Skip to content

TAO-Pro Terraform Authoring and Operations Professional Practice Questions

Prepare for TAO-Pro with more than an answer.

216 questions in the full set17 sample questionsUpdated Mar 12, 2026
Exam fee
$295 USD
Time limit
240 minutes
Questions on the exam
12 multiple-choice questions + 4 lab-based scenarios
Passing score
Not publicly disclosed by HashiCorp
Level
Professional
Valid for
2 years
Domains covered on the exam 6
  1. Manage Resource Lifecycle20%
  2. Develop and Troubleshoot Dynamic Configuration25%
  3. Develop Collaborative Terraform Workflows15%
  4. Create, Maintain, and Use Terraform Modules20%
  5. Configure and Use Terraform Providers10%
  6. Collaborate on Infrastructure as Code Using HCP Terraform10%
  1. 1

    You are working on a Terraform configuration that provisions a multi-region application. You have a root module that instantiates a child module named network. The root module has two provider configurations for AWS: the default one (us-east-1) and an aliased one (us-west-2). You need to pass the aliased provider to the network module so it creates resources in us-west-2. Which syntax correctly achieves this?

    Show answer details

    Correct answer: A

    To pass providers to a module, you use the providers meta-argument map. The key is the provider name expected by the module (e.g., aws), and the value is the provider configuration in the root module (e.g., aws.us-west-2).

  2. 2

    You need to select ALL correct statements regarding the terraform plan -refresh-only command. (Select TWO)

    Show answer details

    Correct answer: B, C

    plan -refresh-only (and the subsequent apply) is designed to reconcile state drift. It reads the current settings from the provider and updates the state file, but it never proposes changes to the actual infrastructure.

    Unlike the legacy terraform refresh command (which was unsafe because it updated state immediately), plan -refresh-only produces a plan that you can inspect. You must then run terraform apply on that plan to actually commit the changes to the state file.

  3. 3

    Which Terraform function would you use to read the contents of a file from the local filesystem and return it as a string, while ensuring that the file contents are treated as UTF-8 encoded text?

    Show answer details

    Correct answer: C

    The file(path) function reads the file at the given path and returns its content as a string. It expects the file to contain UTF-8 text.

  4. 4

    You are designing a module that accepts a variable instance_count. You want to use this variable to create multiple EC2 instances, but only if the variable enable_instances is set to true. If enable_instances is false, no instances should be created. Which meta-argument combination is best suited for this conditional creation logic?

    Show answer details

    Correct answer: D

    The count meta-argument accepts a numeric value. Using a ternary operator condition ? true_val : false_val allows you to set the count to 0 (disabling creation) when enable_instances is false, or the desired number when true.

  5. 5

    You have a root module that defines an aws_s3_bucket resource. You want to execute a script on your local machine immediately after this bucket is successfully created. Which provisioner should you use?

    Show answer details

    Correct answer: D

    The local-exec provisioner invokes a local executable after a resource is created. It runs on the machine where Terraform is being executed.

  6. 6

    You are the Lead Terraform Architect for a financial services firm. You are refactoring a large monolithic configuration into smaller, reusable modules to improve maintainability. One specific resource, an aws_s3_bucket named logs, needs to be moved from the root configuration into a new child module named audit_logs. You must ensure that the existing bucket is NOT destroyed and recreated during this refactoring process, as it contains petabytes of compliance data. Which configuration block should you add to your root module to facilitate this state migration?

    Show answer details

    Correct answer: D

    The moved block allows you to refactor infrastructure code without destroying and recreating resources. By specifying the from address (the old resource location) and the to address (the new location inside the module), Terraform interprets the change as a rename in the state file rather than a create/destroy action.

  7. 7

    A DevOps engineer is tasked with importing a legacy EC2 instance into a Terraform configuration. The engineer has written the resource "aws_instance" "legacy" {} block but does not know the exact instance ID required for the import. However, they know the instance has a specific tag Role = "LegacyApp". Which approach allows the engineer to import this resource using Terraform 1.5+ declarative import syntax without manually looking up the ID first?

    Show answer details

    Correct answer: B

    Terraform 1.5+ import blocks allow the id field to be an expression that references other values, including data sources. This allows dynamic resolution of the ID based on tags before the import occurs.

  8. 8

    You are managing a critical production environment where applying a configuration that accidentally changes the user_data of an EC2 instance would trigger a replacement, causing unacceptable downtime. You want to ensure that any future terraform apply fails if it attempts to replace this specific instance due to a change in user_data. Which lifecycle configuration should you apply?

    Show answer details

    Correct answer: C

    Using ignore_changes instructs Terraform to ignore differences between the configuration and the live state for the specified attributes. If the user_data in config changes, Terraform will simply ignore it and NOT trigger a replacement. This achieves the goal of preventing downtime caused by this specific change.

Create an account to continue.