OnCallReady

Lesson 14.29 · Terraform in Real Life & the Associate Exam · 11 min read

The Terraform Associate (004) exam

In plain words

A driving test does not check whether you can drive your own car around your own street. It checks you know the rules everyone must know, in the examiner's words, in a fixed time. Some questions are tricky on purpose: two answers sound right, and you must know which road sign really means what.

The Terraform Associate (004) exam is like that: one hour, multiple choice, testing Terraform 1.12 across eight objectives, from what IaC is to HCP Terraform. It asks exact commands and flags (-replace, not taint; init -upgrade, not terraform upgrade), "what happens when" questions (removing an item from a count list, a stale plan), and recall facts like the ~> rules and variable precedence. This lesson maps every objective to where the course taught it.

Why take the exam at all

A certification does not make you better at Terraform. What it does: it gets a CV past the filters for platform and DevOps roles, gives you shared vocabulary with interviewers, and - most usefully - its objective list is a completeness check. Anything on the list you cannot explain out loud is a gap that would also trip you in a real PR review.

This lesson is the map: which exam, what it looks like, where each objective was taught, how the questions are written, and the facts that are pure recall. The steps after it are the question banks and timed mock exams.

What you need to know already: Chapters 12-14. Nothing new is taught here; it points back.

Which exam - 003 or 004?

The Notion page says Terraform Associate 003. That exam was retired on 7 January 2026; its replacement, Terraform Associate (004), has been the only version since 8 January 2026. Booking in December 2026 means 004.

Terraform Associate (004)
  format       multiple choice (including multiple-answer and true/false items)
  duration     1 hour, online proctored
  price        70.50 USD plus local taxes, no free retake
  version      tests on Terraform 1.12
  valid for    2 years
  language     English

What changed from 003, in substance: more HCP Terraform (projects, workspaces, organisation - 14.28), full coverage of custom conditions (validation, preconditions, postconditions, checks - 12.8, 12.10), more on drift (13.21), and more on handling sensitive data (including ephemeral values and Key Vault patterns - 14.20).

The 004 objectives, as a checklist

Each line points at the step numbers where the course covers it.

1  Infrastructure as Code with Terraform
   1a  Explain what IaC is                                            12.1
   1b  Describe the advantages of IaC patterns                        12.1
   1c  Explain how Terraform manages multi-cloud, hybrid cloud,
       and service-agnostic workflows                                 12.1, 12.3

2  Terraform fundamentals
   2a  Install and version Terraform providers                        12.3
   2b  Describe how Terraform uses providers                          12.3
   2c  Write Terraform configuration using multiple providers         12.4
   2d  Explain how Terraform uses and manages state                   13.1

3  Core Terraform workflow
   3a  Describe the Terraform workflow                                12.24
   3b  Initialize a Terraform working directory                       12.24, 13.4
   3c  Validate a Terraform configuration                             12.24, 14.6
   3d  Generate and review an execution plan                          12.24, 12.23
   3e  Apply changes to infrastructure                                12.24
   3f  Destroy Terraform-managed infrastructure                       12.24
   3g  Apply formatting and style adjustments                         12.25, 14.6

4  Terraform configuration
   4a  Use and differentiate resource and data blocks                 12.18
   4b  Refer to resource attributes and create cross-resource refs    12.11, 12.18
   4c  Use variables and outputs                                      12.5
   4d  Understand and use complex types                               12.8
   4e  Write dynamic configuration using expressions and functions    12.11, 12.14, 12.13
   4f  Define resource dependencies in configuration                  12.18 (graph, depends_on)
   4g  Validate configuration using custom conditions                 12.8, 12.10
   4h  Understand best practices for managing sensitive data          12.5, 14.20

5  Terraform modules
   5a  Explain how Terraform sources modules                          13.34
   5b  Describe variable scope within modules                         13.34, 13.35
   5c  Use modules in configuration                                   13.37, 13.42
   5d  Manage module versions                                         13.38

6  Terraform state management
   6a  Describe the local backend                                     13.1, 13.4
   6b  Describe state locking                                         13.11
   6c  Configure remote state using the backend block                 13.4
   6d  Manage resource drift and Terraform state                      13.21, 13.15

7  Maintain infrastructure with Terraform
   7a  Import existing infrastructure into your workspace             13.25
   7b  Use the CLI to inspect state                                   13.15
   7c  Describe when and how to use verbose logging                   12.24 (TF_LOG)

8  HCP Terraform
   8a  Use HCP Terraform to create infrastructure                     14.28
   8b  Describe collaboration and governance features                 14.28
   8c  Organize and use HCP workspaces and projects                   14.28
   8d  Configure and use HCP Terraform integration                    14.28 (cloud block, login)

Work through the list as a checklist in the last two weeks: for each line, explain it out loud in two minutes, then do the matching lab or drill again from memory with redo N.M (the game command that rebuilds a step's lab for a fresh attempt). Anything you cannot explain goes to the top of the review queue (review).

How the questions are written

Facts that are pure recall

lock file                 .terraform.lock.hcl - providers only, commit it
state file                terraform.tfstate, backup terraform.tfstate.backup
plugin/module cache       .terraform/ - never commit
default workspace         "default", cannot be deleted
fmt -check exit code      3 (non-zero) when files need formatting
plan -detailed-exitcode   0 none, 1 error, 2 changes
~> 1.2 / ~> 1.2.3         < 2.0.0 / < 1.3.0
precedence                default < TF_VAR_ < terraform.tfvars < *.auto.tfvars < -var/-var-file
TF_LOG levels             TRACE DEBUG INFO WARN ERROR (and JSON)
TF_LOG_PATH               needs TF_LOG set; appends
import block              1.5+; for_each in import 1.7+; -generate-config-out
moved block               1.1+; removed block 1.7+; check block 1.5+
terraform test            1.6+; mock providers 1.7+
ephemeral values          1.10+; write-only arguments 1.11+
cloud block               1.1+; terraform login stores a token
Sentinel levels           advisory, soft-mandatory, hard-mandatory

A few lines decoded:

Exam-day logistics

The remaining steps in this chapter are the question bank (as debriefs you answer out loud, and as cards in review) and timed mock exams.

What you can now do:

Why it helps

The certification is a concrete, checkable signal for a frontend engineer moving into platform work: it gets you past CV filters for platform and DevOps roles, and gives you shared vocabulary with interviewers. More practically, the objective list is a completeness check on your Terraform knowledge; the items you cannot explain out loud in two minutes are the gaps that would also trip you in a real PR review. The traps in exam questions, like sensitive "encrypting" state or depends_on being "required for every reference", are exactly the misconceptions you will hear from colleagues.

FAQ

Is the Notion plan's 003 exam still available?

No. Terraform Associate 003 was retired in early January 2026 and replaced by 004, which is now the only version. It tests Terraform 1.12 and adds more HCP Terraform, custom conditions, drift and sensitive-data handling, including ephemeral values. If you book it this year, it is 004.

How should I study the objectives in the last two weeks?

Use the objective list as a checklist. For each line, explain it out loud in about two minutes, then redo the matching lab or drill from memory with redo. Anything you cannot explain goes to the top of the review queue. Then do timed mock exams to practise the one-minute-per-question pace.

How do I handle select-two and true/false questions?

Read every option. Exactly the number asked for is correct, so select-two means two, no more. Eliminate absolutes ("always", "never") first, since Terraform almost always has an exception. Watch for real words in the wrong place, like a non-existent terraform upgrade command. Mark hard questions and come back; don't get stuck.

The lab runs 1.9 but the exam tests 1.12. What am I missing?

Mainly: ephemeral values (1.10+), write-only arguments (1.11+), and short-circuiting of && and || (1.12). Everything else in the objectives works in 1.9, including import blocks with for_each, removed blocks, check blocks and terraform test. The chapter covers the newer features as concepts; know what problem each solves and its version.

What are the pure-recall facts I should have cold?

The lock file covers providers only; default workspace cannot be deleted; fmt -check exits 3; plan -detailed-exitcode gives 0, 1, 2; ~> 1.2 is below 2.0.0 and ~> 1.2.3 below 1.3.0; variable precedence from default to -var; TF_LOG levels and that TF_LOG_PATH needs TF_LOG and appends; the version each block arrived in; Sentinel levels.

In an interview Junior

What are the benefits of Infrastructure as Code?

Infrastructure described in text files in git, applied by a tool, gives you:

Terraform adds being declarative and idempotent (describe the end state; applying twice changes nothing), one workflow across many providers, and state that maps code to real objects - which is also what you must protect.

Also asked: What happens when you run terraform apply while someone else is applying the same configuration? · Which command replaced terraform taint? · What does the dependency lock file record, and should it be committed?

Practise this lesson in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.