TF-004 Understand Terraform's purpose Practice Question
An organization has multiple teams using Terraform to manage shared infrastructure. They want to enforce policies such as requiring specific tags on all resources and preventing the use of certain instance types. Which Terraform feature should they implement to meet these requirements?
⚠ Common exam trap
Terraform certification exams often test the distinction between operational features (workspaces, backends) and governance features (policy enforcement), leading candidates to confuse state management with policy control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sentinel policy enforcement
Sentinel is HashiCorp's policy-as-code framework that integrates with Terraform Cloud and Enterprise to enforce fine-grained, logic-based policies before resources are created or modified. It can mandate that all resources carry specific tags (e.g., `required_tags`) and block prohibited instance types (e.g., `t2.micro`) by evaluating Terraform plan output against Sentinel rules, making it the correct choice for these governance requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Terraform workspaces
Why it's wrong here
Terraform workspaces merely separate state instances for the same configuration, so they cannot inspect resource tags or reject prohibited instance types. It is tempting because workspaces isolate environments across teams, and they would be correct when the requirement is separate dev, staging and production state.
- ✗
Custom Terraform providers
Why it's wrong here
Custom providers extend Terraform to manage new APIs or resource types; they do not enforce tag or instance-type rules on existing resources. It is tempting because providers underpin all Terraform resource handling, and writing one would be correct when integrating an unsupported platform.
- ✗
Remote backends with state locking
Why it's wrong here
Remote backends with state locking only coordinate concurrent state access and prevent corruption; they cannot evaluate resource attributes or block disallowed instance types. It is tempting because shared state is essential for multi-team Terraform, and it would be correct when the requirement is safe concurrent applies.
- ✓
Sentinel policy enforcement
Why this is correct
Sentinel is HashiCorp's policy-as-code framework, integrated into Terraform Cloud and Enterprise, that evaluates plans against rules before apply. It directly satisfies the stem's constraints — mandatory tags and blocked instance types — by rejecting non-compliant plans, unlike OPA or manual review.
Go deeper
Related to this question
About these practice questions
Courseiva writes every TF-004 question from scratch — 434 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.