terraform-associate-003 Sample Questions

terraform-associate-003 Sample Questions & Answers

Provider installation and plugin architecture ties with the write-plan-create workflow and variable or secret handling for the top weighting, alongside IaC's advantages, import versus refresh, module input and output scope, state locking, and HCP Terraform.

Launch the full terraform-associate-003 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Read, Generate, and Modify Configuration · Demonstrate use of variables and outputs

    A developer is writing a Terraform configuration and needs to ensure that a variable instance_count is always a positive integer greater than zero. Which of the following code blocks correctly implements this validation?

    Show answer & explanation

    Correct answer: B

    This is the correct syntax. The validation block (not validate) is used within a variable block. The condition argument must be a boolean expression that is true for the value to be valid. Here, var.instance_count > 0 checks for positivity, and floor(var.instance_count) == var.instance_count is a standard way to check if a number is a whole number (an integer). The error_message is returned if the condition is false.

  2. Question 2BeginnerSelect 2

    Interact with Terraform Modules · Contrast and use different module sources

    Which of the following are valid sources for a Terraform module in a module block? (Select TWO)

    Show answer & explanation

    Correct answers: C, E

    This is a valid Git source URL. The git:: prefix indicates the source type, and the ?ref= argument is used to pin the module to a specific branch, tag, or commit hash.

    This is a valid shorthand for a module from the public Terraform Registry. It follows the / / format.

  3. Question 3Advanced

    Understand Terraform Basics · Install and version Terraform providers

    A CI/CD pipeline running on a Linux agent executes terraform plan. The same configuration, when planned on a developer's macOS laptop, shows no changes. However, the pipeline's plan shows a provider version change and wants to update the lock file. What is the most likely cause of this discrepancy?

    Show answer & explanation

    Correct answer: A

    The .terraform.lock.hcl file records dependency checksums for each provider for each platform (OS and architecture) it has been initialized on. If terraform init was only run on macOS, the lock file will only contain hashes for darwin_amd64 or darwin_arm64. When the CI/CD pipeline runs on Linux (linux_amd64), it won't find a matching hash, forcing it to select a provider version based on the constraints and add the new platform's hash to the lock file. To prevent this, terraform providers lock -platform=linux_amd64 -platform=darwin_amd64 should be run.

  4. Question 4Intermediate

    Read, Generate, and Modify Configuration · Create and differentiate resource and data configuration

    A new team member runs terraform plan and receives an error message: Error: Missing required argument. The missing argument is for a resource that is created by a colleague's configuration in a separate directory. The team is using a shared remote state backend. What is the most effective way to resolve this error?

    Show answer & explanation

    Correct answer: A

    The terraform_remote_state data source is the standard way to share information between separate Terraform configurations. It allows one configuration to access the output values of another. By adding this data source and configuring it to point to the colleague's remote state, the new team member can reference the required values (like a VPC ID or subnet ID) without duplicating resource definitions.

  5. Question 5Beginner

    Understand HCP Terraform Capabilities · Describe HCP Terraform workspaces

    When working with HCP Terraform, what is the primary purpose of a workspace?

    Show answer & explanation

    Correct answer: C

    In HCP Terraform (and Terraform Cloud), a workspace is a container for everything Terraform needs to manage a collection of infrastructure: the configuration itself (often from a VCS repository), the values for input variables, and most importantly, its own separate state file. This allows teams to manage different environments (dev, staging, prod) or components from the same configuration codebase with isolated state and variables.

  6. Question 6IntermediateSelect 3

    Implement and Maintain State · Differentiate remote state back end options

    What are the key benefits of using a remote backend such as Amazon S3 with DynamoDB instead of the default local backend? (Select THREE)

    Show answer & explanation

    Correct answers: C, E, F

    Storing state centrally is a primary reason for using a remote backend. It allows all team members to work from the same understanding of the infrastructure's current state.

    Remote backends like S3 with DynamoDB support state locking, which is crucial for team collaboration. It ensures only one person can run apply at a time, preventing state corruption.

    Most remote backends, including Amazon S3, support server-side encryption. This is a critical security feature, as state files can often contain sensitive information.

  7. Question 7Intermediate

    Implement and Maintain State · Describe state locking

    During a terraform apply, an engineer accidentally closes their terminal. Upon re-running terraform apply, they receive an error indicating the state is locked. The lock ID belongs to the original, terminated process. What is the safest command to resolve this situation?

    Show answer & explanation

    Correct answer: A

    The terraform force-unlock command is designed specifically for this scenario, where a lock is held by a defunct process and cannot be released automatically. It manually removes the specified lock ID, allowing other operations to proceed. Before running it, one should always verify that no other operation is genuinely in progress to avoid state corruption.

  8. Question 8Advanced

    Read, Generate, and Modify Configuration · Use resource addressing and resource parameters

    A platform team provides a Terraform module for creating standardized Kubernetes clusters. To ensure compliance, they need to prevent users from creating clusters with public endpoints. Which Terraform feature allows them to embed this rule directly into their module or configuration?

    Show answer & explanation

    Correct answer: B

    The lifecycle block's precondition checks a condition before a resource is created, updated, or destroyed. This is the ideal place to enforce policies about the configuration of a resource itself. The team can add a precondition that checks if the public endpoint variable is false. If a user tries to set it to true, the terraform plan or apply will fail with the custom error message provided in the precondition, thus enforcing the compliance rule.

  9. Question 9Advanced

    Use Terraform Outside the Core Workflow · Use terraform state to modify Terraform state

    A team has decided to refactor their monolithic Terraform configuration by moving a set of aws_s3_bucket resources into a new, dedicated module. Which sequence of Terraform commands represents the safest workflow to perform this refactoring without causing downtime or resource recreation?

    Show answer & explanation

    Correct answer: B

    This is the correct and safest procedure. When you move HCL code for a resource into a module, its address in the Terraform state changes (e.g., from aws_s3_bucket.my_bucket to module.my_module.aws_s3_bucket.my_bucket). If you just run apply, Terraform will think you want to destroy the old resource and create a new one. The terraform state mv command allows you to update the state file to reflect the new address, telling Terraform that the existing resource is now managed by the code in the new location. A successful refactor will result in a terraform plan that shows no infrastructure changes.

  10. Question 10Beginner

    Read, Generate, and Modify Configuration · Use resource addressing and resource parameters

    You are tasked with creating a set of similarly configured virtual machines, but the exact number is not known in advance and will be determined by the length of a list variable. Which meta-argument should you use in your resource block?

    Show answer & explanation

    Correct answer: C

    The count meta-argument is used to create a specific number of instances of a resource. It is ideal when the resources are nearly identical and can be differentiated by an index number (count.index). You can set count = length(var.my_list) to create one resource for each item in the list. While for_each also creates multiple resources, it is used when you need to iterate over a map or a set of strings and use unique keys for each resource instance.

Ready for the real thing?

The full terraform-associate-003 simulator has every exam-style question, timed mode, and instant scoring.