Courseiva

Migrate Terraform State to Remote Backend

Which THREE actions should be taken when migrating Terraform state from local to a remote backend?

Quick Answer

The answer is to add a backend block to the configuration, because this block defines the remote storage location and triggers Terraform’s built-in migration workflow. When you run `terraform init` after adding the block, Terraform detects the change and automatically prompts you to copy the existing local state file to the new remote backend, handling the entire migration seamlessly without manual file manipulation. On the HashiCorp Terraform Associate TF-003 exam, this concept tests your understanding of state management and backend initialization—a common trap is thinking you need to manually move or copy the `terraform.tfstate` file, but `terraform init` does this for you. The exam often presents a scenario where you must identify the correct sequence: add the backend block, then run `terraform init` and type "yes" to confirm migration. Memory tip: "Block first, then init—Terraform handles the lift."

⚠ Common exam trap

HashiCorp often tests the misconception that you must manually delete or move the local state file before initializing a remote backend, when in fact `terraform init` handles the migration automatically and safely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run terraform init to initialize the backend and migrate state.

Option E is correct because you must declare a backend block (for example, backend "s3" or backend "azurerm") in the Terraform configuration so Terraform knows which remote backend to use. Option B is correct because after adding the backend block you run terraform init, which initializes the backend and, when existing local state is detected, offers to copy it to the new remote backend. Option D is correct because terraform init prompts 'Do you want to copy existing state to the new backend?' and you must confirm by typing 'yes' to complete the migration. Option A is wrong because deleting the local state file first would destroy the state that needs to be migrated. Option C is wrong because terraform import is used for bringing existing infrastructure under management, not for migrating an already-tracked state file to a remote backend.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the local state file before running terraform init.

    Why it's wrong here

    Deleting the local state file discards the resource mappings Terraform needs to reconcile, so the remote backend would initialise empty and orphan every existing resource. It is tempting because a clean slate feels tidy, but removal is only correct when abandoning state entirely, not when migrating it.

  • ✓

    Run terraform init to initialize the backend and migrate state.

    Why this is correct

    After adding the backend block, terraform init detects the existing local state and offers to copy it into the configured remote backend. Running init satisfies the migration requirement by performing the actual state transfer and reconfiguring the working directory.

  • ✗

    Manually import all existing resources into the remote state.

    Why it's wrong here

    Terraform already records every resource in the local state, so importing them again would duplicate or conflict with entries carried over by the backend migration. Import is for adopting resources Terraform has never tracked, not for relocating state that already exists.

  • ✓

    Confirm migration by typing 'yes' when prompted.

    Why this is correct

    Typing 'yes' at the prompt authorises Terraform to copy existing local state into the configured remote backend, completing the migration. Without this confirmation, the state remains local and subsequent runs diverge. This satisfies the stem's requirement to confirm the migration, ensuring the remote backend holds the authoritative state.

  • ✓

    Add a backend block to the configuration.

    Why this is correct

    Terraform needs a backend block declaring the remote storage type and location before any state can be migrated. Adding it satisfies the migration prerequisite, since init reads this configuration to know where to copy state.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every TF-004 question from scratch — 434 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on TF-004

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user wants to use a remote state backend for the first time. After adding the backend configuration, which command must they run to migrate the state from local to remote?

easy
  • A.`terraform plan`
  • ✓ B.`terraform init`
  • C.`terraform apply`
  • D.`terraform state push`

Why B: When you add a remote backend configuration to your Terraform code, `terraform init` is the required command to initialize the backend and migrate the existing local state file to the remote backend. During initialization, Terraform detects the backend change, prompts for confirmation, and automatically copies the state from the local `terraform.tfstate` to the configured remote store (e.g., S3, Azure Storage, or Terraform Cloud). Without running `init`, the remote backend is not configured and local state remains unchanged.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.