TF-004 Understand Terraform basics Practice Question
You are maintaining a Terraform configuration for a team that uses the local backend. A junior engineer accidentally deletes the terraform.tfstate file from the working directory before running terraform destroy. You need to recover from this situation without disrupting the existing infrastructure. Which two statements about Terraform state are true? (Choose two.)
⚠ Common exam trap
The trap here is assuming Terraform can rediscover existing infrastructure automatically or that state is optional, when in fact state must be rebuilt manually via import.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Terraform state maps real-world resources to your configuration and tracks metadata such as resource dependencies.
Terraform state is the mapping between configuration and real infrastructure, and terraform import is the supported way to reattach existing resources to configuration when state is lost. State also tracks dependencies and metadata, enabling correct planning and destruction order. Automatic discovery is not a feature, and local state is not encrypted by default.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
State files are encrypted by default when using the local backend, so deletion is the only risk.
Why it's wrong here
The local backend stores state as plain JSON on disk and does not encrypt it by default. Sensitive values may be present in cleartext, which is why remote backends with encryption and access controls are recommended for teams. Deletion is not the only risk; exposure and tampering are also concerns. This statement is factually incorrect for the local backend.
- ✗
The state file is optional; Terraform can operate correctly using only the configuration files and provider APIs.
Why it's wrong here
Configuration alone describes desired state but does not record which real resources already exist or their unique IDs. Without state, Terraform cannot determine whether to create, update, or destroy anything, and it would attempt to create new resources that may already exist. State is essential for idempotent operations and for mapping configuration to reality.
- ✗
Terraform can automatically reconstruct the state file by scanning the cloud provider for resources that match the configuration.
Why it's wrong here
Terraform does not perform automatic resource discovery to rebuild state. Providers expose data sources for querying specific resources, but there is no built-in mechanism that scans an entire account and reconstructs resource addresses and dependencies. Recovery requires manual state manipulation or import commands, which is why losing state is serious. This option overstates Terraform's capabilities.
- ✓
Terraform state maps real-world resources to your configuration and tracks metadata such as resource dependencies.
Why this is correct
State is the source of truth that binds configuration resource addresses to actual remote objects. It stores attributes, dependency ordering, and provider information. Without it, Terraform cannot know which real resources correspond to which blocks, so it would plan to create duplicates instead of managing existing ones. This is a core purpose of the state file in every backend, including local.
- ✓
If state is lost, you can use terraform import to associate existing resources with resource addresses in your configuration.
Why this is correct
The terraform import command reads an existing remote object by its provider-specific ID and writes a matching resource instance into state. After importing, you must ensure the configuration matches the real resource attributes. This is the standard recovery path when state is missing. It does not generate configuration, only state entries, so it is a manual and per-resource process.
Go deeper
Related to this question
About these practice questions
This TF-004 question is part of Courseiva's 434-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.