WorksheetsTerraform Quiz
Total questions: 49
Worksheet time: 35mins
Which of the following statements represents the most accurate statement about the Terraform language?
Terraform is a mutable, imperative, Infrastructure as Code provisioning language based on Hashicorp Configuration Language, or optionally YAML.
Terraform is an immutable, declarative, Infrastructure as Code provisioning language based on Hashicorp Configuration Language, or optionally JSON.
Terraform is a mutable, declarative, Infrastructure as Code configuration management language based on Hashicorp Configuration Language, or optionally JSON.
Terraform is an immutable, imperative, Infrastructure as Code configuration management language based on Hashicorp Configuration Language, or optionally JSON.
Why might a user opt to include the following snippet in their configuration file?
terraform {
required_version = ">= 1.9.2"
}
The user wants to specify the minimum version of Terraform that is required to run the configuration
The user wants to ensure that the application being deployed is a minimum version of 1.9.2
versions before Terraform 1.9.2 were not approved by HashiCorp to be used in production
this ensures that all Terraform providers are above a certain version to match the application being deployed
Which of the following are tasks that terraform apply can perform? (select three)
import existing infrastructure
provision new infrastructure
update existing infrastructure with new configurations
destroy infrastructure previously deployed with Terraform
Your organization has multiple engineers that have permission to manage Terraform as well as administrative access to the public cloud where these resources are provisioned. If an engineer makes a change outside of Terraform, what command can you run to detect drift and update the state file?
terraform get
terraform init
terraform state list
terraform apply -refresh-only
Infrastructure as Code (IaC) provides many benefits to help organizations deploy application infrastructure much faster than manually clicking in the console. Which is NOT an additional benefit to IaC?
allows infrastructure to be versioned
eliminates API communication to the target platform
code can easily be shared and reused
creates self-documenting infrastructure
Rather than having to scan and inspect every resource on every run, Terraform relies on what feature to help manage resources?
local variables
state
providers
environment variables
What feature does Terraform use to map configuration to resources in the real world?
state
parallelism
resource blocks
local variables
Given the code snippet below, how would you identify the arn to be used in the output block that was retrieved by the data block?
```
data "aws_s3_bucket" "data-bucket" {bucket = "my-data-lookup-bucket-btk"
}
...
output "s3_bucket_arn" {
value = ????
}
```
aws_s3_bucket.data-bucket
data.aws_s3_bucket.data-bucket.arn
data.aws_s3_bucket.arn
data.aws_s3_bucket.data-bucket
True or False? When referencing a module, you must specify the version of the module in the calling module block.
True
False
You've included two different modules from the official Terraform registry in a new configuration file. When you run a terraform init, where does Terraform OSS download and store the modules locally?
in the same root directory where the Terraform configuration files are stored
Terraform stores them in memory on the machine running Terraform
in the .terraform/modules folder in the working directory
in the /tmp directory of the machine executing Terraform
Given the definition below, what Terraform feature is being described?
"helps you share Terraform providers and Terraform modules across your organization. It includes support for versioning, a searchable list of available providers and modules, and a configuration designer to help you build new workspaces faster."
Terraform Workspaces
Private Registry
CDK for Terraform
HashiCorp Sentinel
Which statement below is true regarding using Sentinel in Terraform Enterprise?
Sentinel can extend the functionality of user permissions in Terraform Enterprise
Sentinel runs before each phase of the Terraform workflow, meaning a terraform init, terraform plan, and terraform apply
Sentinel policies can be developed using HCL, JSON, or YAML
Sentinel runs before a configuration is applied, therefore potentially reducing cost for public cloud resources
True or False? Infrastructure as code (IaC) tools allow you to manage infrastructure with configuration files rather than through a graphical user interface.
False
True
A child module created a new subnet for some new workloads. What Terraform block type would allow you to pass the subnet ID back to the parent module?
resource block
output block
data block
terraform block
You have a number of different variables in a parent module that calls multiple child modules. Can the child modules refer to any of the variables declared in the parent module?
Yes, child modules can refer to any variable in a parent module
Not the variable, but it can only refer to values that are passed to the child module
No, child modules can never refer to any variables or values declared in the parent module
Both you and a colleague are responsible for maintaining resources that host multiple applications using Terraform CLI. What feature of Terraform helps ensure only a single person can update or make changes to the resources Terraform is managing?
version control
local backend
state locking
provisioners
The command `terraform destroy` is actually just an alias to which command?
terraform apply -replace-all
terraform plan - destroy
terraform delete
terraform apply -destroy
Beyond storing state, what capability can an enhanced storage backend, such as the remote backend, provide your organization?
allow multiple people to execute operations on the state file at the same time
execute your Terraform on infrastructure either locally or in Terraform Cloud
replicate your state to a secondary location for backup
provides versioning capabilities on your state file in the event it becomes corrupted
What command can be used to display the resources that are being managed by Terraform?
terraform output
terraform version
terraform show
terraform state rm
You need to enable logging for Terraform and persist the logs to a specific file. What two environment variables can be set to enable logs and write them to a file? (select two)
TF_LOG_OUTPUT="<file_path>"
TF_LOG=TRACE
TF_LOG_PATH="<file_path>"
TF_ENABLE_LOG=true
Based on the code snippet below, where is the module that the code is referencing?
module "server_subnet_1" {
source = "./modules/web_server"
ami = data.aws_ami.ubuntu.id
key_name = aws_key_pair.generated.key_name
user = "ubuntu"
private_key = tls_private_key.generated.private_key_pem
subnet_id = aws_subnet.public_subnets["public_subnet_1"].id
security_groups = [aws_security_group.vpc-ping.id, aws_security_group.vpc-web.id]
}
stored in a private registry managed by the organization
in the modules subdirectory in the current working directory where Terraform is being executed
the same working directory where Terraform is being executed
stored in the Terraform public registry
What is NOT a benefit of using Infrastructure as Code?
the reduction of misconfigurations that could lead to security vulnerabilities and unplanned downtime
the ability to programmatically deploy infrastructure
reducing vulnerabilities in your publicly-facing applications
your infrastructure configurations can be version controlled and stored in a code repository alongside the application code
True or False? You can use a combination of Terraform Cloud's cost estimation feature and Sentinel policies to ensure your organization doesn't apply changes to your environment that would result in exceeding your monthly operating budget.
False
True
What is the primary language used by terraform to define resources and infrastructure?
YAML
JSON
HCL
XML
How would you define Terraform?
A configuration management tool
An orchestration tool
An infrastructure as code tool
A continuous integration tool
What does the terraform plan command do?
Applies the changes required to reach the desired state of the configuration
Shows the execution plan for the changes required to reach the desired state
Initializes the configuration
Deletes the resources defined in the configuration
You are provisioning a set of virtual machines using Terraform, each with its own set of tags(key-value pairs) for classification and organization. Which collection type in Terraform would be most suitable for representing the set of tags for each virtual machine?
list
set
object
map
You want to inspect the details of resources managed by Terraform within your project. Which Terraform command should you use?
terraform plan
terraform apply
terraform show
terraform state list
You want to list all resources tracked by Terraform within your project. Which Terraform command would provide you with this information?
terraform state list
terraform state show
terraform state pull
terraform state refresh
Terraform relies on state in order to create and manage resources. Which of the following is true regarding the state file? (select four)
remote state is required when more than one person wants to manage the infrastructure managed by Terraform
state should be modified by editing the file directly
by default, state is stored in a file named terraform.tfstate in the current working directory
it may contain sensitive data that you might not want others to view
the state file is formatted using JSON
As you are developing new Terraform code, you are finding that you are constantly repeating the same expression over and over throughout your code, and you are worried about the effort that will be needed if this expression needs to be changed. What feature of Terraform can you use to avoid repetition and make your code easier to maintain?
remote backend
data block
locals
terraform graph
You need to set the value for a Terraform input variable. Which of the following allows you to set the value using an environment variable?
export TF_VARIABLE_app=eCommerce01
export TF_VAR_user=dbadmin01
export VAR_database=prodsql01
export TF_db-pass=P@ssw0rd01!
What actions does a terraform init perform for you?
ensures that all Terraform files match the canonical formatting and style
compares the current configuration to the prior state and notes any differences
ensures any configuration file that ends with a .tf file extension is syntactically valid and internally consistent
downloads plugins and retrieves the source code for referenced modules
True or False? A provider block is required in every configuration file so Terraform can download the proper plugin.
True
False
True or False? In Terraform OSS, workspaces generally use the same code repository while workspaces in Terraform Enterprise/Cloud are often mapped to different code repositories.
True
False
True or False? Running a terraform apply will fail if you do not run a terraform plan first.
True
False
Which of the following code snippets will ensure you're using a specific version of the AWS provider?
terraform {
required_version = ">= 3.0"
}
provider "aws" {
region = "us-east-1"
required_provider ">= 3.0"
}
provider "aws" {
region = "us-east-2"
required_version ">= 3.0"
}
terraform {
required_providers {
aws = ">= 3.0"
}
}
You need to define a single input variable to support the IP address of a subnet, which is defined as a string, and the subnet mask, which is defined as a number. What type of variable variable should you use?
type = bool
type = string
type = object ()
type = map ()
You want to restrict your team members to specific modules that are approved by the organization's security team when using Terraform Cloud. What feature should you use?
Terraform Registry (public)
Terraform Workspaces
Terraform Cloud Private Registry
Terraform Cloud Organizations
Given the following code snippet, what is the managed resource name for this particular resource?
resource "aws_vpc" "prod-vpc" {
cidr_block = var.vpc_cidr
tags = {
Name = var.vpc_name
Environment = "demo_environment"
Terraform = "true"
}
enable_dns_hostnames = true
}
Which of the following Terraform versions would be permitted to run the Terraform configuration based on the following code snippet?
terraform {
required_version = "~> 1.0.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 3.0"
}
random = {
source = "hashicorp/random"
version = "3.1.0"
}
}
}
Terraform v1.1.0
Terraform v1.4.9
Terraform v1.0.5
Terraform v1.2.0
Which of the following is an advantage of using Infrastructure as Code?
elimination of security vulnerabilities in your application deployment workflow
standardize your deployment workflow
simplification of using a user interface to define your infrastructure
increase the time to market for application deployment
Your colleague provided you with a Terraform configuration file and you're having trouble reading it because parameters and blocks are not properly aligned. What command can you run to quickly update the file configuration file to make it easier to consume?
terraform fmt
terraform workspace
terraform state
terraform init
You have declared the variable as shown below. How should you reference this variable throughout your configuration?
variable "aws_region" {
type = string
description = "region used to deploy workloads"
default = "us-east-1"
validation {
condition = can(regex("^us-", var.aws_region))
error_message = "The aws_region value must be a valid region in the USA, starting with \"us-\"."
}
}
By default, where does Terraform CLI store its state?
in the terraform.tfstate file on the local backend
in the default workspace in Terraform Cloud
in a temp directory on the local machine executing the Terraform configurations
in the .terraform directory within the current working directory
After hours of development, you've created a new Terraform configuration from scratch and now you want to test it. Before you can provision the resources, what is the first command that you should run?
terraform validate
terraform init
terraform import
terraform apply
You are having trouble with executing Terraform and want to enable the most verbose logs. What log level should you set for the TF_LOG environment variable?
INFO
DEBUG
TRACE
ERROR
After deploying a new virtual machine using Terraform, you find that the local script didn't run properly. However, Terraform reports the virtual machine was successfully created. How can you force Terraform to replace the virtual machine without impacting the rest of the managed infrastructure?
run a terraform destroy and then run terraform import to pull in the other resources under Terraform management
use terraform apply -replace to tag the resource for replacement
execute a terraform debug command to see why the script failed to run
update the virtual machine resource and run a terraform init
Where is the most secure place to store credentials when using a remote backend?
environment variables
defined outside of Terraform
in the backend configuration block where the remote state location is defined
using an input variable defined in your variables.tf file
