SASERÁ Academy
HashiCorp Terraform Associate · study plan

The Terraform Associate 004 study plan: 2 to 4 weeks

Four weeks for newcomers, two for people who already write Terraform. Hands-on every week, with practice-exam checkpoints so you book when you are ready, not before.

8objective areas
1 hexam time
1.12Terraform version
80%+target before booking
Terraform Associate 004 exam prep cover

The four-week plan

About an hour a day. Keep a small test configuration with a free provider such as random or local, and run every command you read about.

  1. W1

    IaC, fundamentals and the core workflow

    Objectives 1 to 3. IaC benefits, providers, version constraints and the lock file, then init, validate, plan, apply, destroy and fmt. End the week with a diagnostic practice exam to find your weak areas.

  2. W2

    Configuration

    Objective 4, the largest. Resources and data sources, references, variables and outputs, complex types, expressions and functions, depends_on and create_before_destroy, custom conditions, sensitive data, ephemeral values and write-only arguments.

  3. W3

    Modules, state and maintenance

    Objectives 5 to 7. Module sources and versions, variable scope, the local backend, locking, remote backends and drift, then import blocks, moved blocks, state commands and TF_LOG. Take a full timed practice exam.

  4. W4

    HCP Terraform and final practice

    Objective 8: remote runs, the cloud block, teams, policies, variable sets, workspaces and projects. Then take unseen timed exams, read every explanation and book when you clear 80%.

Two-week version: if you already use Terraform at work, do weeks 1 and 2 in the first week, weeks 3 and 4 in the second, and spend the saved time on practice exams and the topics new in 004.

Habits that raise scores

Run it, then read about it. Plan output, error messages and state files are easier to recognize on the exam once you have seen them in your own terminal.

Learn the commands by their job. Most command questions are really about intent: detect drift, move to a new backend, rename without destroying, unlock after a crash. Match the job to the command.

Separate the CLI from HCP Terraform. For every feature, ask whether the Community edition CLI does it on its own or whether it needs HCP Terraform.

Read every option explanation. Wrong options on Terraform questions are real commands and flags for a different situation, so each explanation teaches one more fact.

5 free Terraform 004 practice questions

From five different objectives, taken from the course. Click an option; every option is explained.

0 of 5 answered · 0 correctEvery option is explained after you answer
IaC with TerraformQuestion 1 of 5

A company runs workloads on AWS and Azure and wants one workflow to manage both. How does Terraform support this?

  • Terraform has no generic cross-cloud resource. Resource types such as aws_instance and azurerm_linux_virtual_machine are provider-specific.
  • A single Terraform binary works with any provider. Providers are plugins downloaded during terraform init.
  • The Terraform CLI can use many providers in one configuration without HCP Terraform.
  • Correct. The same HCL and the same init, plan, and apply workflow work for both clouds. The aws and azurerm providers translate the configuration into each platform's API calls.
Why it matters: Terraform gives one workflow across clouds, while providers handle each platform's specific API.
Terraform FundamentalsQuestion 2 of 5

After terraform init, a file named .terraform.lock.hcl appears in the working directory. What does this file record?

  • State locking is handled by the backend. The lock file is about provider dependencies.
  • Correct. The dependency lock file records the exact version of each provider plus package hashes, so later inits install the same, verified packages.
  • The dependency lock file does not track modules, only providers.
  • The lock file never contains credentials.
Why it matters: .terraform.lock.hcl pins provider versions and their checksums.
Core WorkflowQuestion 3 of 5

A new team member asks which sequence an individual practitioner follows to change infrastructure with Terraform. Which sequence describes the core Terraform workflow?

  • You cannot plan changes before the configuration that describes them exists. Writing always comes first.
  • Destroying resources is not part of the normal change workflow. Terraform changes existing objects in place or replaces them when needed.
  • Correct. The core workflow is Write, Plan, Apply: author the code, review the proposed changes, then provision them.
  • Planning after apply defeats its purpose. The plan exists so you can review changes before they happen.
Why it matters: The Terraform core workflow has three steps: Write the configuration, Plan to preview changes, and Apply to make them real.
Terraform ModulesQuestion 4 of 5

A module block uses a registry module with version = "~> 3.0", which allows any 3.x release. The working directory has 3.1.0, and 3.4.0 was just published. Running terraform init again keeps 3.1.0. How can the team move to 3.4.0?

  • -replace forces a resource to be recreated. It does not change which module version is installed.
  • Correct. By default init keeps modules that already satisfy the constraint. -upgrade makes Terraform choose the newest versions allowed by the constraints.
  • The dependency lock file records providers, not modules, and plan does not install modules.
  • -migrate-state moves state between backends and has no effect on module versions.
Why it matters: Use terraform init -upgrade (or terraform get -update) to fetch the newest module version that still meets the constraint.
Maintain InfrastructureQuestion 5 of 5

An engineer on Terraform 1.12 must bring an existing S3 bucket named acme-logs under Terraform management. The team requires that every state change is previewed in a plan and reviewed in a pull request. What should the engineer do?

  • The terraform import command writes to state immediately with no plan preview, which breaks the requirement to review every change first.
  • A refresh-only run only updates objects that are already in state. It never adopts an unmanaged bucket.
  • Correct. An import block is part of the configuration, so it goes through the pull request, appears in the plan, and is written to state during apply.
  • Hand-editing state is error-prone and skips the plan entirely. It is never the supported way to import.
Why it matters: Config-driven import with an import block (Terraform 1.5+) shows the import in the plan and writes it to state only on apply, so it fits a reviewed workflow.

Checkpoints for every week of your plan

Six timed Terraform 004 exams, 360 original questions, every option explained.

See the Terraform 004 course →

FAQ

How long does it take to prepare for Terraform Associate 004?

Engineers who already use Terraform often need about two weeks. If Terraform is new to you, plan on four weeks of an hour or so a day, with hands-on practice.

Do I need to use Terraform before the exam?

It helps a lot. Running init, plan, apply and destroy on a small configuration makes plan output, state and error messages familiar, and many questions are built on them.

Do I need an HCP Terraform account?

It is not required, but a free account lets you see organizations, projects, workspaces and remote runs for yourself, which makes objective 8 much easier.

What score should I reach before booking?

HashiCorp does not publish a passing score. Aim for 80% or higher on full practice exams you have not seen before, across all eight objectives.

More guides: Terraform 003 vs 004 · Terraform state explained · Free Terraform 004 questions · all guides