HashiCorp Certified: Terraform Associate (003) Practice Questions
Prepare for terraform-associate-003 with more than an answer.
- Exam fee
- $70.5 USD
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 9
- Understand Infrastructure as Code (IaC) Concepts10%
- Understand the Purpose of Terraform (vs Other IaC)10%
- Understand Terraform Basics16%
- Use Terraform Outside the Core Workflow12%
- Interact with Terraform Modules15%
- Use the Core Terraform Workflow16%
- Implement and Maintain State15%
- Read, Generate, and Modify Configuration16%
- Understand HCP Terraform Capabilities10%
- 1
True or False: The
sensitive = trueargument in an output block prevents the sensitive value from ever being written to the Terraform state file.Show answer details
Correct answer: B
False. The
sensitive = trueargument is a UI affordance. It tells the Terraform CLI to redact the value from console output (e.g., inplanorapplylogs). However, the value is still recorded in the state file in plaintext. This is why securing the state file itself (e.g., using an encrypted remote backend) is a critical security best practice. - 2
An organization is migrating from Terraform Community Edition to HCP Terraform Enterprise. They want to enforce a policy that all S3 buckets must have versioning enabled. How can this be implemented in HCP Terraform?
Show answer details
Correct answer: A
Sentinel is the policy-as-code framework integrated with HCP Terraform. It allows you to define fine-grained, logic-based policies on Terraform runs. A Sentinel policy can be written to inspect the planned changes (
tfplanimport) and check the configuration of all resources of typeaws_s3_bucket. If theversioningblock is missing or disabled, the policy can fail the run before any infrastructure is applied, thus enforcing the organizational requirement. - 3
You need to write a Terraform expression that returns a list of all public IP addresses from a set of AWS EC2 instances created with
for_each. The resource is defined asresource "aws_instance" "web" { for_each = var.instance_names ... }. What is the correct expression?Show answer details
Correct answer: B
When
for_eachis used, the resource (aws_instance.web) behaves as a map of objects, where the keys are the items from thefor_eachset and the values are the instance objects. The splat operator ([*]) only works on lists. To get a list of the instance objects from the map, you must first use thevalues()function. After applyingvalues(), you have a list of objects, and then the splat operator can be used to extract thepublic_ipfrom each object in the list. - 4
A Terraform plan shows the following output for a resource:
~ aws_instance.web[0] (update in-place)What does the
~symbol indicate?Show answer details
Correct answer: D
In
terraform planoutput, the~(tilde) symbol indicates an in-place update. This means Terraform has detected a change in one or more arguments of the resource that the provider can modify without destroying and recreating the resource itself (e.g., changing tags on an EC2 instance). - 5
A team is setting up a new Terraform project that will manage infrastructure on both Google Cloud and an on-premises vSphere environment. How must they configure Terraform to handle these two different platforms?
graph TD Terraform_Core[Terraform Core] -->|Manages| Google_Cloud[Google Cloud] Terraform_Core -->|Manages| vSphere[On-Prem vSphere]Show answer details
Correct answer: D
Terraform's plugin-based architecture allows it to manage multiple disparate platforms simultaneously. The correct approach is to include a
required_providersblock for bothgoogleandvsphere, and then configure each provider in its ownproviderblock with the necessary credentials and settings. Resources from each provider can then be defined in the same configuration. - 6
A financial services company is using Terraform to manage a multi-tenant environment where each tenant's infrastructure is defined in a separate module. To ensure strict isolation and prevent accidental cross-tenant modifications, the lead architect has mandated that each module invocation must use a unique provider configuration with tenant-specific credentials. How can this be achieved within the root module?
Show answer details
Correct answer: D
The correct way to handle multiple configurations for the same provider is by using the
aliasattribute in theproviderblock. This creates distinct provider instances. Each module can then be instructed to use a specific provider instance by passing a map to theprovidersmeta-argument within themoduleblock, mapping the provider name (e.g.,aws) to the aliased name (e.g.,aws.tenant_a). This ensures that each module's resources are managed exclusively by the provider instance configured with that tenant's credentials. - 7
A DevOps team is managing a large-scale application on AWS using Terraform. They have a module that creates an S3 bucket with logging enabled. The logging bucket must be created in a separate security account. The team has configured two AWS provider instances in their root module: one default and one with an alias
security. How must they configure the S3 bucket module to ensure the main bucket uses the default provider and the logging bucket uses thesecurityprovider?Show answer details
Correct answer: C
Modules are encapsulated and do not automatically inherit aliased providers from the calling module. To use multiple provider configurations within a single module, the module must be explicitly designed to accept them. This is done by defining multiple provider requirements within the module's own
terraformblock and then passing the correctly configured provider instances from the root module via theprovidersmeta-argument. The root module would map its aliased providers to the provider names expected by the child module, such asproviders = { aws.main = aws, aws.logging = aws.security }. - 8
A Terraform configuration contains the following code:
locals { instances = { "web-1" = { type = "t3.medium", zone = "us-east-1a" } "app-1" = { type = "m5.large", zone = "us-east-1b" } } } resource "aws_instance" "server" { for_each = local.instances ami = "ami-0c55b159cbfafe1f0" instance_type = each.value.type availability_zone = each.value.zone }How would you reference the availability zone of the
app-1instance in an output value?Show answer details
Correct answer: D
When a resource is created using
for_each, its instances are accessed like a map. The general format is. [" "]. In this case, the resource isaws_instance.server, and the key for the desired instance is"app-1". Therefore,aws_instance.server["app-1"]references the specific instance object, and.availability_zoneaccesses its attribute. - 9
True or False: Using the
terraform state replace-providercommand is the recommended method for upgrading a provider to a new major version within your configuration.Show answer details
Correct answer: B
False. The
terraform state replace-providercommand is used when a provider's source address changes (e.g., moving from a community fork to an official version), not for version upgrades. The recommended method for upgrading a provider version is to update the version constraint in therequired_providersblock and then runterraform init -upgradeto download the new version and update the lock file. - 10
A team is building a reusable Terraform module to create a web application stack. They want to allow consumers of the module to optionally define a set of firewall rules. Each rule is an object with
protocol,from_port,to_port, andcidr_blocks. Which Terraform language feature should be used to dynamically generate theingressblocks for the security group resource based on a variable list of rule objects?Show answer details
Correct answer: C
A
dynamicblock is specifically designed for this purpose. It iterates over a complex type (like a list of objects) and generates a nested block (likeingress) for each item in the collection. By settingfor_eachto the variable containing the list of rules, you can use theiterator(e.g.,ingress.value) to access the attributes of each rule object and populate thecontentof the generated block.
