TF-004 Use Terraform outside the core workflow Practice Question
Which TWO of the following are valid ways to pass variables to Terraform in an automated pipeline?
⚠ Common exam trap
HashiCorp often tests the exact environment variable prefix (`TF_VAR_` vs `TERRAFORM_`) and the existence of non-existent flags like `-vars`, expecting candidates to confuse them with similar-sounding options from other tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creating a .tfvars file and referencing it with -var-file.
Option A is correct because Terraform supports variable definition files (commonly with a .tfvars or .tfvars.json extension), and you can explicitly load one with the -var-file flag, e.g. terraform apply -var-file="prod.tfvars", which is ideal for automated pipelines where the file is committed or generated by the CI/CD system. Option C is correct because the -var flag lets you pass individual input variables directly on the command line, e.g. terraform apply -var="instance_type=t3.micro", which works non-interactively and is therefore suitable for pipeline execution. Option B is not valid for automation because interactive prompts require a human to type values at the terminal, which defeats unattended pipeline runs. Option D is incorrect because Terraform reads input variables from environment variables prefixed with TF_VAR_, not TERRAFORM_. Option E is incorrect because there is no -vars flag in Terraform; the correct flags are -var and -var-file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Creating a .tfvars file and referencing it with -var-file.
Why this is correct
Creating a .tfvars file, such as `production.tfvars`, allows for defining multiple input variables in a structured key-value format. This file can then be explicitly loaded using the `terraform plan -var-file=production.tfvars` or `terraform apply -var-file=production.tfvars` command-line flag. This method is highly effective for managing environment-specific configurations or large sets of variables, promoting reusability and version control of variable definitions.
- ✗
Using interactive prompts during terraform apply.
Why it's wrong here
Terraform does not typically prompt for variable values during `terraform apply` if all required variables are not explicitly provided. While `terraform plan` or `apply` *can* prompt for missing variable values, relying on interactive prompts is generally discouraged for automation and consistent deployments. This approach introduces human intervention, making it unsuitable for CI/CD pipelines and repeatable infrastructure provisioning.
- ✓
Using the -var flag to specify individual variables.
Why this is correct
The `-var` flag provides a direct mechanism to pass individual variable values directly on the command line. For instance, `terraform plan -var='region=us-east-1'` assigns the string 'us-east-1' to the `region` variable. This method is particularly useful for overriding default values, passing sensitive information securely via shell history management, or for quick, ad-hoc testing and automation scripts where only a few variables need to be set.
- ✗
Setting environment variables with prefix TERRAFORM_.
Why it's wrong here
Terraform recognizes environment variables as a source for input variables, but they must adhere to a specific naming convention. The correct prefix for environment variables that Terraform will automatically load is `TF_VAR_`, not `TERRAFORM_`. For example, setting `TF_VAR_instance_type=t2.micro` in the shell environment before running Terraform commands will correctly pass the `instance_type` variable.
- ✗
Using the -vars flag to pass JSON string.
Why it's wrong here
Terraform does not include a `-vars` command-line flag for passing a JSON string directly. While variables can be defined in JSON format within a `.tfvars.json` file, which can then be referenced using the `-var-file` flag, there is no direct `-vars` flag to embed a JSON string on the command line. Attempting to use a non-existent flag like `-vars` will result in a command-line parsing error.
Go deeper
Related to this question
About these practice questions
One of 434 original TF-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.