Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What does the -auto-approve flag do in Terraform?
The -auto-approve flag skips the manual approval step and applies changes immediately without asking for confirmation.
Click to reveal answer
beginner
Why can using -auto-approve be dangerous?
Because it applies changes without review, it can cause unintended infrastructure changes or outages if mistakes are present in the configuration.
Click to reveal answer
beginner
What is a safer alternative to using -auto-approve?
Review the plan output manually and run terraform apply without -auto-approve to confirm changes before applying.
Click to reveal answer
intermediate
In what situations might -auto-approve be acceptable?
In automated pipelines where changes are small, tested, and reviewed beforehand, and quick deployment is needed without manual steps.
Click to reveal answer
intermediate
How can teams reduce risks when using -auto-approve in Terraform?
By implementing code reviews, automated tests, and approval gates before the apply step, even if -auto-approve is used in automation.
Click to reveal answer
What happens when you run terraform apply -auto-approve?
ATerraform only shows the plan but does not apply changes.
BTerraform applies changes immediately without asking for confirmation.
CTerraform asks twice for confirmation before applying.
DTerraform cancels the apply process.
✗ Incorrect
The -auto-approve flag skips the confirmation prompt and applies changes right away.
Why is it risky to use -auto-approve in production environments?
AIt requires manual approval every time.
BIt slows down the deployment process.
CIt disables Terraform logging.
DIt can cause unexpected infrastructure changes without review.
✗ Incorrect
Using -auto-approve skips manual review, increasing the risk of mistakes affecting production.
Which practice helps reduce risks when using -auto-approve?
ARunning automated tests and code reviews before apply.
BSkipping the plan step entirely.
CApplying changes without any prior checks.
DUsing <code>-auto-approve</code> only on local machines.
✗ Incorrect
Automated tests and code reviews catch errors before changes are applied automatically.
When might using -auto-approve be acceptable?
AIn automated pipelines with tested and reviewed changes.
BWhen making large untested changes in production.
CWhen you want to avoid writing Terraform plans.
DWhen you want to disable Terraform state locking.
✗ Incorrect
Automated pipelines with prior testing and review can safely use -auto-approve for faster deployment.
What does Terraform normally do before applying changes without -auto-approve?
ASkips the plan step.
BApplies changes immediately.
CShows a plan and asks for manual confirmation.
DDeletes the state file.
✗ Incorrect
Terraform shows the planned changes and waits for user confirmation before applying.
Explain what the -auto-approve flag does in Terraform and why it can be dangerous.
Think about what happens when you don't get a chance to review changes.
You got /4 concepts.
Describe best practices to safely use -auto-approve in automated Terraform workflows.
Consider how teams can prevent mistakes before applying changes automatically.
You got /4 concepts.
Practice
(1/5)
1. What does the -auto-approve flag do when running terraform apply?
easy
A. It cancels the apply process automatically.
B. It shows a detailed plan before applying changes.
C. It skips the confirmation prompt and applies changes immediately.
D. It only validates the configuration without applying changes.
Solution
Step 1: Understand the purpose of the -auto-approve flag
This flag is designed to skip the manual confirmation step during terraform apply.
Step 2: Identify the effect on the apply process
By skipping confirmation, Terraform applies changes immediately without waiting for user input.
Final Answer:
It skips the confirmation prompt and applies changes immediately. -> Option C
Quick Check:
-auto-approve skips confirmation [OK]
Hint: Remember: auto-approve means no manual confirmation [OK]
Common Mistakes:
Thinking it shows the plan before applying
Assuming it cancels the apply
Confusing it with validation only
2. Which is the correct syntax to apply Terraform changes without confirmation?
easy
A. terraform apply --force-apply
B. terraform apply --skip-confirm
C. terraform apply --no-approve
D. terraform apply -auto-approve
Solution
Step 1: Recall the exact flag name for skipping confirmation
The correct flag is -auto-approve, which tells Terraform to apply changes without asking.
Step 2: Check the options for correct syntax
Only terraform apply -auto-approve uses the correct flag -auto-approve with proper syntax.
Final Answer:
terraform apply -auto-approve -> Option D
Quick Check:
Correct flag syntax is -auto-approve [OK]
Hint: Flag always spelled exactly as -auto-approve [OK]
Common Mistakes:
Using --skip-confirm which does not exist
Confusing with --no-approve or --force-apply
Adding extra dashes or misspelling the flag
3. Given this command: terraform apply -auto-approve, what is the main risk involved?
medium
A. Changes will be applied without reviewing the plan first.
B. Terraform will only validate the configuration.
C. Terraform will prompt twice for confirmation.
D. Terraform will not apply any changes.
Solution
Step 1: Understand what -auto-approve does
This flag skips the manual confirmation step, so Terraform applies changes immediately.
Step 2: Identify the risk of skipping confirmation
Without reviewing the plan, unintended or harmful changes might be applied automatically.
Final Answer:
Changes will be applied without reviewing the plan first. -> Option A
Quick Check:
Auto-approve skips review, causing risk [OK]
Hint: Auto-approve skips review, so risk is blind apply [OK]
Common Mistakes:
Thinking no changes will apply
Assuming double confirmation happens
Believing it only validates without applying
4. You ran terraform apply -auto-approve and accidentally deleted a critical resource. What is the best way to prevent this in the future?
medium
A. Always run terraform apply without any flags.
B. Use -auto-approve only after reviewing the plan with terraform plan.
C. Disable Terraform state locking.
D. Run terraform apply -auto-approve twice to confirm.
Solution
Step 1: Identify the cause of accidental deletion
Using -auto-approve without reviewing the plan can cause unintended changes.
Step 2: Find the best practice to avoid mistakes
Always review the plan output with terraform plan before applying changes automatically.
Final Answer:
Use -auto-approve only after reviewing the plan with terraform plan. -> Option B
Quick Check:
Review plan before auto-approve prevents mistakes [OK]
Hint: Review plan first, then auto-approve safely [OK]
Common Mistakes:
Thinking running apply without flags always prevents errors
Disabling state locking which is unrelated
Running auto-approve twice does not add confirmation
5. In an automated CI/CD pipeline, you want to safely use terraform apply -auto-approve. Which practice reduces the danger of unintended changes?
hard
A. Run terraform plan and save the plan output, then apply only if the plan matches expectations.
B. Use -auto-approve with terraform destroy to clean up resources automatically.
C. Skip the plan step and apply directly to save time.
D. Run terraform apply manually after the pipeline finishes.
Solution
Step 1: Understand the risk of auto-approve in automation
Auto-approve skips manual review, so unintended changes can happen if the plan is not checked.
Step 2: Identify a safe automation practice
Running terraform plan first and saving its output allows verification before applying changes automatically.
Step 3: Confirm the best option
Run terraform plan and save the plan output, then apply only if the plan matches expectations. describes this safe practice, reducing risk in CI/CD pipelines.
Final Answer:
Run terraform plan and save the plan output, then apply only if the plan matches expectations. -> Option A
Quick Check:
Plan then apply ensures safe automation [OK]
Hint: Always plan and verify before auto-approve in pipelines [OK]