TERRAFORM ASSOCIATE EXAM
2021 - LIST 1 2025 QUESTIONS AND
ANSWERS
True or False? When using the Terraform provider for Vault, the tight integration
between these HashiCorp tools provides the ability to mask secrets in the `terraform
plan` and state files.
a) True
b) False - ....ANSWER ...-b) False
Currently, Terraform has no mechanism to redact or protect secrets that are returned via
data sources, so secrets read via this provider will be persisted into the Terraform state,
into any plan files, and in some cases in the console output produced while planning and
applying. These artifacts must, therefore, all be protected accordingly.
https://learn.hashicorp.com/tutorials/terraform/secrets-vault
During a terraform apply, a resource is successfully created but eventually fails during
provisioning. What happens to the resource?
....FOR STUDY PURPOSES...©️2025 ALL RIGHTS RESERVED... 1
, a) it is automatically deleted
b) the resource is marked as tainted
c) Terraform attempt to provision the resource up to 3 times before existing with an error
d) the terraform plan is rolled back and all provisioned resources are removed -
....ANSWER ...-b) the resource is marked as tainted
If a resource successfully creates but fails during provisioning, Terraform will error and
mark the resource as "tainted". A resource that is tainted has been physically created,
but can't be considered safe to use since provisioning failed.
Terraform also does not automatically roll back and destroy the resource during the
apply when the failure happens, because that would go against the execution plan: the
execution plan would've said a resource will be created, but does not say it will ever be
deleted.
https://www.terraform.io/docs/provisioners/index.html#creation-time-provisioners
Which of the following commands will launch the Interactive console for Terraform
interpolations?
a) terraform cli
b) terraform cmdline
c) terraform console
d) terraform - ....ANSWER ...-c) terraform console
....FOR STUDY PURPOSES...©️2025 ALL RIGHTS RESERVED... 2
2021 - LIST 1 2025 QUESTIONS AND
ANSWERS
True or False? When using the Terraform provider for Vault, the tight integration
between these HashiCorp tools provides the ability to mask secrets in the `terraform
plan` and state files.
a) True
b) False - ....ANSWER ...-b) False
Currently, Terraform has no mechanism to redact or protect secrets that are returned via
data sources, so secrets read via this provider will be persisted into the Terraform state,
into any plan files, and in some cases in the console output produced while planning and
applying. These artifacts must, therefore, all be protected accordingly.
https://learn.hashicorp.com/tutorials/terraform/secrets-vault
During a terraform apply, a resource is successfully created but eventually fails during
provisioning. What happens to the resource?
....FOR STUDY PURPOSES...©️2025 ALL RIGHTS RESERVED... 1
, a) it is automatically deleted
b) the resource is marked as tainted
c) Terraform attempt to provision the resource up to 3 times before existing with an error
d) the terraform plan is rolled back and all provisioned resources are removed -
....ANSWER ...-b) the resource is marked as tainted
If a resource successfully creates but fails during provisioning, Terraform will error and
mark the resource as "tainted". A resource that is tainted has been physically created,
but can't be considered safe to use since provisioning failed.
Terraform also does not automatically roll back and destroy the resource during the
apply when the failure happens, because that would go against the execution plan: the
execution plan would've said a resource will be created, but does not say it will ever be
deleted.
https://www.terraform.io/docs/provisioners/index.html#creation-time-provisioners
Which of the following commands will launch the Interactive console for Terraform
interpolations?
a) terraform cli
b) terraform cmdline
c) terraform console
d) terraform - ....ANSWER ...-c) terraform console
....FOR STUDY PURPOSES...©️2025 ALL RIGHTS RESERVED... 2