Why take the exam at all
A certification does not make you better at Terraform. What it does: it gets a CV past the filters for platform and DevOps roles, gives you shared vocabulary with interviewers, and - most usefully - its objective list is a completeness check. Anything on the list you cannot explain out loud is a gap that would also trip you in a real PR review.
This lesson is the map: which exam, what it looks like, where each objective was taught, how the questions are written, and the facts that are pure recall. The steps after it are the question banks and timed mock exams.
What you need to know already: Chapters 12-14. Nothing new is taught here; it points back.
Which exam - 003 or 004?
The Notion page says Terraform Associate 003. That exam was retired on 7 January 2026; its replacement, Terraform Associate (004), has been the only version since 8 January 2026. Booking in December 2026 means 004.
Terraform Associate (004)
format multiple choice (including multiple-answer and true/false items)
duration 1 hour, online proctored
price 70.50 USD plus local taxes, no free retake
version tests on Terraform 1.12
valid for 2 years
language English
- Multiple choice - pick one answer; multiple-answer items say "select two" (or three), and exactly that many are right.
- Online proctored - you take it at home, on camera, with a remote supervisor (the proctor) watching.
- Tests on Terraform 1.12 - a few features are newer than the lab's 1.9 (below).
What changed from 003, in substance: more HCP Terraform (projects, workspaces, organisation - 14.28), full coverage of custom conditions (validation, preconditions, postconditions, checks - 12.8, 12.10), more on drift (13.21), and more on handling sensitive data (including ephemeral values and Key Vault patterns - 14.20).
The 004 objectives, as a checklist
Each line points at the step numbers where the course covers it.
1 Infrastructure as Code with Terraform
1a Explain what IaC is 12.1
1b Describe the advantages of IaC patterns 12.1
1c Explain how Terraform manages multi-cloud, hybrid cloud,
and service-agnostic workflows 12.1, 12.3
2 Terraform fundamentals
2a Install and version Terraform providers 12.3
2b Describe how Terraform uses providers 12.3
2c Write Terraform configuration using multiple providers 12.4
2d Explain how Terraform uses and manages state 13.1
3 Core Terraform workflow
3a Describe the Terraform workflow 12.24
3b Initialize a Terraform working directory 12.24, 13.4
3c Validate a Terraform configuration 12.24, 14.6
3d Generate and review an execution plan 12.24, 12.23
3e Apply changes to infrastructure 12.24
3f Destroy Terraform-managed infrastructure 12.24
3g Apply formatting and style adjustments 12.25, 14.6
4 Terraform configuration
4a Use and differentiate resource and data blocks 12.18
4b Refer to resource attributes and create cross-resource refs 12.11, 12.18
4c Use variables and outputs 12.5
4d Understand and use complex types 12.8
4e Write dynamic configuration using expressions and functions 12.11, 12.14, 12.13
4f Define resource dependencies in configuration 12.18 (graph, depends_on)
4g Validate configuration using custom conditions 12.8, 12.10
4h Understand best practices for managing sensitive data 12.5, 14.20
5 Terraform modules
5a Explain how Terraform sources modules 13.34
5b Describe variable scope within modules 13.34, 13.35
5c Use modules in configuration 13.37, 13.42
5d Manage module versions 13.38
6 Terraform state management
6a Describe the local backend 13.1, 13.4
6b Describe state locking 13.11
6c Configure remote state using the backend block 13.4
6d Manage resource drift and Terraform state 13.21, 13.15
7 Maintain infrastructure with Terraform
7a Import existing infrastructure into your workspace 13.25
7b Use the CLI to inspect state 13.15
7c Describe when and how to use verbose logging 12.24 (TF_LOG)
8 HCP Terraform
8a Use HCP Terraform to create infrastructure 14.28
8b Describe collaboration and governance features 14.28
8c Organize and use HCP workspaces and projects 14.28
8d Configure and use HCP Terraform integration 14.28 (cloud block, login)
Work through the list as a checklist in the last two weeks: for each line, explain it out loud in two minutes, then do the matching lab or drill again from memory with redo N.M (the game command that rebuilds a step's lab for a fresh attempt). Anything you cannot explain goes to the top of the review queue (review).
How the questions are written
- "Which command...": know the exact subcommand and flag.
terraform state list, not "state show all";-replace, nottaint;-refresh-only, notrefresh(the old commands still exist but the exam wants the modern ones, 13.21). - "What happens when...": predict behaviour. Removing an item from a
countlist (12.20); applying a stale plan (14.15); two applies at once (13.11); a variable set in bothTF_VAR_and tfvars (12.5). - "Which is true" (select two): read every option; exactly the number asked for is correct. Eliminate the absolutes ("always", "never") first - Terraform almost always has an exception.
- Distractors - wrong options written to look right - reuse real words in the wrong place:
terraform init -upgradevsterraform upgrade(does not exist);sensitive"encrypts" state (it does not);depends_on"required for every reference" (it is not).
Facts that are pure recall
lock file .terraform.lock.hcl - providers only, commit it
state file terraform.tfstate, backup terraform.tfstate.backup
plugin/module cache .terraform/ - never commit
default workspace "default", cannot be deleted
fmt -check exit code 3 (non-zero) when files need formatting
plan -detailed-exitcode 0 none, 1 error, 2 changes
~> 1.2 / ~> 1.2.3 < 2.0.0 / < 1.3.0
precedence default < TF_VAR_ < terraform.tfvars < *.auto.tfvars < -var/-var-file
TF_LOG levels TRACE DEBUG INFO WARN ERROR (and JSON)
TF_LOG_PATH needs TF_LOG set; appends
import block 1.5+; for_each in import 1.7+; -generate-config-out
moved block 1.1+; removed block 1.7+; check block 1.5+
terraform test 1.6+; mock providers 1.7+
ephemeral values 1.10+; write-only arguments 1.11+
cloud block 1.1+; terraform login stores a token
Sentinel levels advisory, soft-mandatory, hard-mandatory
A few lines decoded:
~> 1.2allows anything below 2.0.0;~> 1.2.3anything below 1.3.0 - only the last number you wrote may grow (12.3, drill 14.26).- Precedence runs left (loses) to right (wins): a
-varflag beats everything. TF_LOG_PATHwrites the debug log to a file, but only ifTF_LOGis also set, and it adds to the end of the file rather than replacing it.- "1.5+" means "added in Terraform 1.5".
Exam-day logistics
- Online proctored: a quiet room, a clear desk, a webcam, photo ID. Run the system check the day before.
- One hour for the whole exam: roughly a minute per question. Mark hard ones and move on; come back to the marked ones at the end.
- Results are shown immediately; the badge arrives by email.
The remaining steps in this chapter are the question bank (as debriefs you answer out loud, and as cards in review) and timed mock exams.
What you can now do:
- Say which exam you are booking, its format and what it tests.
- Use the objective list as a checklist and find the step for each line.
- Spot the common question traps and recall the version facts.