HashiCorp Certified: Terraform Associate (003) Free Sample Questions

20 free sample questions207 in the full practice test

Try simulator

terraform-associate-003 Sample Questions

  1. Question 1

    A financial services company is using Terraform to manage a multi-tenant environment where each tenant's infrastructure is defined in a separate module. To ensure strict isolation and prevent accidental cross-tenant modifications, the lead architect has mandated that each module invocation must use a unique provider configuration with tenant-specific credentials. How can this be achieved within the root module?

    Answer and explanation

    Correct answer: C

    The correct way to handle multiple configurations for the same provider is by using the alias attribute in the provider block. This creates distinct provider instances. Each module can then be instructed to use a specific provider instance by passing a map to the providers meta-argument within the module block, mapping the provider name (e.g., aws) to the aliased name (e.g., aws.tenant_a). This ensures that each module's resources are managed exclusively by the provider instance configured with that tenant's credentials.

  2. Question 2

    A DevOps team is managing a large-scale application on AWS using Terraform. They have a module that creates an S3 bucket with logging enabled. The logging bucket must be created in a separate security account. The team has configured two AWS provider instances in their root module: one default and one with an alias security. How must they configure the S3 bucket module to ensure the main bucket uses the default provider and the logging bucket uses the security provider?

    Answer and explanation

    Correct answer: C

    Modules are encapsulated and do not automatically inherit aliased providers from the calling module. To use multiple provider configurations within a single module, the module must be explicitly designed to accept them. This is done by defining multiple provider requirements within the module's own terraform block and then passing the correctly configured provider instances from the root module via the providers meta-argument. The root module would map its aliased providers to the provider names expected by the child module, such as providers = { aws.main = aws, aws.logging = aws.security }.

  3. Question 3

    A Terraform configuration contains the following code:

    locals {
    instances = {
    "web-1" = { type = "t3.medium", zone = "us-east-1a" }
    "app-1" = { type = "m5.large", zone = "us-east-1b" }
    }
    }
    
    resource "aws_instance" "server" {
    for_each = local.instances
    
    ami = "ami-0c55b159cbfafe1f0"
    instance_type = each.value.type
    availability_zone = each.value.zone
    }
    

    How would you reference the availability zone of the app-1 instance in an output value?

    Answer and explanation

    Correct answer: B

    When a resource is created using for_each, its instances are accessed like a map. The general format is . [" "]. In this case, the resource is aws_instance.server, and the key for the desired instance is "app-1". Therefore, aws_instance.server["app-1"] references the specific instance object, and .availability_zone accesses its attribute.

  4. Question 4

    True or False: Using the terraform state replace-provider command is the recommended method for upgrading a provider to a new major version within your configuration.

    Answer and explanation

    Correct answer: B

    False. The terraform state replace-provider command is used when a provider's source address changes (e.g., moving from a community fork to an official version), not for version upgrades. The recommended method for upgrading a provider version is to update the version constraint in the required_providers block and then run terraform init -upgrade to download the new version and update the lock file.

  5. Question 5

    A team is building a reusable Terraform module to create a web application stack. They want to allow consumers of the module to optionally define a set of firewall rules. Each rule is an object with protocol, from_port, to_port, and cidr_blocks. Which Terraform language feature should be used to dynamically generate the ingress blocks for the security group resource based on a variable list of rule objects?

    Answer and explanation

    Correct answer: C

    A dynamic block is specifically designed for this purpose. It iterates over a complex type (like a list of objects) and generates a nested block (like ingress) for each item in the collection. By setting for_each to the variable containing the list of rules, you can use the iterator (e.g., ingress.value) to access the attributes of each rule object and populate the content of the generated block.

  6. Question 6

    A developer is writing a Terraform configuration and needs to ensure that a variable instance_count is always a positive integer greater than zero. Which of the following code blocks correctly implements this validation?

    Answer and explanation

    Correct answer: C

    This is the correct syntax. The validation block (not validate) is used within a variable block. The condition argument must be a boolean expression that is true for the value to be valid. Here, var.instance_count > 0 checks for positivity, and floor(var.instance_count) == var.instance_count is a standard way to check if a number is a whole number (an integer). The error_message is returned if the condition is false.

  7. Question 7

    Multiple answers

    Which of the following are valid sources for a Terraform module in a module block? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    This is a valid shorthand for a module from the public Terraform Registry. It follows the / / format.

    This is a valid Git source URL. The git:: prefix indicates the source type, and the ?ref= argument is used to pin the module to a specific branch, tag, or commit hash.

  8. Question 8

    A CI/CD pipeline running on a Linux agent executes terraform plan. The same configuration, when planned on a developer's macOS laptop, shows no changes. However, the pipeline's plan shows a provider version change and wants to update the lock file. What is the most likely cause of this discrepancy?

    Answer and explanation

    Correct answer: B

    The .terraform.lock.hcl file records dependency checksums for each provider for each platform (OS and architecture) it has been initialized on. If terraform init was only run on macOS, the lock file will only contain hashes for darwin_amd64 or darwin_arm64. When the CI/CD pipeline runs on Linux (linux_amd64), it won't find a matching hash, forcing it to select a provider version based on the constraints and add the new platform's hash to the lock file. To prevent this, terraform providers lock -platform=linux_amd64 -platform=darwin_amd64 should be run.

  9. Question 9

    A new team member runs terraform plan and receives an error message: Error: Missing required argument. The missing argument is for a resource that is created by a colleague's configuration in a separate directory. The team is using a shared remote state backend. What is the most effective way to resolve this error?

    Answer and explanation

    Correct answer: B

    The terraform_remote_state data source is the standard way to share information between separate Terraform configurations. It allows one configuration to access the output values of another. By adding this data source and configuring it to point to the colleague's remote state, the new team member can reference the required values (like a VPC ID or subnet ID) without duplicating resource definitions.

  10. Question 10

    When working with HCP Terraform, what is the primary purpose of a workspace?

    Answer and explanation

    Correct answer: B

    In HCP Terraform (and Terraform Cloud), a workspace is a container for everything Terraform needs to manage a collection of infrastructure: the configuration itself (often from a VCS repository), the values for input variables, and most importantly, its own separate state file. This allows teams to manage different environments (dev, staging, prod) or components from the same configuration codebase with isolated state and variables.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 207 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon