Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A team uses Terraform to manage AWS infrastructure. After a recent update, a state file shows that a security group rule was created, but the rule does not exist in AWS. Running 'terraform plan' shows no changes. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'terraform refresh' command was not run before the plan.

If a security group rule was deleted manually from AWS (e.g., via console or CLI), the state file still contains the resource. Without running 'terraform refresh', Terraform does not detect the deletion and assumes the state is accurate. Thus, 'terraform plan' shows no changes because it compares the current state (which still includes the rule) with the configuration (which likely does define it, otherwise plan would show a destroy). If 'terraform refresh' had been run, the state would be updated to remove the rule, and then plan would show a creation. Option A is incorrect because if the rule were imported into state but not defined in configuration, plan would show a destroy. Option C is incorrect because workspace conflicts typically cause state isolation issues, not missing resources. Option D is incorrect because adding a rule manually would create it, not cause it to be missing; the scenario states the rule does not exist in AWS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The security group rule was imported into state but not defined in configuration.

    Why it's wrong here

    If a resource was imported into state but is absent from configuration, Terraform treats it as an unmanaged resource and will propose a destroy action during plan, because the desired state no longer includes it. The given scenario shows 'no changes,' which is impossible with an orphaned state-only resource. Therefore, the imported-but-undefined rule cannot be the cause; it would produce a removal plan, not zero changes.

  • ✓

    The 'terraform refresh' command was not run before the plan.

    Why this is correct

    When a resource is deleted outside of Terraform, the state still contains the old resource until a refresh reconciles it with the live AWS inventory. Running terraform plan without a preceding terraform refresh — or with refresh explicitly disabled — lets Terraform compare configuration only against stale state, so it concludes the rule still exists and reports no changes. A manual deletion is exactly the kind of drift that refresh is designed to detect; skipping it hides the missing security group rule from the planner.

  • ✗

    There is a conflict between multiple Terraform workspaces.

    Why it's wrong here

    Terraform workspaces are isolated state files for the same configuration; they don't cause a resource to vanish from AWS while remaining in a single workspace's state. A conflict between workspaces would manifest as unexpected resource creation/destruction or state file mixing, not as a plan that reports no changes when the security group rule is absent. Since the rule is missing in AWS yet present in the state used by the current workspace, this points to drift, not workspace multiplexing.

  • ✗

    The security group rule was added manually via the AWS console and is not managed by Terraform, causing state to be out of sync.

    Why it's wrong here

    Manually adding a security group rule via the AWS console would create an untracked resource in AWS, making state under-complete rather than over-complete. In that case, the rule would actually exist in the account, but the scenario says the rule does not exist, so this explanation contradicts the premise. Even if the manual rule were never imported or defined, Terraform plan would still see the existing rule as outside its management and would not plan changes — but it wouldn't explain a missing resource.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.