hardMultiple Choice
CV0-004 Practice Question: After reviewing the Terraform plan, a cloud…
Exhibit
Refer to the exhibit.
```
$ terraform plan
...
# aws_instance.web will be created
+ resource "aws_instance" "web" {
+ ami = "ami-0c55b159cbfafe1f0"
+ instance_type = "t2.micro"
+ subnet_id = "subnet-06e3d2f8a8b9c1234"
+ vpc_security_group_ids = [
+ "sg-0123456789abcdef0",
]
+ associate_public_ip_address = true
+ user_data = <<-EOT
#!/bin/bash
apt-get update
apt-get install -y nginx
systemctl enable nginx
EOT
+ tags = {
+ "Name" = "web-server"
}
}
Plan: 1 to add, 0 to change, 0 to destroy.
```After reviewing the Terraform plan, a cloud administrator notices that the instance will be created with a public IP address. However, the company policy requires that all instances in this subnet remain private. What should the administrator do to meet the policy before applying the plan?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the 'associate_public_ip_address' argument to 'false' in the resource block.
Setting 'associate_public_ip_address' to false in the Terraform resource block explicitly prevents the instance from receiving a public IP address, directly adhering to the policy. Option A is wrong: using user_data to remove the public IP after boot is unreliable, creates a temporary exposure, and violates the principle of declarative infrastructure. Option B is wrong: the AMI choice does not control public IP assignment; that is determined by subnet settings and resource arguments. Option D is wrong: changing to a private subnet might work if it disables auto-assign public IP, but it is unnecessary and could have other implications; the direct fix is to set the argument to false.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a shell command in user_data to remove the public IP after boot.
Why it's wrong here
user_data runs after the instance launches, so the public IP exists during boot and the policy is breached before removal; Terraform would also show drift on the next plan. user_data suits boot-time configuration such as package installation, not enforcing network posture at creation.
- ✗
Use a different AMI that does not require public access.
Why it's wrong here
The AMI governs the operating system image, not whether the instance receives a public IP; that is set by the subnet's map_public_ip_on_launch attribute or the instance's associate_public_ip_address argument. A different AMI would be chosen to change the OS, not the network exposure.
- ✓
Change the 'associate_public_ip_address' argument to 'false' in the resource block.
Why this is correct
Setting `associate_public_ip_address` to `false` directly removes the public IP assignment from the instance's network interface, satisfying the policy that all instances in this subnet remain private. This argument controls the instance-level public addressing behaviour, so the plan no longer provisions a public address before apply.
- ✗
Modify the subnet_id to point to a private subnet with no internet gateway.
Why it's wrong here
Changing subnet_id relocates the instance but does not itself disable public addressing; a private subnet still assigns a public IP if map_public_ip_on_launch is true, and the plan would still show one. Subnet selection is the right lever when the target subnet's addressing behaviour is already correct.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.