESTION # 25
You want to use API tokens and other secrets within your team's Terraform workspaces. Where does HashiCorp recommend you store these sensitive values? (Pick the 3 correct responses)
- A. In a terraform.tfvars file, checked into your version control system.
- B. In a terraform.tfvars file, securely managed and shared with your team.
- C. In a plaintext document on a shared drive.
- D. In an HCP Terraform/Terraform Cloud variable, with the sensitive option checked.
- E. In HashiCorp Vault.
Answer: B,D,E
Explanation:
Sensitive values such as API tokens should be stored in a secure way, either in Terraform Cloud variables marked as sensitive or in HashiCorp Vault. Storing secrets in version control systems or plaintext files is not recommended.
References:
Terraform Cloud Environment Variables
NEW QUESTION # 26
If a module declares a variable without a default value, you must pass the value of the variable within the module block when you call the module in your configuration.
- A. False
- B. True
Answer: B
Explanation:
Rationale for Correct Answer (True):
Variables without defaults are required inputs. If the calling module doesn't supply a value, Terraform will fail with an error at plan time.
Analysis of Incorrect Option:
False: Incorrect, because Terraform does not assume defaults when none are provided.
Key Concept:
Terraform modules enforce required vs. optional variables depending on whether a default is set.
Reference:
Terraform Exam Objective - Interact with Terraform Modules.
NEW QUESTION # 27
Your team uses HCP Terraform to manage infrastructure. You need to make a change to an infrastructure stack running in a public cloud. Which pattern follows Infrastructure as Code best practices for making the change?
- A. Run the public cloud CLI tool to make the change.
- B. Submit a pull request and wait for an approved merge of the change.
- C. Make the change through the public cloud API endpoint.
- D. Use the public cloud console to make the change.
- E. Clone the repository containing your infrastructure code, and then run the code.
Answer: B
Explanation:
Detailed Explanation:
* Rationale for Correct Answer: Infrastructure as Code best practice is to make infrastructure changes through version-controlled configuration. With HCP Terraform, a common and recommended workflow is to modify Terraform code in a branch, submit a pull request, review and approve the change, merge it, and let HCP Terraform execute the run based on that VCS-driven workflow. This preserves review history, auditability, collaboration, and consistency.
* Analysis of Incorrect Options (Distractors):
* A. Clone the repository containing your infrastructure code, and then run the code. Incorrect.
Running locally can bypass centralized HCP Terraform workflow controls, policy checks, approvals, and audit trails.
* B. Use the public cloud console to make the change. Incorrect. Console changes create configuration drift and bypass Terraform state and version control.
* C. Make the change through the public cloud API endpoint. Incorrect. Direct API changes bypass Terraform and can cause drift.
* D. Run the public cloud CLI tool to make the change. Incorrect. Cloud CLI changes are imperative changes outside Terraform's managed workflow.
* Key Concept: Infrastructure changes should be made through version-controlled Terraform configuration and reviewed before being applied.
Reference: Terraform Objective Domain: Understand Infrastructure as Code (IaC) Concepts
NEW QUESTION # 28
A provider configuration block is required in every Terraform configuration.
Example:
- A. False
- B. True
Answer: A
Explanation:
A provider configuration block is not required in every Terraform configuration. A provider configuration block can be omitted if its contents would otherwise be empty. Terraform assumes an empty default configuration for any provider that is not explicitly configured. However, some providers may require some configuration arguments (such as endpoint URLs or cloud regions) before they can be used. A provider's documentation should list which configuration arguments it expects. For providers distributed on the Terraform Registry, versioned documentation is available on each provider's page, via the "Documentation" link in the provider's header1. References = [Provider Configuration]1
NEW QUESTION # 29
What functionality do providers offer in Terraform?(Pick 3 correct responses)
- A. Provision resources for on-premises infrastructure services.
- B. Group a collection of Terraform configuration files that map to a single state file.
- C. Provision resources for public cloud infrastructure services.
- D. Enforce security and compliance policies.
- E. Interact with cloud provider APIs.
Answer: A,C,E
Explanation:
A (#Correct)- Providers allow Terraform tointeract with APIsof cloud/on-premises services.
B (#Correct)- Some Terraform providers can provisionon-premises infrastructure, such as VMware, OpenStack, etc.
C (#Incorrect)- This describesTerraform Workspaces, not providers.
D (#Correct)- Terraform providers allow provisioning ofpublic cloud resources(AWS, Azure, GCP, etc.).
E (#Incorrect)- Enforcing security and compliance policies isnot a direct provider function, but it can be done using Sentinel or other policy-as-code tools.
Official Terraform Documentation Reference:
Terraform Providers
NEW QUESTION # 30
You need to destroy all of the resources in your Terraform workspace, except for aws_instance.ubuntu[1], which you want to keep. How can you tell Terraform to stop managing that specific resource without destroying it?
- A. Use a moved block.
- B. Run terraform state rm aws_instance.ubuntu[1].
- C. Change the value of the count argument on the resource.
- D. Remove the resource block from your configuration.
Answer: B
Explanation:
Rationale for Correct answer: terraform state rm <address> removes a resource from Terraform state without destroying the real infrastructure. After removal, Terraform "forgets" it and will no longer manage it (unless it's re-imported). That matches the requirement: keep the resource, stop managing it.
Analysis of Incorrect Options (Distractors):
A: Removing the resource block causes Terraform to plan to destroy the resource (because it's in state but no longer in config), which is the opposite of "keep it." B: Changing count can cause Terraform to destroy instances that no longer have an address (depending on indexing), and it doesn't explicitly "stop managing" a specific existing instance safely.
D: moved blocks are for renaming/refactoring addresses while keeping management; they do not stop managing a resource.
Key Concept: Detaching resources from Terraform management using state subcommands (terraform state rm).
Reference:
NEW QUESTION # 31
......
Exam Materials for You to Prepare & Pass Terraform-Associate-004 Exam: https://actualtests.dumpsquestion.com/Terraform-Associate-004-exam-dumps-collection.html