Command jobs
- init providers, modules, backend
- fmt style only
- validate syntax, no API
- plan preview
- apply change
Study guide · Flashcards & memory notes
40 recall cards for the facts Terraform Associate (004) keeps asking you to separate: providers and state, the workflow, configuration and modules, and HCP Terraform.
How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.
Choose a deck, flip each card, and mark what you already know.
You marked every card in this deck as known. Shuffle and run through it again, or choose another deck.
Select a question to reveal its answer.
Infrastructure as code, providers, and why state exists.
Infrastructure defined in files that a tool can create, change, and destroy, instead of one-off console clicks.
You describe the desired end state. Terraform decides the actions that get there.
Each cloud has a provider plugin. One configuration can call more than one provider.
The mapping from each resource address to the real object Terraform manages, plus attributes.
A plugin that creates, reads, updates, and deletes resources for one API.
In required_providers inside the terraform block. terraform init downloads the plugin.
Version 5.0 and later 5.x releases, and not 6.0.
Add a second provider block with an alias, then set provider to that alias on the resources that need it.
No. It is a local cache of providers and modules. Commit .terraform.lock.hcl for a root module.
No. Without state, Terraform does not know which real object belongs to which resource block.
init, fmt, validate, plan, apply, and destroy.
Write configuration, init, plan, then apply. Destroy removes what that state manages.
It downloads providers and modules and configures the backend for this working directory.
Syntax and internal consistency, using provider schemas. It does not call the remote API.
Nothing remote. It prints the create, update, and destroy actions an apply would take.
Style only. It rewrites files to a canonical format and does not decide whether they are valid.
Create, destroy, update in place, and replace.
It saves a plan you can review and then apply exactly. Treat the file as sensitive.
The infrastructure recorded in this configuration's state. Deleting one resource block destroys only that object on the next apply.
Validate loads provider schemas. Those plugins are installed by init.
A normal apply asks you to confirm. Applying a saved plan file runs that already-reviewed plan.
Blocks, secrets, and the module boundary.
A resource block manages an object. A data block reads an object that already exists.
When Terraform cannot see the dependency from a reference. A reference already creates an implicit dependency.
Terraform creates the replacement before it destroys the old object.
No. It redacts CLI output. The value is still stored in state. An ephemeral value is not stored.
A provider argument you can set and cannot read back. Pair it with an ephemeral value so the secret is not stored.
No. Pass them as arguments on the module block. The child sees only its own variables and locals.
Set the version argument. A Git source uses a ref on the source address instead.
for_each addresses instances by key, so removing one item does not shift the others. count uses an index.
A validation block rejects a bad input. A failed check is reported and does not, by itself, stop apply the way a postcondition does.
No. Use built-in functions, or a provider-defined function. There is no function body in the configuration.
Backends, import, logs, workspaces, and projects.
In terraform.tfstate in the working directory.
It stops a second Terraform operation from writing the same state at the same time.
It updates state to match real infrastructure and does not change that infrastructure.
It associates an existing object with a resource address. It does not destroy that object.
It removes an address from state and leaves the real object in place.
TRACE. Logs can contain secrets, so leave TF_LOG unset for a normal apply.
Its own remote state, variables, and runs. A project groups workspaces.
No. terraform workspace selects a named state in one directory. Objective 8 tests the HCP Terraform workspace.
A commit or pull request on the connected repository. A speculative plan shows the diff without applying.
A Sentinel or Open Policy Agent check can block an apply that breaks a rule. It is not a cloud provider.
Groupings that make the highest-yield Terraform Associate facts easier to recall.
+ creates. - destroys. ~ updates in place. -/+ replaces.
A data block reads. A resource block manages. Import adopts an existing object. state rm forgets it without deleting it.
An HCP Terraform workspace holds remote state, variables, and runs. A CLI workspace only selects a state name. A project groups HCP workspaces.
Pass inputs on the module block. Read outputs. Root variables do not leak in. Registry modules take a version. Git sources take a ref.
Test what you have learned with a timed practice exam.
Exam format, Terraform 1.12, the eight objectives, and a study plan.
Reference notes for providers, the workflow, configuration, modules, state, and HCP Terraform.
40 recall cards in four decks, plus memory notes for workflow, state, and secrets.
200 original questions with custom exams, explanations, and a score report by objective.
Useful companions while you study.
Convert structured data between JSON and YAML with formatting and validation.
Compare two text blocks and highlight added, removed, and changed content.
Generate strong random passwords with custom length, characters, symbols, and security options.
Encode text and files to Base64 or decode Base64 data with UTF-8 support.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. HashiCorp, Terraform, and HCP Terraform are trademarks of HashiCorp. NodnWebTools is not affiliated with, endorsed by, or sponsored by HashiCorp or IBM.