Study guide · Flashcards & memory notes

Terraform Associate Flashcards & Memory Notes

40 recall cards for the facts Terraform Associate (004) keeps asking you to separate: providers and state, the workflow, configuration and modules, and HCP Terraform.

Exam: Terraform Associate (004)4 decks · 40 cardsNo sign-up required

How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.

Study mode

Choose a deck, flip each card, and mark what you already know.

All flashcards

Select a question to reveal its answer.

Deck 1 · Foundations

Infrastructure as code, providers, and why state exists.

10 cards
1.1What is infrastructure as code?

Infrastructure defined in files that a tool can create, change, and destroy, instead of one-off console clicks.

1.2What does declarative mean in Terraform?

You describe the desired end state. Terraform decides the actions that get there.

1.3How can one Terraform configuration use two clouds?

Each cloud has a provider plugin. One configuration can call more than one provider.

1.4What does Terraform state record?

The mapping from each resource address to the real object Terraform manages, plus attributes.

1.5What is a Terraform provider?

A plugin that creates, reads, updates, and deletes resources for one API.

1.6Where do you pin a provider source and version?

In required_providers inside the terraform block. terraform init downloads the plugin.

1.7What does the version constraint ~> 5.0 allow?

Version 5.0 and later 5.x releases, and not 6.0.

1.8How do you use two regions of the same provider?

Add a second provider block with an alias, then set provider to that alias on the resources that need it.

1.9Should you commit the .terraform directory?

No. It is a local cache of providers and modules. Commit .terraform.lock.hcl for a root module.

1.10Is state safe to delete because Terraform can rediscover everything?

No. Without state, Terraform does not know which real object belongs to which resource block.

Deck 2 · Workflow

init, fmt, validate, plan, apply, and destroy.

10 cards
2.1What is the core Terraform workflow?

Write configuration, init, plan, then apply. Destroy removes what that state manages.

2.2What does terraform init do?

It downloads providers and modules and configures the backend for this working directory.

2.3What does terraform validate check?

Syntax and internal consistency, using provider schemas. It does not call the remote API.

2.4What does terraform plan change?

Nothing remote. It prints the create, update, and destroy actions an apply would take.

2.5What does terraform fmt change?

Style only. It rewrites files to a canonical format and does not decide whether they are valid.

2.6What do +, -, ~, and -/+ mean in a plan?

Create, destroy, update in place, and replace.

2.7What is terraform plan -out for?

It saves a plan you can review and then apply exactly. Treat the file as sensitive.

2.8What does terraform destroy remove?

The infrastructure recorded in this configuration's state. Deleting one resource block destroys only that object on the next apply.

2.9Why run terraform init before terraform validate?

Validate loads provider schemas. Those plugins are installed by init.

2.10Does terraform apply always prompt?

A normal apply asks you to confirm. Applying a saved plan file runs that already-reviewed plan.

Deck 3 · Configuration and modules

Blocks, secrets, and the module boundary.

10 cards
3.1What is the difference between a resource block and a data block?

A resource block manages an object. A data block reads an object that already exists.

3.2When is depends_on required?

When Terraform cannot see the dependency from a reference. A reference already creates an implicit dependency.

3.3What does create_before_destroy do?

Terraform creates the replacement before it destroys the old object.

3.4Does sensitive = true keep a value out of state?

No. It redacts CLI output. The value is still stored in state. An ephemeral value is not stored.

3.5What is a write-only argument?

A provider argument you can set and cannot read back. Pair it with an ephemeral value so the secret is not stored.

3.6Are root variables visible inside a child module?

No. Pass them as arguments on the module block. The child sees only its own variables and locals.

3.7How do you pin a registry module?

Set the version argument. A Git source uses a ref on the source address instead.

3.8Why prefer for_each over count when items are removed?

for_each addresses instances by key, so removing one item does not shift the others. count uses an index.

3.9What is the difference between a variable validation and a check block?

A validation block rejects a bad input. A failed check is reported and does not, by itself, stop apply the way a postcondition does.

3.10Can you define your own function in a .tf file?

No. Use built-in functions, or a provider-defined function. There is no function body in the configuration.

Deck 4 · State, maintenance, and HCP Terraform

Backends, import, logs, workspaces, and projects.

10 cards
4.1Where does the local backend store state?

In terraform.tfstate in the working directory.

4.2What is state locking for?

It stops a second Terraform operation from writing the same state at the same time.

4.3What does terraform apply -refresh-only do?

It updates state to match real infrastructure and does not change that infrastructure.

4.4What does an import block do?

It associates an existing object with a resource address. It does not destroy that object.

4.5What does terraform state rm do?

It removes an address from state and leaves the real object in place.

4.6Which TF_LOG setting is the most detailed?

TRACE. Logs can contain secrets, so leave TF_LOG unset for a normal apply.

4.7What does an HCP Terraform workspace contain?

Its own remote state, variables, and runs. A project groups workspaces.

4.8Is a CLI workspace the same as an HCP Terraform workspace?

No. terraform workspace selects a named state in one directory. Objective 8 tests the HCP Terraform workspace.

4.9What starts a VCS-driven run?

A commit or pull request on the connected repository. A speculative plan shows the diff without applying.

4.10What is policy as code in HCP Terraform for?

A Sentinel or Open Policy Agent check can block an apply that breaks a rule. It is not a cloud provider.

Memory notes

Groupings that make the highest-yield Terraform Associate facts easier to recall.

Command jobs

  • init providers, modules, backend
  • fmt style only
  • validate syntax, no API
  • plan preview
  • apply change

Plan symbols

+ creates. - destroys. ~ updates in place. -/+ replaces.

Secrets

  • sensitive redacts the CLI, still in state
  • ephemeral not stored
  • write-only set, never read back

Read versus manage

A data block reads. A resource block manages. Import adopts an existing object. state rm forgets it without deleting it.

Two workspaces

An HCP Terraform workspace holds remote state, variables, and runs. A CLI workspace only selects a state name. A project groups HCP workspaces.

Module boundary

Pass inputs on the module block. Read outputs. Root variables do not leak in. Registry modules take a version. Git sources take a ref.

Continue the Terraform Associate study path

Test what you have learned with a timed practice exam.

Terraform Associate hub →
Available

Overview

Exam format, Terraform 1.12, the eight objectives, and a study plan.

Available

Core Notes

Reference notes for providers, the workflow, configuration, modules, state, and HCP Terraform.

Available · You are here

Flashcards & Memory Notes

40 recall cards in four decks, plus memory notes for workflow, state, and secrets.

Available

Practice Exams

200 original questions with custom exams, explanations, and a score report by objective.

Related Tools

Useful companions while you study.

All study topics →