terraform-associate-003 Sample Questions & Answers
Provider installation and plugin architecture ties with the write-plan-create workflow and variable or secret handling for the top weighting, alongside IaC's advantages, import versus refresh, module input and output scope, state locking, and HCP Terraform.
Launch the full terraform-associate-003 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Read, Generate, and Modify Configuration · Demonstrate use of variables and outputs
A developer is writing a Terraform configuration and needs to ensure that a variable
instance_countis always a positive integer greater than zero. Which of the following code blocks correctly implements this validation?Show answer & explanation
Correct answer: B
This is the correct syntax. The
validationblock (notvalidate) is used within avariableblock. Theconditionargument must be a boolean expression that is true for the value to be valid. Here,var.instance_count > 0checks for positivity, andfloor(var.instance_count) == var.instance_countis a standard way to check if a number is a whole number (an integer). Theerror_messageis returned if the condition is false. - Question 2BeginnerSelect 2
Interact with Terraform Modules · Contrast and use different module sources
Which of the following are valid sources for a Terraform module in a
moduleblock? (Select TWO)Show answer & explanation
Correct answers: C, E
This is a valid Git source URL. The
git::prefix indicates the source type, and the?ref=argument is used to pin the module to a specific branch, tag, or commit hash.This is a valid shorthand for a module from the public Terraform Registry. It follows the
/ /format. - Question 3Advanced
Understand Terraform Basics · Install and version Terraform providers
A CI/CD pipeline running on a Linux agent executes
terraform plan. The same configuration, when planned on a developer's macOS laptop, shows no changes. However, the pipeline's plan shows a provider version change and wants to update the lock file. What is the most likely cause of this discrepancy?Show answer & explanation
Correct answer: A
The
.terraform.lock.hclfile records dependency checksums for each provider for each platform (OS and architecture) it has been initialized on. Ifterraform initwas only run on macOS, the lock file will only contain hashes fordarwin_amd64ordarwin_arm64. When the CI/CD pipeline runs on Linux (linux_amd64), it won't find a matching hash, forcing it to select a provider version based on the constraints and add the new platform's hash to the lock file. To prevent this,terraform providers lock -platform=linux_amd64 -platform=darwin_amd64should be run. - Question 4Intermediate
Read, Generate, and Modify Configuration · Create and differentiate resource and data configuration
A new team member runs
terraform planand receives an error message:Error: Missing required argument. The missing argument is for a resource that is created by a colleague's configuration in a separate directory. The team is using a shared remote state backend. What is the most effective way to resolve this error?Show answer & explanation
Correct answer: A
The
terraform_remote_statedata source is the standard way to share information between separate Terraform configurations. It allows one configuration to access the output values of another. By adding this data source and configuring it to point to the colleague's remote state, the new team member can reference the required values (like a VPC ID or subnet ID) without duplicating resource definitions. - Question 5Beginner
Understand HCP Terraform Capabilities · Describe HCP Terraform workspaces
When working with HCP Terraform, what is the primary purpose of a workspace?
Show answer & explanation
Correct answer: C
In HCP Terraform (and Terraform Cloud), a workspace is a container for everything Terraform needs to manage a collection of infrastructure: the configuration itself (often from a VCS repository), the values for input variables, and most importantly, its own separate state file. This allows teams to manage different environments (dev, staging, prod) or components from the same configuration codebase with isolated state and variables.
- Question 6IntermediateSelect 3
Implement and Maintain State · Differentiate remote state back end options
What are the key benefits of using a remote backend such as Amazon S3 with DynamoDB instead of the default local backend? (Select THREE)
Show answer & explanation
Correct answers: C, E, F
Storing state centrally is a primary reason for using a remote backend. It allows all team members to work from the same understanding of the infrastructure's current state.
Remote backends like S3 with DynamoDB support state locking, which is crucial for team collaboration. It ensures only one person can run
applyat a time, preventing state corruption.Most remote backends, including Amazon S3, support server-side encryption. This is a critical security feature, as state files can often contain sensitive information.
- Question 7Intermediate
Implement and Maintain State · Describe state locking
During a
terraform apply, an engineer accidentally closes their terminal. Upon re-runningterraform apply, they receive an error indicating the state is locked. The lock ID belongs to the original, terminated process. What is the safest command to resolve this situation?Show answer & explanation
Correct answer: A
The
terraform force-unlockcommand is designed specifically for this scenario, where a lock is held by a defunct process and cannot be released automatically. It manually removes the specified lock ID, allowing other operations to proceed. Before running it, one should always verify that no other operation is genuinely in progress to avoid state corruption. - Question 8Advanced
Read, Generate, and Modify Configuration · Use resource addressing and resource parameters
A platform team provides a Terraform module for creating standardized Kubernetes clusters. To ensure compliance, they need to prevent users from creating clusters with public endpoints. Which Terraform feature allows them to embed this rule directly into their module or configuration?
Show answer & explanation
Correct answer: B
The
lifecycleblock'spreconditionchecks a condition before a resource is created, updated, or destroyed. This is the ideal place to enforce policies about the configuration of a resource itself. The team can add apreconditionthat checks if the public endpoint variable is false. If a user tries to set it to true, theterraform planorapplywill fail with the custom error message provided in the precondition, thus enforcing the compliance rule. - Question 9Advanced
Use Terraform Outside the Core Workflow · Use terraform state to modify Terraform state
A team has decided to refactor their monolithic Terraform configuration by moving a set of
aws_s3_bucketresources into a new, dedicated module. Which sequence of Terraform commands represents the safest workflow to perform this refactoring without causing downtime or resource recreation?Show answer & explanation
Correct answer: B
This is the correct and safest procedure. When you move HCL code for a resource into a module, its address in the Terraform state changes (e.g., from
aws_s3_bucket.my_buckettomodule.my_module.aws_s3_bucket.my_bucket). If you just runapply, Terraform will think you want to destroy the old resource and create a new one. Theterraform state mvcommand allows you to update the state file to reflect the new address, telling Terraform that the existing resource is now managed by the code in the new location. A successful refactor will result in aterraform planthat shows no infrastructure changes. - Question 10Beginner
Read, Generate, and Modify Configuration · Use resource addressing and resource parameters
You are tasked with creating a set of similarly configured virtual machines, but the exact number is not known in advance and will be determined by the length of a list variable. Which meta-argument should you use in your
resourceblock?Show answer & explanation
Correct answer: C
The
countmeta-argument is used to create a specific number of instances of a resource. It is ideal when the resources are nearly identical and can be differentiated by an index number (count.index). You can setcount = length(var.my_list)to create one resource for each item in the list. Whilefor_eachalso creates multiple resources, it is used when you need to iterate over a map or a set of strings and use unique keys for each resource instance.
Ready for the real thing?
The full terraform-associate-003 simulator has every exam-style question, timed mode, and instant scoring.