Reviewed 10 October 2026 against the linked published scope. Associate 004 targets Terraform 1.12. Multiple-choice knowledge exam; keep the tested version separate from the latest CLI.
Memory hook: Configuration declares intent; state binds identity; the plan explains the change.
Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.
Workflow and provider rules
- Terraform is declarative infrastructure provisioning. Its dependency graph orders API operations; providers implement resource/data-source behavior. Multi-cloud support does not translate one vendor's resource schema into another.
required_versionconstrains the CLI;required_providersdeclares provider sources and constraints;providerconfigures API access/region. An alias selects another configuration, not another state. Reusable modules receive aliases through explicit mappings.initprepares backend, providers and modules;fmtformats;validatechecks configuration consistency;plancompares intent and observations;applyexecutes;destroyremoves managed objects in the selected state.- A saved plan captures proposed actions and inputs.
apply FILEexecutes it without the normal approval prompt. Plans can contain secrets. A plan without-outis a preview; later apply creates another plan. - Commit
.terraform.lock.hclfor provider selections/checksums. It does not pin module versions.~> 6.2permits 6.x from 6.2;~> 6.2.0stays in 6.2.x.init -upgradereselects within constraints.
Configuration and modules
- Resources manage lifecycles; data sources read. References create implicit dependencies;
depends_onhandles genuine hidden relationships. Variables are inputs, locals derived names and outputs exposed results. - Lists are ordered, sets deduplicate without index order, maps have string keys, tuples and objects can combine types.
fortransforms values;dynamicemits nested blocks;count/for_eachcreate instances. countuses numeric addresses;for_eachuses known nonsecret keys. Removing an early list entry can shift count identities. Unknown or sensitive identity keys are invalid forfor_each.- In the CLI, explicit
-var/-var-fileinputs outrank automatic variable files and environment values. Child modules have their own scope; pass inputs and consume declared outputs. An HCP workflow adds its documented variable precedence rules. - Validation rejects unsuitable inputs. Preconditions and postconditions can block operations; failed
checkassertions report warnings. Lifecycle options alter behavior:create_before_destroy,prevent_destroy,ignore_changesandreplace_triggered_byare not interchangeable safety guarantees. sensitiveredacts display; it does not encrypt or remove state values. Supported ephemeral values and write-only arguments reduce persistence in permitted contexts. Protect state, saved plans, logs and credentials regardless.- A module is a configuration directory. Pin registry versions or Git commits; local modules share the checked-out project version. Module boundaries do not automatically isolate state or credentials.
State, recovery and collaboration
- State maps resource addresses to remote IDs. Backends determine storage, supported locking and access. Remote storage does not necessarily mean remote execution. Backend configuration cannot use ordinary input variables.
init -migrate-statemigrates an existing backend's state;-reconfigurereinitializes configuration without that migration behavior. Locking prevents concurrent writers; force-unlock is only for a verified stale lock, not a convenient bypass.- Drift is real infrastructure differing from desired/recorded state. A refresh-only plan proposes state/output changes without changing remote objects; applying it still writes state. Decide deliberately whether to accept drift or restore configuration.
- Import binds an existing object to a managed address. CLI import does not generate full matching configuration. A
movedblock preserves identity through address refactoring.state rmforgets an object without deleting it; leftover configuration may recreate it. - CLI workspaces select separate states for one configuration, not strong account isolation. HCP workspaces bundle state, configuration, variables and run settings; projects group them. HCP agents reach private infrastructure; speculative plans support review without applying.
- Policies, run tasks, private modules and permissions support team governance. Prefer scoped short-lived provider credentials. Inspect
state list,state showand protectedTF_LOGoutput before attempting recovery.
Traps
validatecannot prove service capacity or production permissions.prevent_destroyis not an account-wide safeguard and cannot protect a resource whose configuration has been removed.- State deletion is neither infrastructure teardown nor a backup strategy.
Final active recall
1. What does sensitive=true guarantee?
Display redaction in ordinary output; not encryption or omission from state.
2. Rename a resource without replacing it?
Use an appropriate moved block and inspect the resulting plan.
3. Does a lock file freeze remote module versions?
No. Pin module sources/versions separately.
4. When is for_each preferable to count?
When stable named identities should survive removing other instances.
5. A colleague changed a setting manually. What next?
Review drift in a plan and decide whether configuration should restore or accept the change.
Sources and further practice
- Official exam scope
- Objective-to-topic coverage map. Each full topic links to its supporting primary technical documentation.
- Terraform language reference
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Infrastructure as Code
Memory hook: Describe the destination; review the journey.
Must remember
- Declarative configuration describes the desired infrastructure. Terraform compares configuration, recorded identity and provider observations to propose changes. Reapplying unchanged configuration should converge without unnecessary replacement.
- Version control makes changes reviewable. A pull request can show a plan before approval; reusable modules make standards easier to repeat. Configuration still needs testing, credentials and operational ownership.
- Multi-cloud means providers can manage several APIs in one workflow. It does not translate an AWS resource into an equivalent Azure resource. Resource schemas and architecture remain platform-specific.
- Hybrid infrastructure can combine cloud services, DNS, SaaS and supported on-premises APIs. Terraform is primarily a provisioning tool; image building and application configuration may use Packer or a configuration-management system.
- Immutable replacement creates a new object when an attribute cannot change in place. A small code change can therefore have a large availability or data impact. Read the actual plan, including deletions.
Recall drill: explain how a hand-edited production setting becomes drift and why rerunning an imperative script is not the same as comparing desired state.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Repeatable environments | Version configuration, inputs and module versions; review differences. |
| One workflow across cloud vendors | Use the appropriate provider for each API; design each resource explicitly. |
Traps
- A successful plan is not proof that the application will function.
- Code review does not replace review of replacements and destructive actions.
02 · Providers and Resource Identity
Memory hook: Provider talks; state remembers.
Must remember
- A provider is a plugin implementing resource and data-source operations for an API. Terraform Core handles language evaluation and the dependency graph; it delegates API behavior to providers.
required_providersdeclares source addresses and allowed versions. Aproviderblock supplies a configuration such as region or endpoint.required_versionconstrains Terraform itself, not a provider.terraform initinstalls providers. Commit.terraform.lock.hclso colleagues reuse selected provider versions and verified checksums. The lock file does not lock remote module versions.~> 6.2permits later 6.x releases;~> 6.2.0permits later 6.2.x patches.init -upgradereselects versions within constraints, so review the lock-file diff.- Multiple configurations of one provider use
alias; select one withprovider = aws.secondary. Child modules receive aliases through an explicitprovidersmapping and declare expected aliases. - A Terraform resource address identifies a configured instance, such as
module.web.aws_instance.node["blue"]. State connects that address to the remote object identifier. Renaming an address without a move declaration can look like delete-and-create.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Same API, two regions | Two provider configurations, one aliased, with explicit resource/module selection. |
| Reproducible plugin selection | Compatible constraints plus the committed dependency lock file. |
Traps
- A provider alias is not a separate state file.
- An omitted default provider configuration can produce an empty default configuration, which may lack required settings.
03 · The Terraform CLI Workflow
Memory hook: Format, initialise, validate, plan, then approve.
Must remember
| Command | What to remember |
|---|---|
terraform fmt -check -recursive |
Checks canonical formatting; does not contact a cloud API. |
terraform init |
Prepares the backend, modules and providers; rerun after their configuration changes. |
terraform validate |
Checks configuration consistency and types using installed dependencies. It does not prove API authorization or service capacity. |
terraform plan -out=review.tfplan |
Refreshes observations by default and saves proposed actions and input values. Treat the file as sensitive. |
terraform show review.tfplan |
Inspects the saved plan. |
terraform apply review.tfplan |
Executes the saved plan without the usual interactive approval prompt. Protect this step in automation. |
terraform destroy |
Plans destruction of objects managed by the current state; it is not an account-wide cleanup. |
+ means create, ~ update, - destroy and a combined delete/create marker means replacement. Values marked unknown become known later. A plan without -out is a preview; a later apply creates a fresh plan.
Practice on paper: trace a provider upgrade, a module-source change and an input change through this sequence. These notes do not ask you to run apply or destroy against a cloud account.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Review precisely what automation executes | Save the plan, protect it and apply that artifact. |
| Catch syntax/type errors early | Initialise dependencies, then validate; also plan in the intended environment. |
Traps
- Plan can read remote APIs and acquire a lock; it is not always offline.
- Destroy cannot remove resources that Terraform has forgotten or never managed.
04 · Configuration and Sensitive Values
Memory hook: References connect; sensitive only conceals.
Must remember
- Resources manage object lifecycles; data sources read information. References such as
aws_subnet.app.idnormally create implicit dependencies. Usedepends_onfor real hidden ordering requirements, not every relationship. - Variables are module inputs; locals name derived expressions; outputs expose results. In the CLI, explicit
-var/-var-fileoptions override automatic variable files and environment variables. Child modules receive arguments from their caller. - Types include
string,number,bool, lists, sets, maps, tuples and objects. A set removes duplicates and has no index ordering.fortransforms values; adynamicblock generates nested blocks;countandfor_eachcreate resource/module instances. countuses numeric addresses.for_eachuses known map keys or set-of-string elements, which are more stable when items are removed. Sensitive or apply-time-unknown values cannot serve as identity keys.- Variable validation checks input constraints. Preconditions check assumptions before an operation; postconditions check results. A failed
checkassertion reports a warning rather than blocking the operation like a failed precondition. sensitive = trueredacts ordinary display but does not itself remove a value from state. Use secure remote storage and least-privilege access. Vault can supply short-lived secrets; retrieving a secret does not automatically keep it out of state.- Terraform 1.10 introduced ephemeral values; 1.11 added write-only resource arguments, where supported by providers. These reduce persistence in permitted contexts. Do not assume every normal argument accepts ephemeral data.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Stable named instances | Use for_each with nonsecret, known keys. |
| Prevent invalid input | Use a type constraint and variable validation. |
| Avoid persistent secret values | Use supported ephemeral/write-only mechanisms and protect remaining state and plans. |
Traps
- Marking an output sensitive is not encryption.
- Broad depends_on can make more values unknown and cause unnecessary conservative plans.
05 · Modules and Composition
Memory hook: Inputs in; outputs out; versions explicit.
Must remember
A module is a directory of Terraform configuration. The directory where you execute Terraform is the root module; its module blocks call child modules. File names such as main.tf are conventions: Terraform loads the directory’s configuration together.
A child module has its own variable scope. It cannot read a root variable simply because the name matches. Pass region = var.region or another explicit argument; read results through module.network.subnet_ids when the child declares that output.
Module sources may be local paths, registry addresses, version-controlled repositories or supported archives. Registry modules support the version argument. A Git source can pin a tag or commit with ?ref=...; a local module has no independently downloaded version. Rerun init after changing module sources or selected versions.
Prefer small modules that expose useful architecture choices and compose through outputs. Do not put provider configuration inside a reusable module when the caller should control accounts and regions. Provider requirements belong in the child; provider configurations normally come from the root.
Recall drill: sketch two calls to the same VPC module, with different CIDRs. Explain why their resource addresses differ and why their input values do not leak into each other.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Reuse a network pattern | Call a module with explicit inputs and consume its outputs. |
| Repeatable remote module source | Pin a registry version or immutable Git commit. |
Traps
- The provider lock file does not pin a registry module.
- A module is a code boundary, not automatically a state or security boundary.
06 · State, Backends and Drift
Memory hook: One binding, one writer, protected history.
Must remember
State maps configured instances to remote object IDs and stores attributes needed for planning. The default local backend uses a local state file. Remote backends place state in shared storage; locking, encryption and access-control behavior depend on the selected backend.
Locking prevents concurrent writers corrupting a state snapshot. Do not disable locks just to get past a busy run. Force-unlock is a recovery operation for your own stale lock after confirming no writer remains. It does not roll back infrastructure.
Configure storage in a backend block; backend configuration cannot refer to normal variables or resource outputs. Supply authentication through the recommended external credential mechanism. Hard-coded or command-line backend secrets may be cached or captured in plans. init -migrate-state transfers state after a reviewed backend change; -reconfigure treats the configuration as new rather than migrating existing state.
Drift is found when providers read real objects during planning. Decide whether configuration should restore the intended value or be updated to accept the external change. A refresh-only plan proposes state/output updates without proposing remote infrastructure changes; applying it still writes state.
CLI workspaces provide separate state instances for one configuration, but shared credentials/backend access can remain. Use separate roots and permissions when environments need strong isolation. Consumers of terraform_remote_state need access to the underlying snapshot, even though the data source exposes only root outputs.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Team collaboration | Shared protected state with supported locking and a controlled apply process. |
| Deliberate external change | Review drift and update configuration or deliberately reconcile state. |
Traps
- Remote state storage does not always mean remote execution.
- Copying state into Git exposes historical secrets and provides poor locking.
07 · Import, Refactoring and Troubleshooting
Memory hook: Import adopts; move renames; remove forgets.
Must remember
- Import associates an existing remote object with a resource address. The CLI import command updates state but does not write a complete matching configuration. Configuration-driven
importblocks allow adoption to appear in a plan; review any generated configuration before applying it. - Import one real object into one managed address. After adoption, plan again: missing or different arguments can propose changes or replacement. Import is not a backup and does not discover an entire application automatically.
- A moved block records an address change, such as moving a resource into a module, so Terraform can retain its identity. Keep historical moves for consumers who upgrade from older module versions.
terraform state listshows addresses;state show ADDRESSshows a recorded object;terraform showdisplays state or a saved plan. State inspection can reveal secrets.terraform state rm ADDRESSforgets the binding without deleting the remote object. If its configuration remains, a later plan may try to create another object. A reviewedremovedblock with destruction disabled provides a declarative alternative.- Set
TF_LOGto a diagnostic level such as DEBUG or TRACE when troubleshooting;TF_LOG_PATHwrites logs to a file. Disable logging afterward and protect logs because provider requests may contain sensitive data. Inspect initialization, authentication, provider diagnostics and the exact address before changing state.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Rename without recreation | Use a moved block and review the plan. |
| Adopt manually created infrastructure | Import the correct ID into matching configuration. |
| Investigate a recorded instance | Use state list/show before attempting recovery. |
Traps
- Removing state is not resource cleanup.
- Import may succeed while the next plan still proposes destructive changes.
08 · HCP Terraform and Team Workflows
Memory hook: Workspace owns a run; project groups the work.
Must remember
HCP Terraform adds a managed workflow around Terraform: shared state, run history, workspace variables, access controls and integrations. Execution can be remote, agent-based for private-network access, or local with supported state workflows. Terraform Enterprise is the self-managed product; Terraform Community supplies the CLI rather than the whole hosted collaboration system.
An HCP workspace represents a configuration, state, variables and run settings. It is not the same concept as a CLI workspace within one working directory. Projects group workspaces and help apply access and organizational controls. Variable sets share configuration across selected workspaces; carefully scope credentials and precedence.
VCS integration starts plans for proposed changes and runs after configured repository events. A speculative plan is a review preview, not an approved apply. CLI-driven and API-driven workflows support other automation models. An agent can execute runs where private infrastructure is reachable without exposing that infrastructure publicly.
Policy checks, run tasks, private modules, team permissions and cost estimation support governance; availability depends on the product edition and subscription. Policies evaluate rules; run tasks integrate external checks. Neither is a guarantee that an application is secure or its final bill matches an estimate.
Prefer workload identity/dynamic provider credentials over shared long-lived secrets where supported. Grant plan and apply permissions separately when reviewers should inspect changes without executing them.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Private APIs unreachable from hosted runners | Use a properly connected execution agent. |
| Shared approved infrastructure patterns | Use a private module registry plus versioned modules. |
| Separate review from deployment | Combine speculative plans, permissions and an approval workflow. |
Traps
- A CLI workspace and an HCP workspace are not interchangeable terms.
- Product governance features and pricing can change; exam concepts matter more than memorising plan names.