Bird
Raised Fist0
Terraformcloud~20 mins

AWS provider setup in Terraform - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
AWS Provider Setup Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ Configuration
intermediate
2:00remaining
Identify the correct AWS provider configuration for a specific region
Which AWS provider configuration will correctly set the region to us-west-2 and use the default profile from your AWS credentials file?
A
provider "aws" {
  region = "us-west-2"
  profile = "default-profile"
}
B
}
"tluafed" = eliforp  
"2-tsew-su" = noiger  
{ "swa" redivorp
C
provider "aws" {
  region = "us-west-2"
  profile = "default"
}
D
provider "aws" {
  region = "us-west-2"
  access_key = "default"
}
Attempts:
2 left
💡 Hint
Remember that region and profile values must be strings enclosed in quotes.
❓ service_behavior
intermediate
2:00remaining
Determine the effect of missing AWS provider region in Terraform
What happens if you configure the AWS provider in Terraform without specifying a region and no environment variables or default region are set?
ATerraform will deploy resources to a random AWS region.
BTerraform will default to us-east-1 region automatically.
CTerraform will use the region from the AWS CLI configuration file regardless of environment variables.
DTerraform will throw an error during plan/apply stating that region is not configured.
Attempts:
2 left
💡 Hint
Think about what Terraform requires to know where to deploy resources.
❓ security
advanced
2:00remaining
Choose the safest way to provide AWS credentials to Terraform
Which option is the most secure and recommended way to provide AWS credentials to Terraform when running on a developer's local machine?
AUse AWS CLI configured profiles and specify the profile in the provider block.
BUse environment variables AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY set in the shell.
CHardcode AWS access key and secret key directly in the Terraform provider block.
DStore credentials in a shared Terraform variables file checked into version control.
Attempts:
2 left
💡 Hint
Think about avoiding exposing secrets in code or version control.
❓ Architecture
advanced
2:00remaining
Select the correct Terraform AWS provider configuration for multi-account setup
You manage multiple AWS accounts and want to deploy resources to two accounts using Terraform. Which provider configuration allows you to switch between accounts using profiles named 'dev' and 'prod'?
A
provider "aws" {
  profile = "dev"
  region = "us-east-1"
}

provider "aws" {
  profile = "prod"
  region = "us-east-1"
}
B
provider "aws" {
  alias = "dev"
  profile = "dev"
  region = "us-east-1"
}

provider "aws" {
  alias = "prod"
  profile = "prod"
  region = "us-east-1"
}
C
provider "aws" {
  profile = "dev,prod"
  region = "us-east-1"
}
D
provider "aws" {
  alias = "dev-prod"
  profile = "dev-prod"
  region = "us-east-1"
}
Attempts:
2 left
💡 Hint
Think about how Terraform handles multiple provider configurations with aliases.
🧠 Conceptual
expert
2:00remaining
Understand the impact of provider version constraints in Terraform AWS provider
Given the following Terraform provider block, what is the effect of the version constraint on provider installation and upgrades? provider "aws" { version = ">= 4.0, < 5.0" region = "us-east-1" }
ATerraform will install any AWS provider version from 4.0 up to but not including 5.0, allowing minor and patch upgrades but preventing major upgrades.
BTerraform will only install version 4.0 exactly, no other versions.
CTerraform will install the latest AWS provider version regardless of version number.
DTerraform will install any version including 5.0 and above.
Attempts:
2 left
💡 Hint
Think about semantic versioning and how version constraints work in Terraform.

Practice

(1/5)
1. What is the minimum required configuration to set up the AWS provider in Terraform?
easy
A. Specify the AWS region in the provider block
B. Provide the AWS access key and secret key directly in the provider block
C. Create an IAM user with admin permissions
D. Install the AWS CLI before running Terraform

Solution

  1. Step 1: Understand AWS provider requirements

    The AWS provider requires at least the region to know where to create resources.
  2. Step 2: Check minimal configuration

    Providing the region in the provider block is the minimal valid setup; credentials can be handled separately.
  3. Final Answer:

    Specify the AWS region in the provider block -> Option A
  4. Quick Check:

    AWS provider needs region at minimum [OK]
Hint: Always specify region in provider block for AWS setup [OK]
Common Mistakes:
  • Putting credentials directly in provider (not recommended)
  • Skipping region configuration
  • Assuming AWS CLI must be installed for Terraform
2. Which of the following is the correct syntax to configure the AWS provider with region us-east-1 in Terraform?
easy
A. provider "aws" region = "us-east-1"
B. provider aws { region = us-east-1 }
C. provider "aws" { region = "us-east-1" }
D. provider "aws" { region: "us-east-1" }

Solution

  1. Step 1: Review Terraform provider block syntax

    Terraform uses HCL syntax with provider name in quotes and block braces.
  2. Step 2: Validate correct key-value assignment

    Key-value pairs use equals sign and values in quotes for strings.
  3. Final Answer:

    provider "aws" { region = "us-east-1" } -> Option C
  4. Quick Check:

    Correct HCL syntax uses equals and braces [OK]
Hint: Use quotes and equals sign inside braces for provider config [OK]
Common Mistakes:
  • Missing quotes around provider name
  • Using colon instead of equals sign
  • Omitting braces around provider block
3. Given this Terraform provider configuration:
provider "aws" {
  region  = "us-west-2"
  profile = "myprofile"
}

What will Terraform use to authenticate AWS API calls?
medium
A. Credentials from the AWS CLI profile named 'myprofile'
B. Default environment variables AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY
C. Anonymous access without credentials
D. Credentials hardcoded in the provider block

Solution

  1. Step 1: Understand the 'profile' argument in AWS provider

    The 'profile' tells Terraform to use credentials stored in the named AWS CLI profile.
  2. Step 2: Confirm authentication source

    Terraform reads credentials from the AWS config files under the specified profile, not environment variables or hardcoded keys.
  3. Final Answer:

    Credentials from the AWS CLI profile named 'myprofile' -> Option A
  4. Quick Check:

    Profile argument uses AWS CLI stored credentials [OK]
Hint: Profile uses AWS CLI stored credentials, not env vars [OK]
Common Mistakes:
  • Assuming environment variables override profile
  • Thinking credentials are anonymous
  • Hardcoding keys inside provider block
4. This Terraform AWS provider configuration causes an error:
provider "aws" {
  region = us-east-1
}

What is the cause of the error?
medium
A. The provider block name is missing quotes
B. The provider block is missing a closing brace
C. The equals sign is missing
D. The region value is missing quotes

Solution

  1. Step 1: Check the region value syntax

    In HCL, string values must be enclosed in double quotes.
  2. Step 2: Identify the error

    The region value us-east-1 is unquoted, causing a syntax error.
  3. Final Answer:

    The region value is missing quotes -> Option D
  4. Quick Check:

    String values require quotes in Terraform [OK]
Hint: Always quote string values like region names [OK]
Common Mistakes:
  • Forgetting quotes around strings
  • Misplacing braces or equals sign
  • Assuming unquoted strings are valid
5. You want to configure the AWS provider in Terraform to use the region 'eu-central-1' and a profile named 'devuser'. Which configuration is correct and follows best security practices?
hard
A. provider "aws" { region = "eu-central-1" profile = "devuser" access_key = "AKIA..." secret_key = "secret" }
B. provider "aws" { region = "eu-central-1" profile = "devuser" }
C. provider "aws" { region = "eu-central-1" access_key = "AKIA..." secret_key = "secret" }
D. provider "aws" { region = "eu-central-1" }

Solution

  1. Step 1: Understand best security practices for AWS credentials

    Hardcoding access keys in Terraform files is insecure and discouraged.
  2. Step 2: Use AWS profiles for credential management

    Using the 'profile' argument lets Terraform use credentials stored securely in AWS CLI config files.
  3. Step 3: Confirm correct configuration

    provider "aws" { region = "eu-central-1" profile = "devuser" } specifies region and profile without hardcoding keys, following best practices.
  4. Final Answer:

    provider "aws" { region = "eu-central-1" profile = "devuser" } -> Option B
  5. Quick Check:

    Use profiles, avoid hardcoding keys [OK]
Hint: Never hardcode keys; use profiles or env variables [OK]
Common Mistakes:
  • Hardcoding AWS keys in Terraform files
  • Omitting region or profile causing errors
  • Using incomplete provider blocks