Free Terraform Associate 004 practice questions, every option explained
Ten exam-style scenarios across the eight 004 objectives: state locking and drift, moved blocks, write-only arguments, modules and HCP Terraform. Answer, then read why each option is right or wrong.
- 1 hour
- Tests Terraform 1.12
- Valid 2 years

10 free Terraform Associate 004 practice questions
At least one from each of the eight objectives, taken from the course. Click an option to answer; the explanation under every option appears as soon as you do.
A pipeline runs terraform apply twice in a row on the same unchanged configuration. Nothing changed in the cloud account between the two runs. What should the second run report?
- Terraform tracks what it already created in state, so it does not create a second copy of each resource.
- Correct. Terraform is idempotent. When the real infrastructure matches the configuration, the plan is empty and the apply makes no changes.
- Existing resources that match the configuration are not an error. They simply need no action.
- Terraform replaces a resource only when a change requires it, not on every apply.
A configuration sets version = "~> 5.1" for the AWS provider. Which versions does this constraint allow?
- That is the behavior of ~> 5.1.0, a three-part value. The two-part value in ~> 5.1 allows later minor releases too.
- The pessimistic operator adds an upper bound at the next major version here, so 6.x is excluded.
- Correct. With a two-part value, only the last part may increase. That allows 5.1, 5.2, 5.99, and so on, but not 6.0.
- 5.0.0 is below the minimum of 5.1, so it is not allowed.
A resource has `lifecycle { create_before_destroy = true }` and a change requires replacing it. Which symbol does the plan show for that resource?
- -/+ is the default destroy-then-create order, which create_before_destroy reverses.
- ~ is an in-place update, not a replacement.
- + alone is a brand-new object, with no old object destroyed.
- Correct. +/- means Terraform creates the replacement first and then destroys the old object.
resource "aws_subnet" "a" sets vpc_id = aws_vpc.main.id. The engineer asks whether depends_on = [aws_vpc.main] is needed so the VPC is created first. What is the correct answer?
- File order does not decide operation order. The dependency graph does.
- Correct. Because the subnet reads aws_vpc.main.id, Terraform creates the VPC first automatically.
- Implicit dependencies apply to all references, including between managed resources.
- Terraform runs independent operations in parallel, but it respects dependencies.
A provider offers a write-only argument for a database password. The engineer passes it an ephemeral value. Which statement describes the behavior?
- That describes sensitive values in normal arguments, not write-only ones.
- Write-only values are not saved in the plan either.
- Terraform does not create a separate encrypted state for these values.
- Correct. Write-only arguments are write-only for Terraform: sent during apply, never persisted.
A module block uses source = "hashicorp/consul/aws". What does each part of this public Terraform Registry address represent, in order?
- Registry addresses are not Git paths. A branch would be selected with ?ref= on a Git source, not by the third segment.
- The first segment is the namespace and the version goes in the separate version argument, not in the source string.
- Correct. Public registry addresses use the NAMESPACE/NAME/PROVIDER format. Here hashicorp is the namespace, consul the module name, and aws the main provider.
- The public registry hostname is implied and omitted. HCP Terraform workspaces are not part of a module address.
An engineer runs terraform apply and gets Error acquiring the state lock. The lock details show a colleague started an apply two minutes ago. What should the engineer do?
- Forcing the unlock during an active apply risks concurrent writes and a corrupted state.
- Disabling locking allows two applies to write state at the same time.
- Deleting state would make Terraform forget every managed resource.
- Correct. The lock is protecting an active run. Waiting, or using -lock-timeout, is the safe choice.
A refresh-only plan shows that an operator added a tag to an instance in the console. The team wants to accept that change in state without changing any infrastructure. Which command should they run?
- Correct. A refresh-only apply writes the refreshed values into state and changes no real infrastructure.
- A normal apply would bring the resource back to the configuration and remove the tag.
- This recreates the instance, which is not the goal.
- The instance is already managed, and import needs a resource ID.
Which statement correctly contrasts a moved block with the terraform state mv command?
- It is the reverse. state mv touches only the current state, while a moved block applies to every workspace that uses the configuration.
- Neither one changes the real infrastructure. Both only change the address recorded in state.
- With a moved block, the old resource block is deleted and only the new address remains in the configuration.
- Correct. The moved block shows up in the plan and applies to every state that uses the configuration. state mv acts immediately on only the current state.
A developer's configuration uses the cloud block with a CLI-driven workspace. They run terraform plan on a laptop. Where does the plan actually run?
- That describes local execution mode. The default remote execution runs in HCP Terraform.
- HCP Terraform runs the plan on its own workers, not on the VCS provider's CI system.
- CLI-driven runs start from the terminal. Pull requests matter only in the VCS-driven workflow.
- Correct. With remote execution, the plan runs on HCP Terraform workers and the log streams to the developer's terminal.
The eight 004 objectives
HashiCorp does not publish weights. The course spreads each 60-question exam across all eight areas, with the most questions on configuration and the core workflow.
| Objective | What it covers | Questions in each course exam |
|---|---|---|
| 1. Infrastructure as Code with Terraform | What IaC is, its advantages, multi-cloud and hybrid workflows | 5 |
| 2. Terraform fundamentals | Installing and versioning providers, multiple providers, how state is used | 6 |
| 3. Core Terraform workflow | init, validate, plan, apply, destroy and fmt | 10 |
| 4. Terraform configuration | Resources and data sources, variables, outputs, types, functions, dependencies, custom conditions, sensitive data | 13 |
| 5. Terraform modules | Module sources, variable scope, using modules, versions | 7 |
| 6. Terraform state management | Local backend, locking, remote backends, drift | 7 |
| 7. Maintain infrastructure | Import, inspecting state from the CLI, verbose logging | 5 |
| 8. HCP Terraform | Runs, collaboration and governance, workspaces and projects, CLI integration | 7 |
What the 004 exam really tests
Reading the plan. Many questions show a change and ask what Terraform will do: update in place, replace, create before destroy, or nothing at all. Know the plan symbols and what forces a replacement.
State, not just syntax. Locking, remote backends, drift detection with refresh-only plans, import blocks and moved blocks all come back to one idea: state is how Terraform maps your code to real objects.
The newer language features. Custom conditions (preconditions, postconditions, check blocks, variable validation), ephemeral values and write-only arguments are new in 004, so expect scenarios, not definitions.
HCP Terraform versus the Community edition. You must tell apart what the CLI does on its own and what HCP Terraform adds: remote runs, teams, policies, variable sets, workspaces and projects.
Six full exams, 360 questions, all options explained
Timed practice across all eight objectives, with Choose TWO and Choose THREE items and an exam tip under every question.
Terraform Associate 004 FAQ
What does the Terraform Associate 004 exam cover?
Eight objective areas: infrastructure as code with Terraform, Terraform fundamentals, the core workflow, Terraform configuration, modules, state management, maintaining infrastructure, and HCP Terraform.
How long is the Terraform Associate 004 exam?
One hour. It is a multiple-choice exam delivered online with a remote proctor, and the certification is valid for two years.
Which Terraform version does 004 test?
HashiCorp states that the 004 exam tests Terraform 1.12 and includes HCP Terraform content, the product previously called Terraform Cloud.
What is new in 004 compared with 003?
HashiCorp lists four new topics: depends_on and the create_before_destroy lifecycle rule, custom conditions for validating configuration, ephemeral values and write-only arguments, and organizing HCP Terraform workspaces and projects.
How many questions are on the exam and what is the passing score?
HashiCorp does not publish a question count, domain weights or a passing score for 004. Practice until you score well above 80% on questions you have not seen before.
Are these real HashiCorp exam questions?
No. Every question is original, written from HashiCorp's public 004 objectives. Real exam content is protected; these train the same reasoning without copying it.
Keep going: Terraform 003 vs 004 · Terraform state explained · 2 to 4 week study plan