Courseiva

TF-004 Understand Terraform's purpose Practice Question

An organization has multiple teams using Terraform to manage shared infrastructure. They want to enforce policies such as requiring specific tags on all resources and preventing the use of certain instance types. Which Terraform feature should they implement to meet these requirements?

⚠ Common exam trap

Terraform certification exams often test the distinction between operational features (workspaces, backends) and governance features (policy enforcement), leading candidates to confuse state management with policy control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sentinel policy enforcement

Sentinel is HashiCorp's policy-as-code framework that integrates with Terraform Cloud and Enterprise to enforce fine-grained, logic-based policies before resources are created or modified. It can mandate that all resources carry specific tags (e.g., `required_tags`) and block prohibited instance types (e.g., `t2.micro`) by evaluating Terraform plan output against Sentinel rules, making it the correct choice for these governance requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terraform workspaces

    Why it's wrong here

    Terraform workspaces merely separate state instances for the same configuration, so they cannot inspect resource tags or reject prohibited instance types. It is tempting because workspaces isolate environments across teams, and they would be correct when the requirement is separate dev, staging and production state.

  • ✗

    Custom Terraform providers

    Why it's wrong here

    Custom providers extend Terraform to manage new APIs or resource types; they do not enforce tag or instance-type rules on existing resources. It is tempting because providers underpin all Terraform resource handling, and writing one would be correct when integrating an unsupported platform.

  • ✗

    Remote backends with state locking

    Why it's wrong here

    Remote backends with state locking only coordinate concurrent state access and prevent corruption; they cannot evaluate resource attributes or block disallowed instance types. It is tempting because shared state is essential for multi-team Terraform, and it would be correct when the requirement is safe concurrent applies.

  • ✓

    Sentinel policy enforcement

    Why this is correct

    Sentinel is HashiCorp's policy-as-code framework, integrated into Terraform Cloud and Enterprise, that evaluates plans against rules before apply. It directly satisfies the stem's constraints — mandatory tags and blocked instance types — by rejecting non-compliant plans, unlike OPA or manual review.

About these practice questions

Courseiva writes every TF-004 question from scratch — 434 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.