SASERÁ Academy
HashiCorp Terraform Associate · 004 · free practice

Free Terraform Associate 004 practice questions, every option explained

Ten exam-style scenarios across the eight 004 objectives: state locking and drift, moved blocks, write-only arguments, modules and HCP Terraform. Answer, then read why each option is right or wrong.

  • 1 hour
  • Tests Terraform 1.12
  • Valid 2 years
Terraform Associate 004 exam prep course cover

10 free Terraform Associate 004 practice questions

At least one from each of the eight objectives, taken from the course. Click an option to answer; the explanation under every option appears as soon as you do.

0 of 10 answered · 0 correctEvery option is explained after you answer
IaC with TerraformQuestion 1 of 10

A pipeline runs terraform apply twice in a row on the same unchanged configuration. Nothing changed in the cloud account between the two runs. What should the second run report?

  • Terraform tracks what it already created in state, so it does not create a second copy of each resource.
  • Correct. Terraform is idempotent. When the real infrastructure matches the configuration, the plan is empty and the apply makes no changes.
  • Existing resources that match the configuration are not an error. They simply need no action.
  • Terraform replaces a resource only when a change requires it, not on every apply.
Why it matters: Idempotency means applying the same configuration repeatedly produces the same result without extra changes.
Terraform FundamentalsQuestion 2 of 10

A configuration sets version = "~> 5.1" for the AWS provider. Which versions does this constraint allow?

  • That is the behavior of ~> 5.1.0, a three-part value. The two-part value in ~> 5.1 allows later minor releases too.
  • The pessimistic operator adds an upper bound at the next major version here, so 6.x is excluded.
  • Correct. With a two-part value, only the last part may increase. That allows 5.1, 5.2, 5.99, and so on, but not 6.0.
  • 5.0.0 is below the minimum of 5.1, so it is not allowed.
Why it matters: The pessimistic operator allows only the rightmost part of the given version to increase.
Core WorkflowQuestion 3 of 10

A resource has `lifecycle { create_before_destroy = true }` and a change requires replacing it. Which symbol does the plan show for that resource?

  • -/+ is the default destroy-then-create order, which create_before_destroy reverses.
  • ~ is an in-place update, not a replacement.
  • + alone is a brand-new object, with no old object destroyed.
  • Correct. +/- means Terraform creates the replacement first and then destroys the old object.
Why it matters: create_before_destroy changes the replacement order, and the plan shows it as +/-.
Terraform ConfigurationQuestion 4 of 10

resource "aws_subnet" "a" sets vpc_id = aws_vpc.main.id. The engineer asks whether depends_on = [aws_vpc.main] is needed so the VPC is created first. What is the correct answer?

  • File order does not decide operation order. The dependency graph does.
  • Correct. Because the subnet reads aws_vpc.main.id, Terraform creates the VPC first automatically.
  • Implicit dependencies apply to all references, including between managed resources.
  • Terraform runs independent operations in parallel, but it respects dependencies.
Why it matters: Referencing another resource's attribute creates an implicit dependency. Terraform builds its graph from these references.
Terraform ConfigurationQuestion 5 of 10

A provider offers a write-only argument for a database password. The engineer passes it an ephemeral value. Which statement describes the behavior?

  • That describes sensitive values in normal arguments, not write-only ones.
  • Write-only values are not saved in the plan either.
  • Terraform does not create a separate encrypted state for these values.
  • Correct. Write-only arguments are write-only for Terraform: sent during apply, never persisted.
Why it matters: Write-only arguments, added in Terraform 1.11, accept values (including ephemeral ones) that are sent to the provider but never stored in plan or state.
Terraform ModulesQuestion 6 of 10

A module block uses source = "hashicorp/consul/aws". What does each part of this public Terraform Registry address represent, in order?

  • Registry addresses are not Git paths. A branch would be selected with ?ref= on a Git source, not by the third segment.
  • The first segment is the namespace and the version goes in the separate version argument, not in the source string.
  • Correct. Public registry addresses use the NAMESPACE/NAME/PROVIDER format. Here hashicorp is the namespace, consul the module name, and aws the main provider.
  • The public registry hostname is implied and omitted. HCP Terraform workspaces are not part of a module address.
Why it matters: Public registry modules use NAMESPACE/NAME/PROVIDER. The registry hostname registry.terraform.io is implied.
State ManagementQuestion 7 of 10

An engineer runs terraform apply and gets Error acquiring the state lock. The lock details show a colleague started an apply two minutes ago. What should the engineer do?

  • Forcing the unlock during an active apply risks concurrent writes and a corrupted state.
  • Disabling locking allows two applies to write state at the same time.
  • Deleting state would make Terraform forget every managed resource.
  • Correct. The lock is protecting an active run. Waiting, or using -lock-timeout, is the safe choice.
Why it matters: A lock held by an active run should be left alone. force-unlock is only for locks that were left behind.
State ManagementQuestion 8 of 10

A refresh-only plan shows that an operator added a tag to an instance in the console. The team wants to accept that change in state without changing any infrastructure. Which command should they run?

  • Correct. A refresh-only apply writes the refreshed values into state and changes no real infrastructure.
  • A normal apply would bring the resource back to the configuration and remove the tag.
  • This recreates the instance, which is not the goal.
  • The instance is already managed, and import needs a resource ID.
Why it matters: apply -refresh-only updates state to match reality. Update the configuration too if the change should be kept.
Maintain InfrastructureQuestion 9 of 10

Which statement correctly contrasts a moved block with the terraform state mv command?

  • It is the reverse. state mv touches only the current state, while a moved block applies to every workspace that uses the configuration.
  • Neither one changes the real infrastructure. Both only change the address recorded in state.
  • With a moved block, the old resource block is deleted and only the new address remains in the configuration.
  • Correct. The moved block shows up in the plan and applies to every state that uses the configuration. state mv acts immediately on only the current state.
Why it matters: A moved block is declarative configuration that is applied through plan and apply wherever the configuration runs. terraform state mv is an imperative edit to a single state file.
HCP TerraformQuestion 10 of 10

A developer's configuration uses the cloud block with a CLI-driven workspace. They run terraform plan on a laptop. Where does the plan actually run?

  • That describes local execution mode. The default remote execution runs in HCP Terraform.
  • HCP Terraform runs the plan on its own workers, not on the VCS provider's CI system.
  • CLI-driven runs start from the terminal. Pull requests matter only in the VCS-driven workflow.
  • Correct. With remote execution, the plan runs on HCP Terraform workers and the log streams to the developer's terminal.
Why it matters: In the CLI-driven workflow with remote execution, Terraform uploads the configuration and the run happens in HCP Terraform while logs stream to the local terminal.

The eight 004 objectives

HashiCorp does not publish weights. The course spreads each 60-question exam across all eight areas, with the most questions on configuration and the core workflow.

ObjectiveWhat it coversQuestions in each course exam
1. Infrastructure as Code with TerraformWhat IaC is, its advantages, multi-cloud and hybrid workflows5
2. Terraform fundamentalsInstalling and versioning providers, multiple providers, how state is used6
3. Core Terraform workflowinit, validate, plan, apply, destroy and fmt10
4. Terraform configurationResources and data sources, variables, outputs, types, functions, dependencies, custom conditions, sensitive data13
5. Terraform modulesModule sources, variable scope, using modules, versions7
6. Terraform state managementLocal backend, locking, remote backends, drift7
7. Maintain infrastructureImport, inspecting state from the CLI, verbose logging5
8. HCP TerraformRuns, collaboration and governance, workspaces and projects, CLI integration7

What the 004 exam really tests

Reading the plan. Many questions show a change and ask what Terraform will do: update in place, replace, create before destroy, or nothing at all. Know the plan symbols and what forces a replacement.

State, not just syntax. Locking, remote backends, drift detection with refresh-only plans, import blocks and moved blocks all come back to one idea: state is how Terraform maps your code to real objects.

The newer language features. Custom conditions (preconditions, postconditions, check blocks, variable validation), ephemeral values and write-only arguments are new in 004, so expect scenarios, not definitions.

HCP Terraform versus the Community edition. You must tell apart what the CLI does on its own and what HCP Terraform adds: remote runs, teams, policies, variable sets, workspaces and projects.

Six full exams, 360 questions, all options explained

Timed practice across all eight objectives, with Choose TWO and Choose THREE items and an exam tip under every question.

See the Terraform 004 course →

Terraform Associate 004 FAQ

What does the Terraform Associate 004 exam cover?

Eight objective areas: infrastructure as code with Terraform, Terraform fundamentals, the core workflow, Terraform configuration, modules, state management, maintaining infrastructure, and HCP Terraform.

How long is the Terraform Associate 004 exam?

One hour. It is a multiple-choice exam delivered online with a remote proctor, and the certification is valid for two years.

Which Terraform version does 004 test?

HashiCorp states that the 004 exam tests Terraform 1.12 and includes HCP Terraform content, the product previously called Terraform Cloud.

What is new in 004 compared with 003?

HashiCorp lists four new topics: depends_on and the create_before_destroy lifecycle rule, custom conditions for validating configuration, ephemeral values and write-only arguments, and organizing HCP Terraform workspaces and projects.

How many questions are on the exam and what is the passing score?

HashiCorp does not publish a question count, domain weights or a passing score for 004. Practice until you score well above 80% on questions you have not seen before.

Are these real HashiCorp exam questions?

No. Every question is original, written from HashiCorp's public 004 objectives. Real exam content is protected; these train the same reasoning without copying it.

Keep going: Terraform 003 vs 004 · Terraform state explained · 2 to 4 week study plan