Skip to content

HashiCorp Certified: Terraform Associate (003) Practice Questions

Prepare for terraform-associate-003 with more than an answer.

207 questions in the full set20 sample questionsUpdated Oct 25, 2025
Exam fee
$70.5 USD
Level
Associate
Valid for
2 years
Domains covered on the exam 9
  1. Understand Infrastructure as Code (IaC) Concepts10%
  2. Understand the Purpose of Terraform (vs Other IaC)10%
  3. Understand Terraform Basics16%
  4. Use Terraform Outside the Core Workflow12%
  5. Interact with Terraform Modules15%
  6. Use the Core Terraform Workflow16%
  7. Implement and Maintain State15%
  8. Read, Generate, and Modify Configuration16%
  9. Understand HCP Terraform Capabilities10%
  1. 1

    True or False: The sensitive = true argument in an output block prevents the sensitive value from ever being written to the Terraform state file.

    Show answer details

    Correct answer: B

    False. The sensitive = true argument is a UI affordance. It tells the Terraform CLI to redact the value from console output (e.g., in plan or apply logs). However, the value is still recorded in the state file in plaintext. This is why securing the state file itself (e.g., using an encrypted remote backend) is a critical security best practice.

  2. 2

    An organization is migrating from Terraform Community Edition to HCP Terraform Enterprise. They want to enforce a policy that all S3 buckets must have versioning enabled. How can this be implemented in HCP Terraform?

    Show answer details

    Correct answer: A

    Sentinel is the policy-as-code framework integrated with HCP Terraform. It allows you to define fine-grained, logic-based policies on Terraform runs. A Sentinel policy can be written to inspect the planned changes (tfplan import) and check the configuration of all resources of type aws_s3_bucket. If the versioning block is missing or disabled, the policy can fail the run before any infrastructure is applied, thus enforcing the organizational requirement.

  3. 3

    You need to write a Terraform expression that returns a list of all public IP addresses from a set of AWS EC2 instances created with for_each. The resource is defined as resource "aws_instance" "web" { for_each = var.instance_names ... }. What is the correct expression?

    Show answer details

    Correct answer: B

    When for_each is used, the resource (aws_instance.web) behaves as a map of objects, where the keys are the items from the for_each set and the values are the instance objects. The splat operator ([*]) only works on lists. To get a list of the instance objects from the map, you must first use the values() function. After applying values(), you have a list of objects, and then the splat operator can be used to extract the public_ip from each object in the list.

  4. 4

    A Terraform plan shows the following output for a resource:

    ~ aws_instance.web[0] (update in-place)

    What does the ~ symbol indicate?

    Show answer details

    Correct answer: D

    In terraform plan output, the ~ (tilde) symbol indicates an in-place update. This means Terraform has detected a change in one or more arguments of the resource that the provider can modify without destroying and recreating the resource itself (e.g., changing tags on an EC2 instance).

  5. 5

    A team is setting up a new Terraform project that will manage infrastructure on both Google Cloud and an on-premises vSphere environment. How must they configure Terraform to handle these two different platforms?

    graph TD Terraform_Core[Terraform Core] -->|Manages| Google_Cloud[Google Cloud] Terraform_Core -->|Manages| vSphere[On-Prem vSphere]

    Show answer details

    Correct answer: D

    Terraform's plugin-based architecture allows it to manage multiple disparate platforms simultaneously. The correct approach is to include a required_providers block for both google and vsphere, and then configure each provider in its own provider block with the necessary credentials and settings. Resources from each provider can then be defined in the same configuration.

  6. 6

    A financial services company is using Terraform to manage a multi-tenant environment where each tenant's infrastructure is defined in a separate module. To ensure strict isolation and prevent accidental cross-tenant modifications, the lead architect has mandated that each module invocation must use a unique provider configuration with tenant-specific credentials. How can this be achieved within the root module?

    Show answer details

    Correct answer: D

    The correct way to handle multiple configurations for the same provider is by using the alias attribute in the provider block. This creates distinct provider instances. Each module can then be instructed to use a specific provider instance by passing a map to the providers meta-argument within the module block, mapping the provider name (e.g., aws) to the aliased name (e.g., aws.tenant_a). This ensures that each module's resources are managed exclusively by the provider instance configured with that tenant's credentials.

  7. 7

    A DevOps team is managing a large-scale application on AWS using Terraform. They have a module that creates an S3 bucket with logging enabled. The logging bucket must be created in a separate security account. The team has configured two AWS provider instances in their root module: one default and one with an alias security. How must they configure the S3 bucket module to ensure the main bucket uses the default provider and the logging bucket uses the security provider?

    Show answer details

    Correct answer: C

    Modules are encapsulated and do not automatically inherit aliased providers from the calling module. To use multiple provider configurations within a single module, the module must be explicitly designed to accept them. This is done by defining multiple provider requirements within the module's own terraform block and then passing the correctly configured provider instances from the root module via the providers meta-argument. The root module would map its aliased providers to the provider names expected by the child module, such as providers = { aws.main = aws, aws.logging = aws.security }.

  8. 8

    A Terraform configuration contains the following code:

    locals {
    instances = {
    "web-1" = { type = "t3.medium", zone = "us-east-1a" }
    "app-1" = { type = "m5.large", zone = "us-east-1b" }
    }
    }
    
    resource "aws_instance" "server" {
    for_each = local.instances
    
    ami = "ami-0c55b159cbfafe1f0"
    instance_type = each.value.type
    availability_zone = each.value.zone
    }
    

    How would you reference the availability zone of the app-1 instance in an output value?

    Show answer details

    Correct answer: D

    When a resource is created using for_each, its instances are accessed like a map. The general format is . [" "]. In this case, the resource is aws_instance.server, and the key for the desired instance is "app-1". Therefore, aws_instance.server["app-1"] references the specific instance object, and .availability_zone accesses its attribute.

  9. 9

    True or False: Using the terraform state replace-provider command is the recommended method for upgrading a provider to a new major version within your configuration.

    Show answer details

    Correct answer: B

    False. The terraform state replace-provider command is used when a provider's source address changes (e.g., moving from a community fork to an official version), not for version upgrades. The recommended method for upgrading a provider version is to update the version constraint in the required_providers block and then run terraform init -upgrade to download the new version and update the lock file.

  10. 10

    A team is building a reusable Terraform module to create a web application stack. They want to allow consumers of the module to optionally define a set of firewall rules. Each rule is an object with protocol, from_port, to_port, and cidr_blocks. Which Terraform language feature should be used to dynamically generate the ingress blocks for the security group resource based on a variable list of rule objects?

    Show answer details

    Correct answer: C

    A dynamic block is specifically designed for this purpose. It iterates over a complex type (like a list of objects) and generates a nested block (like ingress) for each item in the collection. By setting for_each to the variable containing the list of rules, you can use the iterator (e.g., ingress.value) to access the attributes of each rule object and populate the content of the generated block.

Create an account to continue.