Courseiva

TF-004 · topic practice

Use the core Terraform workflow practice questions

This domain covers Terraform's core workflow: init, validate, plan, apply, and destroy, plus how state locking, saved plan files, and remote backends behave across CLI and CI/CD runs. TF-004 questions present operational scenarios — interrupted applies, lock errors, manual runs against remote state — and ask which command or practice resolves them correctly.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Use the core Terraform workflow

What the exam tests

What to know about Use the core Terraform workflow

Be able to execute the full init-to-destroy workflow, pass a saved plan file to apply, and diagnose lock or interruption errors. The single most important thing: know that apply without a plan file re-plans, and that stale locks are cleared with force-unlock only after confirming the holder stopped.

Running terraform init, validate, plan, apply, and destroy in correct order

Using terraform plan -out and terraform apply with a saved plan file

Remote backends such as S3 with DynamoDB locking and Azure Storage

Recovering from state lock errors with terraform force-unlock and lock IDs

Watch out for

Common Use the core Terraform workflow exam traps

  • ▸Assuming terraform apply reuses an earlier saved plan file; without the file argument it creates a fresh plan against current state.
  • ▸Running terraform force-unlock without verifying the lock holder is truly dead, risking two writers corrupting state.
  • ▸Believing local runs and CI runs cannot conflict; both share remote state, so a crashed manual apply can leave a stale lock.

Practice set

Use the core Terraform workflow questions

20 questions · select your answer, then reveal the explanation

During a 'terraform plan', you see the following output: 'Plan: 1 to add, 2 to change, 0 to destroy.' However, after running 'terraform apply', the actual number of resources changed is different. What is the most likely reason?

Which TWO of the following are valid steps in the core Terraform workflow?

A team is adopting Terraform for infrastructure deployment. They want to ensure that the core workflow (write, plan, apply) is followed effectively. Which two practices should they adopt? (Choose two.)

What is the most likely cause of this error?

Exhibit

Refer to the exhibit.

```hcl
resource "aws_instance" "web" {
  ami           = "ami-0c55b159cbfafe1f0"
  instance_type = "t2.micro"
}
```

An engineer runs `terraform apply` with this configuration and receives the following error:

```
Error: Error launching source instance: UnauthorizedOperation: You are not authorized to perform this operation.
```

Which of the following statements about the core Terraform workflow (Write, Plan, Apply) are correct? (Choose all that apply. There are four correct answers.)

Drag and drop the steps to import existing infrastructure into Terraform state in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each Terraform workflow stage to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Author infrastructure as code configuration

Preview changes before applying

Execute the planned changes

Tear down managed infrastructure

Restructure configuration without changing external resources

A developer runs `terraform init` in a directory containing Terraform configuration files. After initialization, they notice that a provider plugin was installed. Where are provider plugins stored locally by default?

When running `terraform plan`, an engineer sees that Terraform proposes to destroy an existing resource even though the resource still exists in the cloud provider. What is the most likely cause?

An engineer accidentally destroys a critical resource by running `terraform apply` after an incorrect `terraform plan`. They want to recover the resource quickly. What should they do?

Which TWO statements accurately describe the `terraform plan` command? (Select TWO.)

Which THREE are valid uses of the `terraform state` command? (Select THREE.)

Which THREE of the following are valid flags for the terraform apply command? (Choose three.)

A team is running terraform in a CI/CD pipeline that executes multiple jobs in parallel for different modules. They notice that terraform init takes a long time in each job because it downloads provider plugins repeatedly. They want to speed up the init process by caching providers. What should they do?

A platform team wants to enforce a policy that all Terraform runs in their CI pipeline must be reviewed before changes are applied. They decide to use a saved plan file. Which TWO statements about using a saved plan file with terraform apply are correct? (Choose two.)

A team uses Terraform to manage infrastructure. After running 'terraform apply', a developer notices that a new security group rule was added, but then immediately removed. What is the most likely cause?

A DevOps engineer is troubleshooting a failed 'terraform apply'. The error message says: 'Error: Error applying IAM policy: The policy failed validation'. The IAM policy is defined using HCL in a JSON-encoded string. What is the most efficient way to debug this issue?

A team wants to ensure that all Terraform runs are recorded for audit purposes. Which practice should they implement?

Which TWO actions are part of the core Terraform workflow? (Choose two.)

Which THREE of the following are valid reasons to use 'terraform refresh'? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Use the core Terraform workflow sessions

Start a Use the core Terraform workflow only practice session

Every question in these sessions is drawn from the Use the core Terraform workflow domain — nothing else.

Related practice questions

Related TF-004 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the TF-004 exam test about Use the core Terraform workflow?
Be able to execute the full init-to-destroy workflow, pass a saved plan file to apply, and diagnose lock or interruption errors. The single most important thing: know that apply without a plan file re-plans, and that stale locks are cleared with force-unlock only after confirming the holder stopped.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Use the core Terraform workflow questions in a focused session?
Yes — the session launcher on this page draws every question from the Use the core Terraform workflow domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other TF-004 topics?
Use the topic links above to move to related areas, or go back to the TF-004 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the TF-004 exam covers. They are not copied from any real exam or dump site.