Courseiva

TF-004 · topic practice

Use Terraform outside the core workflow practice questions

This domain covers running Terraform beyond the local CLI: remote backends (S3, Terraform Cloud), state locking with DynamoDB, workspaces, and CI/CD automation. Questions present realistic pipeline failures—lock acquisition errors, interrupted applies, concurrent jobs—and ask for the correct operational response using Terraform commands and backend configuration.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Use Terraform outside the core workflow

What the exam tests

What to know about Use Terraform outside the core workflow

Be able to configure an S3 backend with DynamoDB locking, diagnose lock errors, and safely clear a stale lock with terraform force-unlock. The key skill is knowing when a lock is genuinely stale versus actively held, and never bypassing locking by editing backend resources directly.

Configuring S3 remote backend with DynamoDB state locking table

Using terraform force-unlock to release a stale state lock

Running terraform init, plan, and apply non-interactively in CI/CD

Managing multiple workspaces and isolating state per environment

Watch out for

Common Use Terraform outside the core workflow exam traps

  • ▸Deleting or editing the DynamoDB lock item manually instead of using terraform force-unlock, risking state corruption.
  • ▸Assuming terraform apply resumes automatically after failure; you must re-run plan/apply to reconcile partial state.
  • ▸Sharing one state file across concurrent CI jobs or workspaces, causing repeated lock contention and failures.

Practice set

Use Terraform outside the core workflow questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following are valid use cases for using Terraform Cloud's Sentinel policies? (Choose two.)

Which TWO of the following are true about Terraform Cloud's run lifecycle? (Choose two.)

Which TWO of the following are valid ways to import existing infrastructure into Terraform management? (Choose TWO.)

Which three of the following are valid ways to use Terraform outside the core provisioning workflow? (Choose three.)

Which four of the following are valid ways to integrate Terraform into an automated pipeline or use it outside the core manual workflow? (Choose all that apply.)

Refer to the exhibit. A Terraform Cloud plan includes an EC2 instance of type 't2.medium'. The team uses Sentinel policies. Which action should they take to proceed?

Exhibit

Sentinel policy "restrict-instance-types" evaluation resulted in "failure".
Description: Instance types must be t2.micro or t2.small.

A Terraform practitioner wants to ensure that the access keys used by a provider are not visible in plan output. Which Terraform attribute should be used when defining the provider?

An organization wants to use Terraform to manage resources across multiple accounts and regions, with different team members responsible for different environments. Which Terraform feature helps separate state and configuration for each environment?

Question 9mediummultiple choice
Read the full Ansible explanation →

An organization uses Terraform to provision infrastructure and then Ansible to configure it. They want to pass dynamic IP addresses from Terraform to Ansible. What is a recommended approach?

A DevOps engineer is troubleshooting a failed 'terraform plan' command. The error message is: 'Error: Error acquiring the state lock' followed by a message that the lock is held by another process. The team uses Terraform Cloud with remote state. Which of the following is the most likely cause and correct resolution?

A team uses Terraform workspaces to manage multiple environments (dev, staging, prod). They are currently in the 'dev' workspace and want to run a plan for the 'staging' workspace without switching workspaces. Which command sequence should they use?

A large enterprise uses Terraform Cloud with remote execution mode to manage infrastructure across multiple AWS accounts. Each environment (dev, staging, prod) has a separate workspace. The security team requires that all changes to production must be approved by a senior engineer before applying. Additionally, developers should be able to plan changes in production to preview the impact, but not apply them. The current setup uses the same Terraform Cloud team membership for all workspaces. When a developer runs a plan in production, the plan succeeds but they are unable to apply. However, the security team notices that the developer can accidentally apply if they quickly approve their own plan via the UI because the workspace is configured with 'Auto Apply' enabled. The security team wants to enforce the approval process without removing the developer's ability to plan. Which combination of changes should be made? (Select only one option.)

A DevOps engineer is responsible for maintaining Terraform configurations that manage resources in AWS. The team uses an S3 backend with DynamoDB state locking. The engineer notices that a recent 'terraform plan' command failed with the following error: 'Error: Failed to get existing workspaces: AccessDenied: Access Denied'. Other team members are able to run plans successfully from their machines. The engineer has verified that they have the correct AWS credentials configured via environment variables and that they can list the contents of the S3 bucket using the AWS CLI. The DynamoDB table exists and the engineer can describe it. What is the most likely cause of this error?

A platform team uses Terraform Cloud to manage infrastructure across multiple workspaces. They want to enforce that all workspaces use remote state and that state is not stored locally. Which TWO actions should they take? (Choose two.)

A developer runs `terraform plan` and it fails with a provider plugin error. Which command should they run first to resolve the issue?

A team uses Terraform Cloud for remote state management. They want to ensure that state file changes are only made through the Terraform Cloud API and not through direct access to the storage backend. Which feature should they enable?

A company uses Terraform with multiple cloud providers and wants to integrate with their existing CI/CD pipeline. They need to enforce that all infrastructure changes go through code review and automated testing before being applied to production. Which approach best meets these requirements?

An operator runs `terraform apply` and receives an error that the state file is locked. What is the most likely cause?

An organization wants to use Terraform to manage infrastructure in multiple environments (dev, staging, prod) with the same configuration but different variable values. Which approach should they use?

A team uses Terraform Cloud with a VCS-backed workflow. They notice that a recent commit triggered a run that failed because of an invalid configuration. The team fixed the configuration and wants to re-run the plan without committing again. Which action should they take?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Use Terraform outside the core workflow sessions

Start a Use Terraform outside the core workflow only practice session

Every question in these sessions is drawn from the Use Terraform outside the core workflow domain — nothing else.

Related practice questions

Related TF-004 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the TF-004 exam test about Use Terraform outside the core workflow?
Be able to configure an S3 backend with DynamoDB locking, diagnose lock errors, and safely clear a stale lock with terraform force-unlock. The key skill is knowing when a lock is genuinely stale versus actively held, and never bypassing locking by editing backend resources directly.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Use Terraform outside the core workflow questions in a focused session?
Yes — the session launcher on this page draws every question from the Use Terraform outside the core workflow domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other TF-004 topics?
Use the topic links above to move to related areas, or go back to the TF-004 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the TF-004 exam covers. They are not copied from any real exam or dump site.