Courseiva

TF-004 · domain

Understand Terraform basics

This domain covers core Terraform mechanics: workspaces, state and backends, providers, data sources, outputs, and the plan/apply/refresh lifecycle. TF-004 questions present short scenarios about multi-environment setups, remote state with locking, and passing values between configurations, then ask which command, block, or feature applies.

49 questions14 easy20 medium15 hard

Focused practice

Practice Understand Terraform basics questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Understand Terraform basics

Be able to choose the right command or block for state isolation, remote backends, data sources, and cross-configuration outputs. The most important thing: know that workspaces and backends manage state, not configuration or credentials, and that locking protects state during concurrent runs.

Using terraform workspace commands to isolate dev, staging, and prod state within one root module

How data sources such as aws_ami with most_recent feed values into resource arguments

Configuring remote state in an S3 backend with DynamoDB state locking and recovery after deletion

Sharing values between configurations via root module outputs and terraform_remote_state data sources

Watch out for

Common Understand Terraform basics exam traps

  • ▸Assuming workspaces separate variables or credentials; they only separate state, so environment-specific values still need distinct inputs.
  • ▸Expecting terraform plan to always show no changes after apply; data sources can return new values on each read.
  • ▸Believing remote state alone provides locking; S3 requires DynamoDB (or equivalent) locking to prevent concurrent writes.

Question index

All Understand Terraform basics questions (49)

Click any question to see the full explanation, or start a practice session above.

1

A Terraform configuration includes a module from the Terraform Registry. After running `terraform init`, the module is downloaded. However, a subsequent `terraform plan` fails with an error that a required provider is not installed, even though it is declared in the module. What is the most likely cause?

Hard
2

A developer is new to Terraform and wants to understand the core workflow. Which sequence of commands correctly represents the basic Terraform workflow?

Easy
3

A company has a monolithic Terraform configuration that manages all infrastructure. As the infrastructure grows, plan and apply times become very long. They want to break the configuration into smaller, independent units to improve performance and reduce blast radius. Which approach should they take?

Hard
4

Refer to the exhibit. Which change to the configuration would prevent this error in the future?

Medium
5

A junior engineer cloned a Terraform repository from GitHub and ran terraform init inside the project directory. The command downloaded the required provider plugins successfully. Next, they ran terraform plan and received the following error: 'Error: No configuration files found in the current directory.' The engineer checked and confirmed that the main.tf file exists in the current directory. What is the most likely cause of this error?

Easy
6

A company wants to use Terraform to create Azure resources. They have written a configuration file but when they run `terraform init`, they get a warning about an 'incomplete lock file'. What should they do first?

Medium
7

Refer to the exhibit. An engineer runs 'terraform plan' and receives an error: 'Error refreshing state: state data in S3 does not have the expected content.' The state file exists and is not corrupted. What is the most likely cause?

Hard
8

A team is new to Terraform and wants to manage their cloud infrastructure. They have written configuration files but have not yet run any commands. What is the correct sequence of initial steps to deploy their infrastructure?

Easy
9

A developer is new to Terraform and wants to understand the purpose of the terraform init command. Which statement correctly describes its primary function?

Easy
10

An organization uses Terraform with multiple workspaces to manage different environments (dev, staging, prod). They want to ensure that sensitive variables for prod are not exposed in the plan output. What should they do?

Medium
11

Refer to the exhibit. An engineer runs terraform state list and sees these resources. The engineer wants to remove the aws_eip.web_ip resource from state without destroying the actual resource. Which command should be used?

Medium
12

A DevOps engineer is writing a Terraform configuration to provision an AWS EC2 instance. They want to ensure that the instance is replaced if the AMI ID changes, but not if the instance type changes. Which lifecycle meta-argument should be used?

Medium
13

In Terraform, which command is used to format configuration files according to the HCL canonical style?

Easy
14

Drag and drop the steps to create and apply a Terraform plan in the correct order.

Medium
15

You are a DevOps engineer managing a multi-environment Terraform setup using workspaces. Your team has three workspaces: dev, staging, and prod. All infrastructure is defined in a single root module with environment-specific variable values stored in separate .tfvars files. Recently, a colleague accidentally ran terraform destroy in the prod workspace, which deleted critical production resources. You need to implement a safety mechanism to prevent accidental destruction of production resources in the future. The solution should not require changes to the Terraform provider or backend configuration. Which approach should you take?

Hard
16

Which of the following are core concepts or behaviors of Terraform's execution model and state management? (Choose four.)

Medium
17

Which two of the following are correct statements about Terraform providers?

Easy
18

A team is using Terraform to manage infrastructure across multiple environments (dev, staging, prod). They want to reuse the same root module configuration but with different variable values. Which approach is the most efficient?

Easy
19

Match each Terraform feature to its description.

Medium
20

Drag and drop the steps to set up remote state with Terraform Cloud in the correct order.

Medium
21

A team uses Terraform to manage AWS resources. They want to ensure that a security group is created before an EC2 instance that references it. What is the best practice?

Medium
22

A developer new to Terraform writes a configuration with a provider block, a resource block, and an output block. They run a single command that initializes the working directory, downloads the provider plugin, and prepares the backend. Which command did they run?

Easy
23

Match each Terraform provisioner to its typical use case.

Medium
24

You are maintaining a Terraform configuration for a team that uses the local backend. A junior engineer accidentally deletes the terraform.tfstate file from the working directory before running terraform destroy. You need to recover from this situation without disrupting the existing infrastructure. Which two statements about Terraform state are true? (Choose two.)

Medium
25

Which three of the following are core characteristics of Terraform's execution plan? (Choose three.)

Medium
26

A Terraform configuration uses `count` to create multiple EC2 instances. After adding a new variable for instance type, the user runs `terraform plan` and sees that all instances are marked for recreation. What is the most likely cause?

Hard
27

You are a platform engineer at a fintech company. Your team manages a multi-region application on AWS using Terraform. The infrastructure includes VPCs, subnets, EC2 instances, and an Application Load Balancer (ALB). The configuration uses modules from the Terraform Registry and remote state in S3 with DynamoDB locking. Recently, after a colleague ran `terraform apply` in the us-east-1 region, the application experienced downtime because the ALB's target group was accidentally updated to point to instances in us-west-2 instead of us-east-1. The root cause was that the Terraform configuration for the ALB used a variable `target_region` which was hardcoded to us-west-2 in a `terraform.tfvars` file that was not intended for that workspace. Your team wants to prevent such misconfigurations in the future. Which course of action would most effectively reduce the risk of using incorrect variable values across workspaces?

Hard
28

Refer to the exhibit. What will happen when terraform plan is run?

Easy
29

A company is using Terraform to manage secrets in AWS Secrets Manager. They want to ensure that sensitive values are not exposed in logs, the console, or plan output. Which two practices should they implement? (Choose two.)

Hard
30

A developer accidentally deletes the local terraform.tfstate file. The backend is configured to store state remotely in an S3 bucket. What is the effect on Terraform operations?

Medium
31

A developer runs `terraform apply` and gets the error: 'Error: No configuration files'. What is the most likely cause?

Hard
32

What file extension is commonly used for Terraform configuration files?

Easy
33

Which three of the following are true regarding Terraform state?

Hard
34

Which three of the following are valid ways to pass variable values to a Terraform configuration?

Medium
35

Your team uses Terraform to manage a multi-region AWS deployment consisting of over 500 resources. The state file is stored in an S3 backend with DynamoDB locking. Recently, one of your colleagues accidentally deleted the state file from S3 while trying to clean up old backups. Fortunately, you have a backup from two days ago. However, after restoring the backup, you notice that several recent changes, including two new EC2 instances and a security group, are missing from the state. The actual resources still exist in AWS. You need to bring the state back in sync with the real-world infrastructure without recreating these resources. What should you do?

Hard
36

Refer to the exhibit. After running terraform apply, the output shows: Apply complete! Resources: 1 added, 0 changed, 0 destroyed. Outputs: instance_id = "i-1234567890abcdef0" However, the engineer notices that the instance type is t2.micro, but the expected instance type was t2.medium. What is the most likely reason for this discrepancy?

Medium
37

Refer to the exhibit. A developer runs `terraform apply` and the operation succeeds. Later, they manually terminate the EC2 instance through the AWS console. What will happen when the developer runs `terraform apply` again?

Easy
38

A developer wants to use the output of one Terraform configuration as input to another. Which Terraform feature should they use?

Easy
39

A Terraform configuration uses a module from the Terraform Registry. The module's documentation states it requires Terraform version >= 0.14. The team is using Terraform 0.12. What should the developer do to use this module?

Medium
40

A developer runs terraform apply to create an AWS EC2 instance using an AMI sourced from the aws_ami data source with most_recent = true. Immediately after apply completes, the developer runs terraform plan again. The plan shows that Terraform intends to replace the EC2 instance. What is the most likely cause?

Easy
41

A team is using Terraform to manage infrastructure across multiple environments (dev, test, prod). They want to reuse the same configuration but vary resource configurations like instance size and number of instances. Which Terraform feature should they use?

Medium
42

Which TWO of the following are valid ways to reference a resource attribute in Terraform?

Hard
43

Refer to the exhibit. An engineer runs terraform plan and sees this output. Which statement about the planned change is true?

Medium
44

Which of the following commands creates an execution plan that shows what resources will be created, updated, or destroyed?

Easy
45

A team uses Terraform with a remote backend that stores state in Azure Storage. A developer runs terraform apply and receives an error: 'Error refreshing state: state data in Azure Blob does not have expected content.' What is the most likely cause?

Hard
46

A developer runs terraform plan and sees a large number of resources will be destroyed. They suspect the state file is corrupted. They have a recent backup of the state file. Which command can help recover the previous state from the backup?

Hard
47

A company uses Terraform to manage infrastructure across dev, staging, and production environments. They use Terraform workspaces to separate state files. The backend is configured with an S3 bucket for state storage and a DynamoDB table for state locking. Recently, the team has grown from 2 to 10 developers, and they frequently encounter the error: 'Error acquiring the state lock' when running terraform apply in quick succession. The error message includes: 'Lock Info: ID: ... Operation: Apply. Who: user@company.com. Version: 1.0.0. Created: ...' The error occurs intermittently, especially during peak deployment times. The DynamoDB table is configured with 5 read and 5 write capacity units. The team's current workflow involves multiple developers running apply on different workspaces simultaneously. Which course of action should the team take to minimize state locking errors?

Hard
48

Which THREE of the following are characteristics of Terraform state? (Choose three.)

Medium
49

A platform team manages a large Terraform codebase with hundreds of resources across multiple environments (dev, staging, prod). They use terraform workspaces to manage environment-specific state files. Recently, an engineer made changes to the production workspace but forgot to switch from the dev workspace before applying. The apply was successful, but now the production resources are in an inconsistent state. The team wants to recover the production state to match the actual infrastructure. The previous state file for production was backed up in an S3 bucket before the accidental apply. What is the best course of action?

Hard

Frequently asked questions

What does the Understand Terraform basics domain cover on the TF-004 exam?
Be able to choose the right command or block for state isolation, remote backends, data sources, and cross-configuration outputs. The most important thing: know that workspaces and backends manage state, not configuration or credentials, and that locking protects state during concurrent runs.
How many questions are in this domain?
This page lists all 49 Understand Terraform basics questions in the TF-004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Understand Terraform basics questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
hashicorp-terraform HASHICORP-TERRAFORM terraform basics Practice Questions