Courseiva

TF-004 Use the core Terraform workflow Practice Question

During terraform init, which TWO of the following actions occur? (Choose two.)

⚠ Common exam trap

HashiCorp often tests the misconception that `terraform init` validates the configuration or creates the state file, when in fact those actions belong to `terraform validate` and `terraform apply` respectively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Download provider plugins.

Option C is correct because terraform init downloads and installs the provider plugins declared in the configuration into the .terraform directory (or the plugin cache), resolving version constraints from the required_providers block. Option E is correct because terraform init initializes the backend, configuring where state is stored (e.g., local, S3, or Terraform Cloud) and, for remote backends, performing the backend setup such as creating or verifying the state storage. Option A is not part of init; configuration validation is performed by terraform validate. Option B is not performed by init; the state file is created or written when Terraform applies changes (or via terraform state operations), not during initialization. Option D is not performed by init; a plan is generated by terraform plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Validate the configuration.

    Why it's wrong here

    While `terraform init` performs initial parsing of configuration files to identify providers and modules, its core responsibility does not include comprehensive validation. The detailed syntax and semantic checks, such as verifying resource arguments, variable declarations, and output references, are specifically handled by the `terraform validate` command. `init` primarily focuses on preparing the environment rather than ensuring the correctness of the infrastructure definition itself.

  • ✗

    Create the state file.

    Why it's wrong here

    The `terraform.tfstate` file, which records the mapping between real-world infrastructure and your configuration, is not created by `terraform init`. Instead, this crucial file is generated and populated during the execution of `terraform apply`, once resources have been successfully provisioned or modified. `init` merely prepares the *location* or *backend* where this state file will eventually be stored or retrieved from, ensuring the mechanism for state management is ready.

  • ✓

    Download provider plugins.

    Why this is correct

    A primary action of `terraform init` is to identify all declared providers within the configuration (e.g., `aws`, `azurerm`, `google`) and download their respective plugin executables. These binaries are stored in the `.terraform/providers` subdirectory of the working directory. This step is essential as these plugins act as the interface between Terraform and the various cloud or service APIs, enabling resource management in subsequent commands like `terraform plan` and `terraform apply`.

  • ✗

    Generate a plan.

    Why it's wrong here

    Generating an execution plan is a distinct and complex operation performed exclusively by the `terraform plan` command. This process involves refreshing the state, comparing the desired configuration with the current infrastructure, and outlining the precise actions (create, update, delete) Terraform proposes to take. `terraform init` establishes the foundational environment, but it does not perform the resource reconciliation or change detection necessary to produce an execution plan.

  • ✓

    Initialize the backend.

    Why this is correct

    Initializing the backend is a critical function of `terraform init`, where it configures how Terraform will store and retrieve its state. This involves reading the `backend` block in the configuration and performing necessary setup, such as creating an S3 bucket, an Azure Blob Storage container, or connecting to a remote state service. This ensures state persistence, locking mechanisms for collaborative work, and the ability to manage infrastructure across different environments.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 434 original TF-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.