The -refresh-only parameter will update your state file when used with terraform plan.
Which of the following command would be use to access all of the attributes and details of a resource managed by Terraform?
Your configuration contains a module block that references a module from the Terraform Registry and sets the version argument to 1.0. You just published a new version of the module and updated your configuration to point to version 1.1.
Which command must be run to install the new version?
Which command must you first run before performing further Terraform operations in a working directory?
terraform validate confirms that your infrastructure matches the Terraform state file.
You want to use API tokens and other secrets within your team ' s Terraform workspaces. Where does HashiCorp recommend you store these sensitive values? (Pick the 3 correct responses)
Exhibit:
variable " sizes " {
type = list(string)
description = " Valid server sizes "
default = [ " small " , " medium " , " large " ]
}
A variable declaration is shown in the exhibit. Which is the correct way to get the value of medium from this variable?
Which option cannot be used to keep secrets out of Terraform configuration files?
terraform apply will fail if you have not run terraform plan first to update the plan output.
Your team uses HCP Terraform to manage infrastructure. You need to make a change to an infrastructure stack running in a public cloud. Which pattern follows Infrastructure as Code best practices for making the change?
You modified your Terraform configuration to fix a typo in the resource ID by renaming it from photoes to photos. What configuration will you add to update the resource ID in state without destroying the existing resource?
Original configuration:
resource " aws_s3_bucket " " photoes " {
bucket_prefix = " images "
}
Updated configuration:
resource " aws_s3_bucket " " photos " {
bucket_prefix = " images "
}
You have successfully deployed an application that includes a resource with a public IP address. Due to a configuration oversight, no outputs were defined.
Using the Terraform CLI, how can you find the IP address of the deployed resource with minimum disruption to the application?
You are working on some new application features and you want to spin up a copy of your production deployment to perform some quick tests. In order to avoid having to configure a new state backend, what open source Terraform feature would allow you create multiple states but still be associated with your current code?
You have two separate Terraform configurations:
Configuration A provisions a virtual network and subnets.
Configuration B provisions compute resources that must be attached to those subnets.
In Configuration B, you have a terraform_remote_state data source configured to read Configuration A’s local state file. When running terraform plan for Configuration B in a CI/CD pipeline, Terraform fails because the state file cannot be found and is not accessible to the pipeline runtime.
What is the best solution to reliably access the state data from Configuration A in this scenario?
Your team is using version 3.1.4 of a module from the public Terraform Registry, and they are worried about possible breaking changes in future versions of the module. Which version argument should you add to the module block to prevent newer versions from being used?
You just scaled your VM infrastructure and realize you set the count variable to the wrong value. You correct the value and save your change. What must you do next to make your infrastructure match your configuration?
What type of information can be found on the Terraform Registry when using published modules?
terraform apply is failing with the following error. What next step should you take to determine the root cause of the problem?
Error:
yaml
CopyEdit
Error loading state: AccessDenied: Access Denied
status code: 403, request id: 288766CE5CCA24A0, host id: web.example.com
What kind of configuration block will manage an infrastructure object with settings specified within the block?
Your Terraform configuration declares a variable. You want to enforce that its value meets your specific requirements, and you want to block the Terraform operation if it does not. What should you add to your configuration?
Part of a configuration is shown in the exhibit below.
You want to pass the id of the vsphere_datacenter data source to the datacenter_id argument of the vsphere_folder resource.
Which reference would you use?
Your Terraform configuration manages a resource that requires maximum uptime. You need to update the resource, and when you run terraform plan, Terraform indicates that the update requires the resource to be destroyed and recreated.
Which lifecycle rule can you add to the resource to reduce downtime while still applying the update?
As a member of an operations team that uses infrastructure as code (lac) practices, you are tasked with making a change to an infrastructure stack running in a public cloud. Which pattern would follow laC best practices for making a change?
You can reference a resource created with for_each using a Splat ( *) expression.
If one of your modules uses a local value, you can expose that value to callers of the module by defining a Terraform output in the module’s configuration.
You want to know from which paths Terraform is loading providers referenced in your Terraform configuration (* files). You need to enable additional logging messages to find this out. Which of the following would achieve this?
Which of these ate secure options for storing secrets for connecting to a Terraform remote backend? Choose two correct answers.
Which of the following does HCP Terraform perform during a health assessment for a workspace?
You should run terraform fnt to rewrite all Terraform configurations within the current working directory to conform to Terraform-style conventions.
How does the Terraform cloud integration differ from other state backends such as S3, Consul,etc?
You must use different Terraform commands depending on the cloud provider you use.
A developer accidentally launched a VM (virtual machine) outside of the Terraform workflow and ended up with two servers with the same name. They don ' t know which VM Terraform manages but do have a list of all active VM IDs.
Which of the following methods could you use to discover which instance Terraform manages?
You want to use API tokens and other secrets within your team ' s Terraform workspaces. Where does HashiCorp recommend you store these sensitive values? (Pick 3)
Which are benefits of migrating from a local state backend to a remote backend? (Pick the 2 correct responses below.)
What Terraform command always causes a state file to be updated with changes that might have been made outside of Terraform?
Which is a benefit of using infrastructure as code (IaC) tools compared to native platform APIs?
You are responsible for a set of infrastructure that is managed by two workspaces: example-network and example-compute. The example-compute workspace uses data from output values configured in the example-network workspace and must be deployed afterward. Currently, this is a manual process:
An operator deploys changes to the example-network workspace.
They manually copy the output values from the example-network workspace to input variables configured for the example-compute workspace.
They deploy the example-compute workspace.
Which HCP Terraform features can you use to automate this process?
Pick the two correct responses below.
Which of the following can you do with terraform plan? (Pick 2 correct responses)
Terraform configuration (including any module references) can contain only one Terraform provider type.
You need to determine from which paths Terraform is loading the providers referenced in your *.tf files.
How can you enable additional logging to see this information?
Which are forbidden actions when the terraform state file is locked? Choose three correct answers.
What information does the public Terraform Module Registry automatically expose about published modules?
When you initialize Terraform, where does it cache modules from the public Terraform Registry?
As a developer, you want to ensure your plugins are up to date with the latest versions. Which Terraform command should you use?
Which of the following is availableonlyinHCP Terraform workspacesandnot in Terraform CLI?
Which type of block fetches or computes information for use elsewhere in a Terraform configuration?
You ' ve used Terraform to deploy a virtual machine and a database. You want to replace this virtual machine instance with an identical one without affecting the database. What is the best way to achieve this using Terraform?
You have declared a variable called var.list which is a list of objects that all have an attribute id . Which options will produce a list of the IDs? Choose two correct answers.
How do you specify a module’s version when publishing it to the public terraform Module Registry?
You want to use API tokens and other secrets within your team ' s Terraform workspaces. Where does HashiCorp recommend you store these sensitive values?
(Pick 3 correct responses)
You want to define multiple data disks as nested blocks inside the resource block for a virtual machine. What Terraform feature would help you define the blocks using the values in a variable?
A developer on your team is going to leaf down an existing deployment managed by Terraform and deploy a new one. However, there is a server resource named aws instant.ubuntu[l] they would like to keep. What command should they use to tell Terraform to stop managing that specific resource?
The HCP Terraform private registry keeps the module configurations confidential within your organization.
Which of the following isnotan advantage of using Infrastructure as Code (IaC) operations?
A resource block is shown in the Exhibit section of this page. How would you reference the attribute name of this resource in HCL?
A resource block is shown in the Exhibit space of this page. What is the Terraform resource name of that resource block?
You have used Terraform lo create an ephemeral development environment in the (loud and are now ready to destroy all the Infrastructure described by your Terraform configuration To be safe, you would like to first see all the infrastructure that Terraform will delete.
Which command should you use to show all of the resources that mil be deleted? Choose two correct answers.
A resource block is shown in the Exhibit space of this page. What is the Terraform resource name of the resource block?
If a module declares a variable without a default value, you must pass the value of the variable within the module block when you call the module in your configuration.
Infrastructure as Code (laC) can be stored in a version control system along with application code.
What type of block is used to construct a collection of nested configuration blocks?
Which of the following commands would you use to access all of the attributes and details of a resource managed by Terraform?
When you include a module block in your configuration that references a module from the Terraform Registry, the " version " attribute is required.
A Terraform output that sets the " sensitive " argument to true will not store that value in the state file.
Which of the following does terraform apply change after you approve the execution plan? (Choose two.)
Which of the following is true about terraform apply?(Pick 2 correct responses)
You used Terraform to create an ephemeral development environment in the cloud and are now ready to destroy all the infrastructure described by your Terraform configuration. To be safe, you would like to first see all the infrastructure that Terraform will delete.
Which command should you use to show all the resources that will be deleted? (Pick the 2 correct responses)
When a check block’s assertion fails, Terraform blocks the current operation from executing.
A Terraform backend determines how Terraform loads state and stores updates when you execute which command?
Outside of the required_providers block, Terraform configurations always refer to providers by their local names.