Courseiva

TF-004 · topic practice

Read, generate and modify configuration practice questions

This domain covers writing and reading Terraform configuration: output blocks, module input and output descriptions, how resource count changes appear in terraform plan, and passing values between configurations. Questions use HCL exhibits, Terraform Registry modules, and AWS EC2 resources, so you must read code and predict plan behavior accurately.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Read, generate and modify configuration

What the exam tests

What to know about Read, generate and modify configuration

Be able to read HCL and explain outputs, module variables, and plan diffs, especially count changes. The key skill is predicting what terraform plan shows and knowing that cross-configuration values flow through outputs, remote state, or module inputs, never by guessing.

Purpose of output blocks in exposing values from a Terraform configuration

Where module input and output descriptions live in Terraform Registry modules

How terraform plan displays instance_count changes on an AWS EC2 resource

Recommended ways to pass outputs from one configuration as input variables

Watch out for

Common Read, generate and modify configuration exam traps

  • ▸Confusing output values with variable declarations, or assuming outputs are required rather than optional configuration elements
  • ▸Expecting instance_count increases to show as in-place updates instead of new resource instances being added
  • ▸Passing outputs between configurations by hardcoding values instead of using remote state data sources or module outputs

Practice set

Read, generate and modify configuration questions

20 questions · select your answer, then reveal the explanation

An operator runs 'terraform plan' and sees that a resource will be replaced. They want to avoid destroying the resource, but still apply other changes. What should they do?

Which THREE statements about Terraform modules are correct?

Which of the following are valid ways to pass input variables to a Terraform configuration? (Select all that apply.)

When running terraform apply on a configuration that creates an AWS EIP resource referencing `aws_instance.web.id`, you receive the error: "Error: Missing required argument: The argument "instance" is required, but no definition was found." Given this configuration, what is the most likely cause of this error?

Exhibit

Refer to the exhibit.

```hcl
resource "aws_instance" "web" {
  ami           = "ami-0c55b159cbfafe1f0"
  instance_type = "t2.micro"
}

resource "aws_eip" "ip" {
  instance = aws_instance.web.id
}

output "public_ip" {
  value = aws_eip.ip.public_ip
}
```

A user runs `terraform apply` and gets: Error: Invalid index on aws_eip.ip, in the 'instance' argument. The resource aws_instance.web has not been created yet.

Which TWO of the following are valid ways to reference a value from a Terraform configuration?

You are managing a multi-environment Terraform configuration using separate workspaces for 'dev', 'staging', and 'prod'. Each workspace uses the same root module but different variable values stored in terraform.tfvars files per workspace. Your team reports that after a recent change to the root module, running `terraform plan` in the 'dev' workspace shows that it will destroy and recreate a critical RDS database instance, even though no changes were made to the database configuration. The state file for 'dev' is stored in a remote S3 backend with DynamoDB locking. You suspect the issue is related to how Terraform generates and reads configuration. What is the most likely cause?

A configuration creates multiple AWS instances using count. The developer wants to output the IDs of all instances. Which output block is valid? (Choose the best answer.)

Refer to the exhibit. A terraform plan shows that the instance will be replaced. What will be the order of operations?

Exhibit

resource "aws_instance" "web" {
  ami           = "ami-abc123"
  instance_type = "t2.micro"

  tags = {
    Name = "web-server"
  }

  lifecycle {
    create_before_destroy = true
  }
}

A team stores sensitive secrets in AWS Secrets Manager and wants to reference them in Terraform without exposing the values. Which approach is most secure and recommended?

A team runs terraform plan and sees changes that are unexpected. Which TWO actions should they take to investigate before applying?

An organization wants to reference outputs from a root module in another Terraform configuration. Which THREE methods are valid for reading those outputs?

Which THREE of the following are valid ways to modify a Terraform configuration to rename a resource without destroying and recreating it? (Select THREE.)

A large organization uses Terraform to manage hundreds of AWS resources across multiple accounts. They have a central repository with modules for common patterns. A new engineer is tasked with adding a new feature that requires modifying the configuration of an existing S3 bucket to enable server-side encryption. The current configuration for the bucket is defined in a module that is used by many other teams. The engineer adds an `aws_s3_bucket_server_side_encryption_configuration` resource as recommended by the latest AWS provider. After running `terraform plan`, they see that the plan will create the new encryption resource but also shows an in-place update to the bucket itself. They check the bucket resource and see that it has a `server_side_encryption_configuration` argument that is deprecated. The engineer wants to ensure backward compatibility and avoid breaking other teams' configurations. What is the best course of action?

A startup uses Terraform to manage their cloud infrastructure. They have a single configuration file that defines an AWS EC2 instance. They want to add an Elastic IP (EIP) and associate it with the instance. The engineer modifies the configuration to add an `aws_eip` resource and references the instance ID. They run `terraform plan` and it shows that the EIP will be created. However, when they run `terraform apply`, they get an error: "Error: Error associating EIP: ... The instance ID 'i-1234567890abcdef0' does not exist." The instance was created successfully in a previous apply. What is the most likely cause?

A DevOps engineer is managing a multi-cloud infrastructure using Terraform. The team relies on a module sourced from the Terraform Registry to deploy a standard web application. This module defines an input variable called 'instance_count' with a default value of 2. For the production environment, the engineer wants to deploy 3 instances. They create a root module configuration that references the module. In the root module's main.tf, they write a block that sets instance_count = 3. However, when they run terraform plan, the output indicates that the module will still use instance_count = 2. The engineer double-checks the configuration: the root module's main.tf is syntactically correct, the module source points to the correct registry module and version, and they have run terraform init and terraform validate without errors. What is the most likely reason the variable override is not taking effect?

An operator maintains a Terraform configuration where a `local_file` resource writes a file whose content includes a timestamp generated by `timestamp()`. During a `terraform plan`, Terraform reports that the `content` attribute will change on every run, but the operator wants the file to be written only once unless the configuration changes. Which action should the operator take?

A platform team is writing a Terraform module that must accept a list of CIDR blocks and create one `aws_subnet` resource per block. The module should also expose the subnet IDs as an output. The team wants to use a `for_each` expression to iterate over the list. Which two statements about using `for_each` with a list are correct? (Choose two.)

A team wants to use Terraform to provision infrastructure across multiple cloud providers. Which configuration approach best supports this goal?

A Terraform configuration uses a module from the Terraform Registry. After updating the module version in the configuration, the operator runs 'terraform plan' but does not see the changes expected from the new version. What is the most likely cause?

A developer wants to conditionally create a resource based on a variable that is a boolean. Which syntax should they use?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Read, generate and modify configuration sessions

Start a Read, generate and modify configuration only practice session

Every question in these sessions is drawn from the Read, generate and modify configuration domain — nothing else.

Related practice questions

Related TF-004 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the TF-004 exam test about Read, generate and modify configuration?
Be able to read HCL and explain outputs, module variables, and plan diffs, especially count changes. The key skill is predicting what terraform plan shows and knowing that cross-configuration values flow through outputs, remote state, or module inputs, never by guessing.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Read, generate and modify configuration questions in a focused session?
Yes — the session launcher on this page draws every question from the Read, generate and modify configuration domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other TF-004 topics?
Use the topic links above to move to related areas, or go back to the TF-004 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the TF-004 exam covers. They are not copied from any real exam or dump site.