SASERÁ Academy
HashiCorp Terraform Associate · version guide

Terraform Associate 003 vs 004: what changed

Same one-hour exam, reorganized objectives, a newer Terraform version and four new topics. Here is everything that moved, in one page.

9 → 8objective areas
1.12Terraform version tested
4new topics
1 hexam time
Terraform Associate 004 exam prep cover

The four topics new in 004

HashiCorp lists these as the additions. They are also where people who studied with older material lose points.

depends_on and create_before_destroyWhen an explicit dependency is really needed, and how replacing a resource changes order when the new object is created first.
Custom conditionsVariable validation, preconditions, postconditions and check blocks: what each validates, and when a failure stops a run or only warns.
Ephemeral values and write-only argumentsValues that are never persisted to plan or state files, and provider arguments that accept a secret without storing it.
HCP Terraform workspaces and projectsGrouping workspaces into projects, and granting team access or variable sets at the project level.
Exam tip: if a scenario asks how to keep a secret out of state entirely, sensitive = true is not the answer. It only hides values in CLI output. Ephemeral values and write-only arguments are.

How the 003 sections map to 004

003 objective004 objectiveWhat to add
1. Understand IaC concepts · 2. Understand the purpose of Terraform1. Infrastructure as Code with TerraformMerged into one area, including multi-cloud, hybrid and service-agnostic workflows
3. Understand Terraform basics2. Terraform fundamentalsProviders, versions, multiple providers, plus how Terraform uses state
6. Use the core Terraform workflow3. Core Terraform workflowThe same steps: init, validate, plan, apply, destroy and fmt
8. Read, generate, and modify configuration4. Terraform configurationNew: depends_on and create_before_destroy, custom conditions, ephemeral values and write-only arguments
5. Interact with Terraform modules5. Terraform modulesSources, variable scope, use and versioning
7. Implement and maintain state6. Terraform state managementLocal backend, locking, backend block, drift
4. Use Terraform outside the core workflow7. Maintain infrastructure with TerraformImport, inspecting state from the CLI, verbose logging
9. Understand Terraform Cloud capabilities8. HCP TerraformNew name, projects, governance, and CLI integration with the cloud block

Side by side

Terraform Associate 003The previous version
  • Nine objective sections
  • Terraform Cloud under its old name
  • Configuration basics without the newer validation features
  • One-hour multiple-choice exam, online proctored
  • Valid for two years
Terraform Associate 004The current version
  • Eight objective areas
  • Tests Terraform 1.12 and includes HCP Terraform
  • Custom conditions, ephemeral values and write-only arguments
  • One-hour multiple-choice exam, online proctored
  • Valid for two years

Studied for 003? Your catch-up plan

  1. 1

    Learn the four new topics

    Work through depends_on and create_before_destroy, the four kinds of custom conditions, and ephemeral values with write-only arguments in a small test configuration.

  2. 2

    Relearn HCP Terraform

    Organizations, projects, workspaces, teams, variable sets, policies and the cloud block. Drop the Terraform Cloud name from your notes.

  3. 3

    Check what 1.12 changed

    Import blocks and moved blocks instead of older command-only habits, refresh-only plans instead of terraform refresh, and native S3 state locking.

  4. 4

    Take unseen timed practice

    Sit full practice exams written for 004 and read every option explanation before you book.

4 practice questions on the new 004 topics

Taken from the Terraform 004 course. Click an option; every option is explained.

0 of 4 answered · 0 correctEvery option is explained after you answer
Terraform ConfigurationQuestion 1 of 4

A resource with create_before_destroy = true has a fixed name argument, and the provider requires names to be unique. A replacement fails because the new object cannot use the same name. What is a common fix?

  • Correct. A different name for each new object avoids the conflict while both exist.
  • This blocks destruction and does not resolve the naming conflict.
  • This goes back to destroy-then-create, with downtime.
  • Parallelism does not change the fact that both objects must exist at once.
Why it matters: With create_before_destroy, both objects exist at the same time. Unique-name constraints then need a generated name or a name prefix.
Terraform ConfigurationQuestion 2 of 4 · choose two

A platform team compares check blocks with lifecycle preconditions. Which statements are accurate? (Choose TWO.)

  • Preconditions are evaluated during normal planning and apply.
  • Correct. Checks are for monitoring. They do not block plan or apply.
  • check is a top-level block, not a lifecycle argument.
  • self is only available in certain blocks inside a resource, such as postconditions.
  • Correct. Preconditions enforce assumptions and halt the run when false.
Why it matters: Failed check assertions produce warnings and do not block operations. Failed preconditions are errors that stop the run.
Terraform ConfigurationQuestion 3 of 4

An engineer passes an ephemeral variable to the tags argument of a normal aws_instance resource. terraform plan reports an error. Why?

  • The type is not the issue. The context where the value is used is.
  • Sensitive does not make a persisted argument valid for ephemeral values.
  • Correct. Tags would be stored in plan and state, which contradicts the ephemeral guarantee.
  • Ephemeral variables can be set the same ways as other variables.
Why it matters: Ephemeral values are only allowed where nothing is persisted: write-only arguments, provider blocks, locals, ephemeral variables, ephemeral child module outputs, ephemeral resources, and provisioner or connection blocks.
HCP TerraformQuestion 4 of 4

An organization in HCP Terraform has 300 workspaces owned by 12 product teams. An administrator wants to group each team's workspaces into a container that can also carry permissions. Which feature should they use?

  • Correct. Projects group workspaces and let admins grant team access once for everything in the project.
  • Tags help filter and select workspaces, but they are not permission boundaries.
  • Run triggers chain runs between workspaces. They do not organize or secure them.
  • Agent pools control where runs execute, not how workspaces are grouped.
Why it matters: Projects are containers for workspaces. Each workspace belongs to one project, and team access can be granted at the project level.

Written for 004, not recycled from 003

Six timed exams, 360 original questions across all eight objectives, every option explained.

See the Terraform 004 course →

FAQ

What is the main difference between Terraform Associate 003 and 004?

004 reorganizes the objectives into eight areas, tests Terraform 1.12, and adds four topics: depends_on and create_before_destroy, custom conditions, ephemeral values and write-only arguments, and HCP Terraform workspaces and projects.

Is my 003 study material still useful for 004?

Mostly yes. The workflow, providers, modules, state and configuration basics carry over. Add the four new topics and learn HCP Terraform under its current name and features.

Is Terraform Cloud still on the exam?

The product is now called HCP Terraform, and 004 has a full objective area on it: runs, collaboration and governance, workspaces and projects, and CLI integration.

Did the exam format change?

Both are one-hour, multiple-choice exams delivered online with a remote proctor, and both certifications are valid for two years. Check HashiCorp's certification page for the current price and availability before you book.

More guides: Terraform state explained · Terraform 004 study plan · Free Terraform 004 questions · all guides