Courseiva
Understand IaC concepts →hardMultiple Select

Declarative vs Imperative Infrastructure as Code: Key Differences

Which two statements accurately describe the difference between declarative and imperative IaC approaches? (Choose two.)

Quick Answer

The correct answer is that imperative approaches can lead to configuration drift because step-by-step instructions may produce unintended states, while declarative IaC defines the desired end state and lets the tool determine the steps. This distinction is fundamental: with declarative IaC, as in Terraform using HCL, you simply declare "I want an EC2 instance with ami-abc123 and type t2.micro," and Terraform automatically figures out the create, update, or delete actions needed to reach that state. In contrast, imperative IaC, like a series of AWS CLI commands, explicitly dictates each step—run-instances, wait, tag—which risks drift if a step fails or the environment changes between commands. On the HashiCorp Terraform Associate TF-003 exam, this concept tests your understanding of why Terraform’s declarative model prevents drift and ensures idempotency. A common trap is confusing Ansible’s declarative YAML with imperative scripting; remember, if you’re telling the tool *how* to do it step-by-step, it’s imperative. Memory tip: "Declarative = *what*; Imperative = *how*."

⚠ Common exam trap

HashiCorp often tests the misconception that declarative IaC eliminates the need for idempotency, but in reality, declarative tools enforce idempotency through state management and plan generation, making it a key feature rather than an omission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Declarative focuses on the desired outcome, while imperative specifies step-by-step commands

Option C is correct because declarative IaC (e.g., Terraform HCL, CloudFormation templates) defines the desired end state of the infrastructure and lets the tool determine the execution path, whereas imperative IaC (e.g., shell scripts, AWS CLI command sequences) explicitly lists the ordered commands needed to reach that state. Option D is correct because imperative approaches execute fixed steps without inherently reconciling actual versus desired state, so re-running or partially failing scripts can leave resources in unintended configurations, producing configuration drift. Option A is wrong because imperative techniques are widely used in IaC, such as provisioning with AWS CLI or Ansible ad-hoc commands. Option B is wrong because speed depends on implementation, provider APIs, and parallelism, not on whether the approach is declarative or imperative. Option E is wrong because declarative tools still rely on idempotency mechanisms (state files, resource providers, or reconciliation loops) to avoid duplicate changes; declarative syntax alone does not eliminate the need for idempotent behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Imperative is only used for scripting, not IaC

    Why it's wrong here

    Imperative tooling does define infrastructure, so restricting it to general scripting misstates the model. The real axis is how desired state is expressed: imperative issues explicit commands in sequence, whereas declarative specifies the end state and lets the tool determine execution. It tempts because imperative code resembles scripts, yet it remains valid IaC.

  • ✗

    Declarative tools are always faster than imperative tools

    Why it's wrong here

    Declarative tools are not inherently faster; execution speed depends on the provider's API calls and reconciliation logic, not the paradigm itself. This option is tempting because declarative configuration often reduces human effort and drift, but speed is not the axis of difference — the distinction concerns specifying desired end state versus explicit procedural steps.

  • ✓

    Declarative focuses on the desired outcome, while imperative specifies step-by-step commands

    Why this is correct

    Declarative IaC defines the target end state and lets the tool determine execution, whereas imperative IaC encodes explicit sequential commands. This outcome-versus-steps axis is the defining distinction between the two approaches, directly matching the question's requirement.

  • ✓

    Imperative can lead to configuration drift because steps may cause unintended states

    Why this is correct

    Imperative scripts execute fixed steps without reconciling actual state, so repeated or partial runs can leave resources in unintended configurations, producing configuration drift. Declarative tools instead converge on the declared desired state, correcting drift automatically, which is why this statement accurately describes imperative IaC.

  • ✗

    Declarative eliminates the need for idempotency

    Why it's wrong here

    Declarative tooling still requires idempotency: reapplying the same configuration must converge to the same state without duplicating resources, so the need remains. It is tempting because declarative tools hide drift-correction behind state files, making idempotency appear automatic. Idempotency is a property of the provider's apply logic, not the paradigm itself.

About these practice questions

One of 434 original TF-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on TF-004

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A team is evaluating Terraform and Ansible for infrastructure provisioning. They note that Terraform describes the desired end state, while Ansible defines steps to reach that state. This difference is best described as:

easy
  • ✓ A.Declarative vs imperative
  • B.Client-server vs agentless
  • C.Immutable vs mutable
  • D.Push vs pull

Why A: Terraform is declarative — you describe the desired end state and Terraform computes the actions to reach it. Ansible playbooks are imperative — you list ordered tasks that execute step by step. This is the classic declarative-versus-imperative distinction the question describes.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.