TAO-Pro Sample Questions

TAO-Pro Sample Questions & Answers

Validating configuration, querying data sources, and computing values with HCL functions carries the biggest weight, alongside running init, plan, and apply, remote-state workflows, authoring and versioning modules, provider configuration, and HCP Terraform runs.

Launch the full TAO-Pro simulator →

Showing 8 of 17 free samples.

  1. Question 1Intermediate

    Develop and Troubleshoot Dynamic Configuration · Use language features to validate configuration

    You are developing a Terraform module that creates an S3 bucket. You want to validate that the bucket name passed via the input variable bucket_name meets AWS naming requirements: it must be between 3 and 63 characters long and must start with a lowercase letter or number. You decide to use a validation block within the variable declaration. Which configuration correctly implements this?

    Show answer & explanation

    Correct answer: A

    This validation block uses length() to check the size constraints and can(regex(...)) to verify the starting character. The condition must return true for valid inputs.

  2. Question 2Advanced

    Develop and Troubleshoot Dynamic Configuration · Configure input variables and outputs, including complex types

    You are creating a reusable Terraform module for an AWS VPC. The module must accept a list of subnet objects, where each object has a cidr (string) and an optional tags (map of strings). If tags is omitted, it should default to an empty map. Which type constraint correctly defines this input variable using Terraform's optional object attributes feature?

    Show answer & explanation

    Correct answer: B

    The optional(type, default) syntax allows you to mark an object attribute as optional. If the attribute is missing, Terraform inserts the provided default value (an empty map {} in this case). This is the correct way to handle optional complex attributes.

  3. Question 3Beginner

    Configure and Use Terraform Providers · Troubleshoot provider errors

    During a terraform apply, you encounter a provider error related to API rate limiting. You need to gather more detailed information about the HTTP requests being made by the AWS provider to debug the issue. Which environment variable should you set to enable the most verbose logging specifically for Terraform core and providers?

    Show answer & explanation

    Correct answer: A

    TF_LOG is the standard environment variable to control logging. TRACE is the most verbose level, showing detailed internal logs including HTTP requests and responses from providers.

  4. Question 4Beginner

    Develop Collaborative Terraform Workflows · Configure remote state

    You are managing a Terraform configuration that uses a local backend. You have been tasked with migrating this state to an S3 backend with DynamoDB locking. After configuring the backend "s3" block in your terraform.tf file, what is the next command you must run to successfully migrate the existing state data to the new backend?

    Show answer & explanation

    Correct answer: C

    When the backend configuration changes, terraform init detects the change. To copy the existing state data from the old backend (local) to the new one (S3), you must run terraform init. While terraform init alone often prompts for migration, explicitly using -migrate-state (or confirming the prompt) is the specific action required to move the data.

  5. Question 5Intermediate

    Collaborate on Infrastructure as Code Using HCP Terraform · Manage provider credentials in HCP Terraform

    You are using HCP Terraform (formerly Terraform Cloud) and want to provision infrastructure in AWS. You need to authenticate the AWS provider without hardcoding long-lived access keys in your workspace variables. Which feature should you configure to allow HCP Terraform to authenticate with AWS using temporary, rotating credentials via OpenID Connect (OIDC)?

    Show answer & explanation

    Correct answer: D

    Dynamic Provider Credentials in HCP Terraform allow you to configure a trust relationship between HCP Terraform and AWS (via OIDC). HCP Terraform exchanges a signed JWT token for temporary AWS credentials at runtime, eliminating the need for static access keys.

  6. Question 6Beginner

    Create, Maintain, and Use Terraform Modules · Use a module in configuration

    You are refactoring a Terraform configuration that manages an AWS VPC. You want to extract the security group rules into a separate module. However, the security groups themselves must remain in the root module. You need to pass the security group ID from the root module to the new child module. Which Terraform concept facilitates this data flow?

    Show answer & explanation

    Correct answer: B

    To pass data into a child module, you define an input variable in the child module and assign a value to it in the module block in the root configuration.

  7. Question 7Advanced

    Manage Resource Lifecycle · Manage resource state, including importing resources and reconciling resource drift

    A developer has defined a resource aws_s3_bucket.data with count = 3. They now realize that managing these buckets by numerical index is brittle, as removing the first bucket causes the remaining two to be renamed and recreated. They decide to switch to for_each using a map of bucket names. What is the critical step they must take to ensure the existing buckets are mapped to the new string-based keys without deletion?

    Show answer & explanation

    Correct answer: C

    When switching from count (integer index) to for_each (string key), the resource addresses in the state file change. Without moved blocks, Terraform sees the old indexed resources as 'to be destroyed' and the new keyed resources as 'to be created'. moved blocks instruct Terraform to rename the state entries, preserving the resources.

  8. Question 8Intermediate

    Develop and Troubleshoot Dynamic Configuration · Use language features to validate configuration

    You are designing a Terraform workflow for a regulated industry. You need to enforce a policy that checks if an S3 bucket is public before the infrastructure is provisioned. If the plan indicates the bucket will be public, the run should fail immediately. Which feature allows you to define this assertion directly within the HCL configuration to run during the planning phase?

    Show answer & explanation

    Correct answer: A

    A precondition block inside the lifecycle block of a resource allows you to define assertions about the resource's configuration (or data sources) that must be true before the resource is applied. This is evaluated during the plan phase.

Ready for the real thing?

The full TAO-Pro simulator has every exam-style question, timed mode, and instant scoring.