Bird
Raised Fist0
Terraformcloud~20 mins

Outputs for module communication in Terraform - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Terraform Module Output Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ service_behavior
intermediate
2:00remaining
What is the output value of the root module after applying this Terraform configuration?
Given a root module that calls a child module which outputs a value, what will be the value of module.child.output_value in the root module?
Terraform
module "child" {
  source = "./child_module"
  input_var = "hello"
}

output "child_output" {
  value = module.child.output_value
}

# child_module/main.tf
variable "input_var" {}

output "output_value" {
  value = "${var.input_var}-world"
}
A"hello-world"
B"hello"
C"world"
D"${var.input_var}-world"
Attempts:
2 left
💡 Hint
Remember that module outputs can be accessed in the root module using module...
❓ Configuration
intermediate
2:00remaining
Which option correctly defines an output in a Terraform module to expose a resource attribute?
You want to expose the ID of an AWS EC2 instance created inside a module. Which output block correctly achieves this?
Terraform
resource "aws_instance" "example" {
  ami           = "ami-123456"
  instance_type = "t2.micro"
}

# Define output here
A
output "instance_id" {
  value = aws_instance.example.id
}
B
output "instance_id" {
  value = aws_instance.example[0].id
}
C
output "instance_id" {
  value = aws_instance.example.instance_id
}
D
output "instance_id" {
  value = aws_instance.example
}
Attempts:
2 left
💡 Hint
Resource attributes are accessed by their exact attribute names, not by index or the whole resource.
❓ Architecture
advanced
2:00remaining
How can you pass a computed value from one module to another in Terraform?
You have two modules: Module A creates a VPC and outputs its ID. Module B needs the VPC ID to create subnets. How should you connect these modules in the root module?
Terraform
module "vpc" {
  source = "./vpc_module"
}

module "subnet" {
  source = "./subnet_module"
  vpc_id = ???
}
ASet vpc_id = output.vpc_id
BSet vpc_id = var.vpc_id
CSet vpc_id = aws_vpc.main.id
DSet vpc_id = module.vpc.vpc_id_output
Attempts:
2 left
💡 Hint
Modules expose outputs that can be referenced by other modules in the root module.
❓ security
advanced
2:00remaining
What is a security risk when exposing sensitive data via Terraform module outputs?
You have a module output that exposes a database password. What is the main risk and how can you mitigate it?
AThe password is stored in plain text in logs; mitigate by disabling logging.
BThe password is encrypted in state files; no mitigation needed.
CThe password appears in Terraform state files; mitigate by marking the output as sensitive.
DThe password is only visible to admins; mitigate by restricting IAM roles.
Attempts:
2 left
💡 Hint
Terraform state files store outputs and can be read if not protected.
✅ Best Practice
expert
2:00remaining
What is the best practice for managing outputs when a module is used multiple times with different configurations?
You use the same module twice to create two different environments (dev and prod). How should you handle outputs to avoid conflicts and confusion?
AAvoid using outputs; instead, hardcode values in the root module.
BUse unique module instance names and reference outputs with those names in the root module.
CDefine outputs only in one module instance and share them via variables.
DUse the same module name and rely on Terraform to merge outputs automatically.
Attempts:
2 left
💡 Hint
Terraform distinguishes module instances by their names in the root module.

Practice

(1/5)
1. What is the main purpose of output blocks in Terraform modules?
easy
A. To share values from one module to another or to the user
B. To create new resources in the cloud
C. To define variables for user input
D. To delete resources after deployment

Solution

  1. Step 1: Understand the role of output blocks

    Output blocks are used to expose values from a module so other modules or users can access them.
  2. Step 2: Differentiate outputs from other blocks

    Unlike resource or variable blocks, outputs do not create or accept input but share information.
  3. Final Answer:

    To share values from one module to another or to the user -> Option A
  4. Quick Check:

    Outputs share values = D [OK]
Hint: Outputs share info between modules or users [OK]
Common Mistakes:
  • Confusing outputs with resource creation
  • Thinking outputs accept user input
  • Assuming outputs delete resources
2. Which of the following is the correct syntax to define an output named instance_ip with value aws_instance.web.private_ip?
easy
A. output instance_ip = aws_instance.web.private_ip
B. output "instance_ip" { value = aws_instance.web.private_ip }
C. output "instance_ip" = aws_instance.web.private_ip
D. output { instance_ip = aws_instance.web.private_ip }

Solution

  1. Step 1: Recall Terraform output block syntax

    Outputs use the syntax: output "name" { value = expression }
  2. Step 2: Match syntax with options

    output "instance_ip" { value = aws_instance.web.private_ip } matches the correct syntax with quotes and value assignment inside braces.
  3. Final Answer:

    output "instance_ip" { value = aws_instance.web.private_ip } -> Option B
  4. Quick Check:

    Correct output block syntax = B [OK]
Hint: Output blocks need quotes and value inside braces [OK]
Common Mistakes:
  • Missing quotes around output name
  • Using equals sign outside braces
  • Placing value outside output block
3. Given this module output block:
output "db_endpoint" {
  value = aws_db_instance.main.endpoint
}

And this root module code:
module "database" {
  source = "./modules/db"
}

output "database_url" {
  value = module.database.db_endpoint
}

What will terraform output database_url show after deployment?
medium
A. The endpoint address of the AWS database instance
B. The string 'module.database.db_endpoint'
C. An error because outputs cannot be nested
D. The IP address of the AWS database instance

Solution

  1. Step 1: Understand module output forwarding

    The module outputs 'db_endpoint' which is accessed in root as 'module.database.db_endpoint'.
  2. Step 2: Check root output value

    The root output 'database_url' uses the module output value, so it will show the actual endpoint string.
  3. Final Answer:

    The endpoint address of the AWS database instance -> Option A
  4. Quick Check:

    Module output forwarded = A [OK]
Hint: Root output uses module output value directly [OK]
Common Mistakes:
  • Thinking output shows variable name as string
  • Assuming outputs cannot be nested
  • Confusing endpoint with IP address
4. You wrote this output block inside a module:
output "server_ip" {
  value = aws_instance.app.private_ip
}

But when you run terraform apply, you get an error: Reference to undeclared resource. What is the likely cause?
medium
A. The output block is missing a description
B. Output blocks cannot reference resource attributes
C. Output names cannot contain underscores
D. The resource aws_instance.app is not defined in the module

Solution

  1. Step 1: Analyze the error message

    'Reference to undeclared resource' means Terraform cannot find 'aws_instance.app' in the module.
  2. Step 2: Check output references

    Outputs must reference existing resources; if resource is missing, error occurs.
  3. Final Answer:

    The resource aws_instance.app is not defined in the module -> Option D
  4. Quick Check:

    Missing resource causes reference error = A [OK]
Hint: Check resource exists before referencing in output [OK]
Common Mistakes:
  • Assuming outputs can't reference resources
  • Thinking underscores are invalid in output names
  • Believing description is mandatory
5. You have a module that creates multiple AWS instances and outputs a list of their private IPs:
output "instance_ips" {
  value = [for i in aws_instance.app : i.private_ip]
}

How can you use this output in the root module to create a security group rule allowing SSH from all these IPs?
hard
A. Use count = length(module.app.instance_ips) but no for_each
B. Directly assign cidr_blocks = module.app.instance_ips without conversion
C. Use for_each = toset(module.app.instance_ips) in the security group rule resource
D. Outputs cannot be used to create security group rules

Solution

  1. Step 1: Understand output is a list of IPs

    The output returns a list of private IP addresses from multiple instances.
  2. Step 2: Use for_each with a set for unique IPs

    Security group rules can be created per IP using for_each with toset() to avoid duplicates.
  3. Final Answer:

    Use for_each = toset(module.app.instance_ips) in the security group rule resource -> Option C
  4. Quick Check:

    Use for_each with toset for multiple IP rules = C [OK]
Hint: Use for_each with toset() for list outputs in resources [OK]
Common Mistakes:
  • Assigning list directly to cidr_blocks without for_each
  • Using count without mapping IPs
  • Thinking outputs can't be used in resource blocks