TF-004 Understand Terraform basics Practice Question
A team uses Terraform to manage AWS resources. They want to ensure that a security group is created before an EC2 instance that references it. What is the best practice?
⚠ Common exam trap
Many candidates incorrectly think that `depends_on` is always required to control resource ordering, but Terraform's implicit dependencies from attribute references handle most cases automatically. Avoid choosing `provisioner` or `count` as ordering mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use `depends_on` meta-argument
`depends_on` is the explicit meta-argument in Terraform that allows you to define a hard dependency between resources. While Terraform often infers implicit dependencies when one resource directly references an attribute of another (e.g., an EC2 instance referencing a security group's ID), there are scenarios where an explicit dependency is required to ensure correct ordering. This is particularly true when references are indirect (e.g., via a variable or data source) or when a non-obvious ordering is critical. In such cases, `depends_on` is the best practice to explicitly ensure the security group is created before the EC2 instance, preventing plan/apply errors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use `for_each` to iterate over resources
Why it's wrong here
The `for_each` meta-argument is designed to create multiple instances of a single resource type based on a map or set, efficiently managing collections of similar resources. While it controls the instantiation of resources, it does not establish or enforce a specific creation order *between different, unrelated resource types*. Its purpose is resource multiplication, not explicit dependency management for sequential provisioning.
- ✗
Use `count` to create the security group first
Why it's wrong here
The `count` meta-argument is used to create multiple instances of a resource based on an integer value, or to conditionally create a single resource. Applying `count` to a security group only dictates how many instances of that specific security group are created; it does not inherently establish a dependency relationship or guarantee its creation *before* another distinct resource that does not explicitly reference it. `count` is for resource quantity, not cross-resource ordering.
- ✗
Use `provisioner` to wait for the security group
Why it's wrong here
Provisioners are blocks configured within a resource to execute scripts or commands *on* or *against* that specific resource *after* it has been successfully created or destroyed. They are intended for post-creation configuration or cleanup tasks, such as installing software on a newly launched server. Provisioners cannot be used to manage the creation order of *other* Terraform resources or to "wait" for a prerequisite resource to be provisioned before the current resource even begins its creation lifecycle.
- ✓
Use `depends_on` meta-argument
Why this is correct
The `depends_on` meta-argument explicitly declares a dependency between resources that Terraform cannot automatically infer from attribute references. By using `depends_on`, you instruct Terraform to ensure that the specified prerequisite resource is fully created, stable, and available before attempting to provision the resource where `depends_on` is declared. This is the precise and correct mechanism for enforcing a specific, non-inferable creation order in the dependency graph.
- ✗
Use a data source to reference the security group
Why it's wrong here
Data sources are used to fetch information about existing resources, whether they are managed by Terraform or external to its state. While referencing a data source's output in another resource creates an *implicit dependency* on the *existence* of the data source's target, the data source itself does not *create* the underlying resource. It merely reads its current state, assuming it has already been provisioned, and therefore cannot enforce its creation order.
Go deeper
Related to this question
About these practice questions
This TF-004 question is part of Courseiva's 434-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.