Sentinel Policy Capabilities: Enforcing Compliance in Terraform Cloud
Which THREE of the following are capabilities of Terraform Cloud's Sentinel policy framework? (Choose three.)
Quick Answer
The answer is that Sentinel policy capabilities include restricting the creation of certain resource types, enforcing mandatory tags, and checking compliance against custom rules. These three functions form the core of Sentinel's policy-as-code framework, which operates as a guardrail in Terraform Cloud’s run lifecycle by evaluating Terraform plans against defined policies before any infrastructure is provisioned. On the HashiCorp Terraform Associate TF-003 exam, this question tests your ability to distinguish Sentinel’s built-in enforcement actions from separate features like cost estimation, which is handled by a different service, or time-based blocking, which is not a native Sentinel capability. A common trap is confusing Sentinel’s policy enforcement with Terraform Cloud’s overall feature set, so remember that Sentinel focuses on logical checks—like resource type restrictions and tag validation—not on scheduling or cost calculations. For a quick memory tip, think “RTC”: Restrict, Tag, Check—the three core actions that Sentinel performs to enforce compliance.
⚠ Common exam trap
A common mix-up: candidates confuse Sentinel's policy enforcement with Terraform Cloud's other features, such as cost estimation or run triggers, and incorrectly assume Sentinel can handle time-based or cost-related logic natively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce that resources have mandatory tags
Sentinel is a policy-as-code framework embedded in Terraform Cloud that evaluates plan data before apply, so option B is correct because a policy can inspect planned resource attributes and fail the run when required tags (e.g., CostCenter, Environment) are missing. Option C is correct because Sentinel policies can encode organizational security rules—such as requiring encrypted S3 buckets, private subnets, or approved instance types—and reject non-compliant plans. Option D is correct because Sentinel can match on resource type (e.g., aws_instance, azurerm_virtual_machine) and forbid or conditionally allow their creation. Option A is not a Sentinel capability because policies evaluate Terraform configuration/plan data, not wall-clock scheduling; time-based run control would come from CI/CD or API triggers. Option E is not a Sentinel capability because cost estimation in Terraform Cloud is provided by the separate cost estimation feature (run tasks/infracost-style integrations), not by Sentinel policy logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block Terraform runs based on the time of day
Why it's wrong here
Sentinel policies evaluate the plan, configuration and state data; they have no access to wall-clock time, so a time-of-day condition cannot be expressed. It would be tempting if scheduling were treated as policy, but that belongs to run triggers or CI scheduling.
- ✓
Enforce that resources have mandatory tags
Why this is correct
Sentinel can inspect planned resource attributes and reject configurations lacking required tags, enforcing the stem's tagging mandate before apply. This is a policy-as-code capability operating on the Terraform plan, not a runtime or post-deployment control.
- ✓
Check that resources comply with security best practices
Why this is correct
Sentinel evaluates planned infrastructure against policy-as-code rules, so it can enforce security best-practice constraints such as requiring encryption or blocking public storage before apply. This satisfies the stem's compliance-checking capability, since policies run against the Terraform plan and can hard-fail or soft-fail non-compliant resources.
- ✓
Restrict the creation of certain resource types
Why this is correct
Sentinel policies evaluate Terraform plans and can block resource types outright, so restricting creation of specified resource types is a genuine capability. This satisfies the scenario's requirement to enforce guardrails on provisioned infrastructure before apply.
- ✗
Estimate the cost of infrastructure changes
Why it's wrong here
Sentinel inspects plan, configuration and state values and returns pass, soft-mandatory or hard-mandatory; cost figures come from Terraform Cloud's separate cost estimation feature. It would be the right tool when policy must evaluate resource attributes, not projected spend.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This TF-004 question is part of Courseiva's 434-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on TF-004
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are valid use cases for using Terraform Cloud's Sentinel policies? (Choose two.)
medium- A.Provide cost estimates for infrastructure changes
- B.Enforce that all Terraform code follows a specific formatting style
- ✓ C.Enforce that all AWS instances are of a specific type
- D.Automatically rotate database passwords
- ✓ E.Enforce that all resources have required tags
Why C: Sentinel policies can enforce that all AWS instances are of a specific type by using a `validate` rule that checks the `aws_instance` resource's `instance_type` attribute against an allowed list. This is a common compliance use case for Sentinel in Terraform Cloud, where policy-as-code ensures infrastructure adheres to organizational standards before provisioning. Similarly, Sentinel can enforce that all resources have required tags by inspecting the `tags` attribute in the Terraform plan and ensuring specific keys and values are present, which is another common compliance and governance use case.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.