TF-004 Read, generate and modify configuration Practice Question
A developer is writing a Terraform configuration that uses a `variable` block to define an input variable `region` with a default value of `us-west-2`. The developer wants to ensure that the variable can only be set to one of three approved regions: `us-west-2`, `us-east-1`, or `eu-west-1`. Which approach should the developer use?
⚠ Common exam trap
The trap here is assuming that Terraform has a built-in `allowed_values` argument or that changing the variable type can restrict values, when only a `validation` block provides that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a `validation` block with a `condition` that checks if `var.region` is in the list of approved regions.
Terraform's `variable` block supports `validation` blocks that define a `condition` and an `error_message`. The condition can use functions like `contains` to check if the provided value is within a list of approved options. This validation occurs during plan and apply, preventing invalid values from being used. It is the standard way to enforce custom constraints on input variables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the variable type to `string` and use a `default` value that is a list of the approved regions.
Why it's wrong here
The `default` value must match the variable type. If the type is `string`, the default cannot be a list. Moreover, a default does not restrict the values that can be provided; it only sets a fallback. This approach would not enforce the allowed regions and would likely cause a type mismatch error.
- ✗
Define the variable with type `list(string)` and set the default to the approved regions, then use `contains` in the resource.
Why it's wrong here
Changing the variable type to `list(string)` would require the input to be a list, not a single string. This contradicts the intended use of a single region. While `contains` can be used in expressions, it would not validate the input variable itself; it would only check within the resource configuration, potentially leading to runtime errors instead of plan-time validation.
- ✓
Add a `validation` block with a `condition` that checks if `var.region` is in the list of approved regions.
Why this is correct
The `validation` block within a `variable` allows custom validation rules using a `condition` expression and an `error_message`. By checking if `var.region` is contained in the list of approved regions, the developer enforces the constraint at plan time. If the condition is false, Terraform returns the specified error message and halts execution.
- ✗
Use the `allowed_values` argument in the `variable` block to specify the permitted regions.
Why it's wrong here
Terraform does not support an `allowed_values` argument in `variable` blocks. While some other tools use similar constructs, Terraform relies on `validation` blocks for custom constraints. Therefore, this argument would be unrecognized and cause a configuration error.
Go deeper
Related to this question
About these practice questions
Courseiva writes every TF-004 question from scratch — 434 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.