Courseiva

TF-004 · topic practice

Understand Terraform basics practice questions

This domain covers core Terraform mechanics: workspaces, state and backends, providers, data sources, outputs, and the plan/apply/refresh lifecycle. TF-004 questions present short scenarios about multi-environment setups, remote state with locking, and passing values between configurations, then ask which command, block, or feature applies.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Understand Terraform basics

What the exam tests

What to know about Understand Terraform basics

Be able to choose the right command or block for state isolation, remote backends, data sources, and cross-configuration outputs. The most important thing: know that workspaces and backends manage state, not configuration or credentials, and that locking protects state during concurrent runs.

Using terraform workspace commands to isolate dev, staging, and prod state within one root module

How data sources such as aws_ami with most_recent feed values into resource arguments

Configuring remote state in an S3 backend with DynamoDB state locking and recovery after deletion

Sharing values between configurations via root module outputs and terraform_remote_state data sources

Watch out for

Common Understand Terraform basics exam traps

  • ▸Assuming workspaces separate variables or credentials; they only separate state, so environment-specific values still need distinct inputs.
  • ▸Expecting terraform plan to always show no changes after apply; data sources can return new values on each read.
  • ▸Believing remote state alone provides locking; S3 requires DynamoDB (or equivalent) locking to prevent concurrent writes.

Practice set

Understand Terraform basics questions

20 questions · select your answer, then reveal the explanation

An organization uses Terraform Cloud for remote state management. They have a workspace that uses the CLI-driven run workflow. A developer runs `terraform plan` locally and sees that the plan succeeds. However, when they push the same configuration to the version control system (VCS) connected to the workspace, the plan fails with a state lock error. What is the most likely reason?

Which TWO of the following are true about Terraform state? (Choose two.)

Refer to the exhibit. What does this output indicate?

Exhibit

Output of `terraform state list`:
aws_instance.web

Refer to the exhibit. What is the most likely cause of this error?

Exhibit

Error: Could not satisfy version constraint for provider hashicorp/aws: required version >= 3.0, installed version 2.70

A team manages infrastructure with Terraform. They recently updated the provider version in the configuration from 2.0 to 3.0. After running `terraform init`, they get errors that some resource arguments are no longer valid. What is the best approach to resolve this?

Which TWO of the following are valid variable types in Terraform? (Choose two.)

Which TWO of the following are valid ways to pass variable values to a Terraform configuration? (Choose two.)

A DevOps engineer is working on a Terraform project that manages resources across multiple AWS accounts. To reduce duplication and ensure consistency, they want to define common configurations like provider settings and variable definitions in a separate location that can be reused across root modules. What feature should they use?

An organization uses Terraform Cloud to manage their infrastructure. They have a workspace configured with a VCS-backed workflow connected to their GitHub repository. They recently added a new AWS provider version requirement in their configuration. After committing and pushing the change, they notice that the plan in Terraform Cloud fails with an error indicating that the provider version is not found. However, the engineer can run the same configuration locally with terraform init and plan successfully. What is the most likely reason for the failure in Terraform Cloud?

Which TWO of the following statements about Terraform state are correct? (Choose two.)

Refer to the exhibit. A user runs terraform init and receives an error about state data content. The state file in S3 has not been manually modified. What is the most likely cause?

Exhibit

$ terraform init

Initializing the backend...

Successfully configured the backend "s3"! Terraform will automatically
use this backend unless the backend configuration changes.

Error refreshing state: state data in S3 does not have the expected content.
This may be due to a bug. If you are sure the state file is valid, run:
terraform force-unlock <lock_id>

Refer to the exhibit. A user applies this configuration and then runs 'terraform state list'. Which resource addresses would appear in the output?

Exhibit

resource "aws_instance" "web" {
  ami           = "ami-0c55b159cbfafe1f0"
  instance_type = "t2.micro"

  tags = {
    Name = "WebServer"
  }
}

resource "aws_eip" "web" {
  instance = aws_instance.web.id
}

Refer to the exhibit. A user runs 'terraform plan' and sees this output. However, when they run 'terraform apply', they get an error: 'Error creating EC2 instance: UnauthorizedOperation: You are not authorized to perform this operation.' The user's IAM permissions allow ec2:RunInstances. What is the most likely missing permission?

Exhibit

$ terraform plan

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create

Terraform will perform the following actions:

  # aws_instance.web will be created
  + resource "aws_instance" "web" {
      + ami                          = "ami-0c55b159cbfafe1f0"
      + instance_type                = "t2.micro"
      + tags                         = {
          + "Name" = "WebServer"
        }
    }

Plan: 1 to add, 0 to change, 0 to destroy.

Refer to the exhibit. A user applies this configuration. They then run 'terraform destroy' but the destroy fails with an error: 'Error deleting load balancer: DependencyViolation: The load balancer 'arn:aws:elasticloadbalancing:...' cannot be deleted because it is currently associated with another resource.' The user has not made any changes to the resources. What is the most likely cause?

Exhibit

resource "aws_lb" "frontend" {
  name               = "frontend-alb"
  internal           = false
  load_balancer_type = "application"
  security_groups    = [aws_security_group.alb.id]
  subnets            = ["subnet-12345678", "subnet-87654321"]
}

resource "aws_lb_listener" "frontend_http" {
  load_balancer_arn = aws_lb.frontend.arn
  port              = 80
  protocol          = "HTTP"

  default_action {
    type = "forward"
    target_group_arn = aws_lb_target_group.frontend.arn
  }
}

resource "aws_lb_target_group" "frontend" {
  name     = "frontend-tg"
  port     = 80
  protocol = "HTTP"
  vpc_id   = "vpc-12345678"
}

Refer to the exhibit. An engineer receives this error when running terraform apply. What is the most likely cause?

Exhibit

Error: Error applying IAM policy to role MyRole: MalformedPolicyDocument: The policy is not in the valid JSON format.

status code: 400, request id: ...

on main.tf line 10, in resource "aws_iam_role_policy" "my_policy":
  10:   policy = <<POLICY
  11: {
  12:   "Version": "2012-10-17",
  13:   "Statement": [
  14:     {
  15:       "Effect": "Allow",
  16:       "Action": "s3:ListBucket",
  17:       "Resource": "arn:aws:s3:::my-bucket"
  18:     }
  19:   ]
  20: }
  21: POLICY

Refer to the exhibit. The engineer runs terraform plan and gets:

Error: Reference to undeclared data source on main.tf line 6, in resource "aws_security_group" "example": 6: vpc_id = data.aws_vpc.selected.id

A data source "aws_vpc" "selected" is declared but not yet read. What is the most likely cause?

Exhibit

data "aws_vpc" "selected" {
  default = true
}

resource "aws_security_group" "example" {
  name   = "example-sg"
  vpc_id = data.aws_vpc.selected.id
}

output "vpc_id" {
  value = data.aws_vpc.selected.id
}

A team uses Terraform to manage infrastructure across two AWS regions. They want to use the same configuration but deploy identical resources to us-east-1 and eu-west-1, with separate state files per region. They prefer not to duplicate the configuration files. Which Terraform feature should they use?

A DevOps engineer is writing a Terraform configuration to provision an AWS EC2 instance. They want to ensure that the instance is replaced if the AMI ID changes, but not if the instance type changes. Which lifecycle meta-argument should be used?

A team is using Terraform to manage infrastructure across multiple environments (dev, staging, prod). They want to reuse the same root module configuration but with different variable values. Which approach is the most efficient?

A Terraform configuration includes a module from the Terraform Registry. After running `terraform init`, the module is downloaded. However, a subsequent `terraform plan` fails with an error that a required provider is not installed, even though it is declared in the module. What is the most likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Understand Terraform basics sessions

Start a Understand Terraform basics only practice session

Every question in these sessions is drawn from the Understand Terraform basics domain — nothing else.

Related practice questions

Related TF-004 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the TF-004 exam test about Understand Terraform basics?
Be able to choose the right command or block for state isolation, remote backends, data sources, and cross-configuration outputs. The most important thing: know that workspaces and backends manage state, not configuration or credentials, and that locking protects state during concurrent runs.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Understand Terraform basics questions in a focused session?
Yes — the session launcher on this page draws every question from the Understand Terraform basics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other TF-004 topics?
Use the topic links above to move to related areas, or go back to the TF-004 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the TF-004 exam covers. They are not copied from any real exam or dump site.