TF-004 Understand IaC concepts Practice Question
An organization is migrating from manually built environments to Terraform-managed infrastructure. During a design review, an architect argues that because Terraform configuration files are the source of truth, the team can safely delete the terraform.tfstate file after every successful apply to avoid storing sensitive data. What is the most accurate assessment of this proposal?
⚠ Common exam trap
The trap here is treating state as disposable output rather than the persistent mapping Terraform requires to manage existing resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is unsafe because state maps configuration to real resources; deleting it causes Terraform to lose track of existing infrastructure and attempt to recreate it.
State is the authoritative mapping between configuration and real infrastructure. Deleting it after each apply would make Terraform treat existing resources as absent and propose recreating them, risking duplicates and disruption. Sensitive values in state should be mitigated through an encrypted remote backend with tight access controls and locking, not by removing the file that Terraform depends on for every subsequent plan and apply.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is safe as long as the team runs terraform import for every resource immediately after each apply to rebuild the state file.
Why it's wrong here
Repeatedly deleting and re-importing every resource is operationally impractical and error-prone, and imports require matching each resource block to its real ID individually. It also does not address sensitive data, since the rebuilt state would contain the same values. Import is a migration tool for adopting existing resources, not a routine replacement for maintaining state between applies.
- ✗
It is recommended because state files never contain sensitive values, so deleting them has no security benefit or risk.
Why it's wrong here
State frequently contains sensitive data such as database passwords, private keys, and connection strings in plaintext. The security concern is legitimate, but deletion is the wrong remedy. The correct approach is a remote backend with encryption at rest, strict IAM, and possibly additional secret management. This option misstates the contents of state and ignores the operational consequences of removing it.
- ✗
It is acceptable because Terraform can always rediscover existing resources by querying provider APIs during the next plan.
Why it's wrong here
Terraform does not enumerate all provider resources to rebuild state; it refreshes only resources already recorded in state. Without state, it has no addresses to refresh and assumes nothing exists. Data sources can look up specific existing items, but they do not reconstruct management of previously created resources. This option overstates Terraform's discovery behavior and would lead to duplicate resource creation.
- ✓
It is unsafe because state maps configuration to real resources; deleting it causes Terraform to lose track of existing infrastructure and attempt to recreate it.
Why this is correct
State records the binding between resource addresses and real provider IDs plus computed attributes. Removing it means the next plan sees no existing resources and proposes creating duplicates, potentially causing conflicts or outages. The proposal misunderstands state's role. Sensitive values in state should instead be protected with encryption, access controls, and a remote backend rather than by deleting state.
Go deeper
Related to this question
About these practice questions
One of 434 original TF-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.