TF-004 Use Terraform outside the core workflow Practice Question
Which THREE are valid use cases for the 'terraform state replace-provider' command?
⚠ Common exam trap
The exam often tests the distinction between state-level provider address changes (source/registry) versus configuration-level changes (version, region, or provider block attributes), and candidates mistakenly think `state replace-provider` can handle version upgrades or configuration edits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Migrating a provider from one registry to another (e.g., from registry.terraform.io to a private registry).
Option A is correct because 'terraform state replace-provider' rewrites the provider source address recorded in the state file, which is exactly what is needed when a provider moves from registry.terraform.io to a private registry. Option D is correct because migrating from a community provider to an official provider is a change of provider source address in state, and this command updates those references without forcing resource re-creation. Option E is correct because changing the provider source from one namespace to another (e.g., hashicorp/aws to mycompany/aws) is precisely the provider address substitution the command performs. Option B is not correct because upgrading a provider to a new major version is done by changing the version constraint and running 'terraform init -upgrade', not by replacing the provider source in state. Option C is not correct because changing a provider's configuration region is a configuration change in the provider block, not a state provider address replacement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Migrating a provider from one registry to another (e.g., from registry.terraform.io to a private registry).
Why this is correct
Migrating a provider between registries requires rewriting every stored provider address in state, since Terraform resolves providers by registry-qualified source address. The replace-provider command performs exactly this state-wide substitution, updating the recorded provider references without touching real infrastructure, satisfying the registry-migration use case.
- ✗
Upgrading the provider to a new major version.
Why it's wrong here
This command rewrites the provider source address recorded in state, for example migrating from hashicorp/aws to a registry fork; it does not change the version constraint or installed provider version. Upgrading a major version is done by editing the required_providers block and running terraform init -upgrade.
- ✗
Changing the provider's configuration region from us-east-1 to eu-west-1.
Why it's wrong here
Region changes live in provider configuration blocks, so editing the configuration and re-running init or apply handles them; replace-provider rewrites the provider source address recorded in state. It is used when migrating between provider namespaces, such as hashicorp/aws to a fork.
- ✓
Migrating from a community provider to an official provider.
Why this is correct
Migrating from a community provider to an official provider works because `terraform state replace-provider` rewrites the provider source address recorded in state, leaving existing resource attributes untouched. This satisfies the scenario's need to swap provider origins without destroying and recreating infrastructure, since the resource type schema remains compatible across both providers.
- ✓
Changing the provider source from one namespace to another (e.g., hashicorp/aws to mycompany/aws).
Why this is correct
Migrating a provider's source address between namespaces, such as hashicorp/aws to mycompany/aws, is exactly what `terraform state replace-provider` handles. It rewrites the provider reference recorded in state without touching resource attributes, satisfying the scenario's requirement to retarget an existing provider to a different registry namespace while preserving managed infrastructure.
Go deeper
Related to this question
About these practice questions
This TF-004 question is part of Courseiva's 434-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.