Bird
Raised Fist0
Terraformcloud~20 mins

Plan output reading in Terraform - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Terraform Plan Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
❓ service_behavior
intermediate
2:00remaining
Interpreting Terraform plan output for resource changes

Given the following Terraform plan output snippet, how many resources will be created?

  # aws_instance.web will be created
  + resource "aws_instance" "web" {
      + ami           = "ami-123456"
      + instance_type = "t2.micro"
    }

  # aws_s3_bucket.data_bucket will be updated in-place
  ~ resource "aws_s3_bucket" "data_bucket" {
      ~ versioning {
          ~ enabled = false -> true
        }
    }

Plan: 1 to add, 1 to change, 0 to destroy.
A0
B3
C2
D1
Attempts:
2 left
💡 Hint

Look for the '+' sign which indicates resource creation.

🧠 Conceptual
intermediate
1:30remaining
Understanding Terraform plan output symbols

In Terraform plan output, what does the symbol '~' before a resource name indicate?

AThe resource will be updated in-place
BThe resource will be created
CThe resource will be destroyed
DThe resource will be replaced
Attempts:
2 left
💡 Hint

Think about what happens when a resource changes but is not destroyed.

❓ Configuration
advanced
2:00remaining
Reading Terraform plan output for resource replacement

Review this Terraform plan output snippet. How many resources will be replaced?

  # aws_lb.web_lb must be replaced
-/+ resource "aws_lb" "web_lb" {
      id             = "lb-1234"
      name           = "web-lb"
      internal       = false
      load_balancer_type = "application"
    }

Plan: 1 to add, 0 to change, 1 to destroy.
A1
B3
C2
D0
Attempts:
2 left
💡 Hint

Look for the '-/+' symbol which indicates replacement.

❓ security
advanced
2:30remaining
Detecting security risks from Terraform plan output

Given this Terraform plan output snippet, which change could introduce a security risk?

  # aws_security_group.sg will be updated in-place
  ~ resource "aws_security_group" "sg" {
      ~ ingress {
          ~ cidr_blocks = ["0.0.0.0/0"] -> ["0.0.0.0/0", "192.168.1.0/24"]
        }
    }

Plan: 0 to add, 1 to change, 0 to destroy.
AAdding 192.168.1.0/24 to ingress rules reduces exposure
BAdding 0.0.0.0/0 to ingress rules increases exposure
CAdding 192.168.1.0/24 to ingress rules increases exposure
DRemoving 0.0.0.0/0 from ingress rules increases exposure
Attempts:
2 left
💡 Hint

Consider which IP ranges are more open and risky.

❓ Architecture
expert
3:00remaining
Analyzing Terraform plan output for multi-resource orchestration

Examine this Terraform plan summary:

Plan: 3 to add, 2 to change, 1 to destroy.

Which of the following statements is true about the infrastructure state after applying this plan?

AThe infrastructure will have 2 fewer resources than before
BThe infrastructure will have 2 more resources than before
CThe infrastructure will have the same number of resources as before
DThe infrastructure will have 1 more resource than before
Attempts:
2 left
💡 Hint

Calculate net resource count: additions minus destructions.

Practice

(1/5)
1. What does the terraform plan command primarily show before applying changes?
easy
A. The current cost of your cloud resources
B. The changes Terraform will make to your infrastructure
C. The list of all Terraform providers installed
D. The history of previous Terraform apply commands

Solution

  1. Step 1: Understand the purpose of terraform plan

    This command previews the changes Terraform will perform on your infrastructure without applying them.
  2. Step 2: Compare options with command purpose

    Only The changes Terraform will make to your infrastructure correctly describes this preview of changes. Other options describe unrelated information.
  3. Final Answer:

    The changes Terraform will make to your infrastructure -> Option B
  4. Quick Check:

    Plan shows changes = B [OK]
Hint: Plan shows what changes will happen before apply [OK]
Common Mistakes:
  • Confusing plan with apply
  • Thinking plan shows costs
  • Assuming plan shows provider list
2. In Terraform plan output, what does the symbol ~ indicate?
easy
A. Resource will be updated
B. Resource will be created
C. Resource will be deleted
D. Resource will be ignored

Solution

  1. Step 1: Recall Terraform plan symbols

    The symbol ~ means a resource will be updated (changed in place).
  2. Step 2: Match symbol to meaning

    + means create, - means delete, so ~ must mean update.
  3. Final Answer:

    Resource will be updated -> Option A
  4. Quick Check:

    ~ means update = A [OK]
Hint: Remember + create, ~ update, - delete symbols [OK]
Common Mistakes:
  • Mixing up ~ with + or -
  • Thinking ~ means delete
  • Assuming ~ means no change
3. Given this Terraform plan output snippet:
  # aws_instance.web will be updated in-place
  ~ resource "aws_instance" "web" {
      instance_type = "t2.micro" -> "t2.small"
    }

What does this output mean?
medium
A. The instance type will change from t2.micro to t2.small
B. No changes will be made to the instance
C. The instance will be deleted and recreated
D. The instance will be created new

Solution

  1. Step 1: Analyze the plan output details

    The symbol ~ shows an in-place update. The instance_type changes from "t2.micro" to "t2.small".
  2. Step 2: Interpret the meaning

    This means the existing instance will be updated to the new type without deletion.
  3. Final Answer:

    The instance type will change from t2.micro to t2.small -> Option A
  4. Quick Check:

    ~ means update, instance_type changed = C [OK]
Hint: Look for ~ and arrow showing old -> new value [OK]
Common Mistakes:
  • Thinking resource will be deleted
  • Ignoring the arrow showing value change
  • Assuming no change because resource exists
4. You see this Terraform plan output:
  # aws_s3_bucket.example will be deleted
  - resource "aws_s3_bucket" "example" {
      bucket = "my-bucket"
    }

But you want to keep the bucket. What should you do?
medium
A. Ignore the plan and continue
B. Remove the resource from your Terraform config
C. Run terraform apply immediately
D. Add lifecycle rule with prevent_destroy to the resource

Solution

  1. Step 1: Understand the delete plan

    The plan shows the bucket will be deleted, but you want to keep it.
  2. Step 2: Use lifecycle prevent_destroy

    Adding a lifecycle block with prevent_destroy = true stops accidental deletion.
  3. Final Answer:

    Add lifecycle rule with prevent_destroy to the resource -> Option D
  4. Quick Check:

    Use prevent_destroy to block deletes = A [OK]
Hint: Use lifecycle prevent_destroy to stop unwanted deletes [OK]
Common Mistakes:
  • Removing resource causes deletion
  • Applying plan deletes bucket
  • Ignoring plan risks data loss
5. You run terraform plan and see:
  # aws_security_group.sg will be replaced
  - resource "aws_security_group" "sg" {
      name = "old-sg"
    }
  + resource "aws_security_group" "sg" {
      name = "new-sg"
    }

What does this mean and why does Terraform replace the resource instead of updating it?
hard
A. Terraform will fail because name change is not allowed
B. Terraform updates the resource in place changing the name
C. Terraform deletes and recreates because the name attribute is immutable
D. Terraform ignores the change because names can be duplicated

Solution

  1. Step 1: Analyze the plan output for replacement

    The plan shows the resource will be deleted (-) and a new one created (+) with a different name.
  2. Step 2: Understand why replacement occurs

    Some attributes like security group name are immutable, so Terraform must replace the resource to change them.
  3. Final Answer:

    Terraform deletes and recreates because the name attribute is immutable -> Option C
  4. Quick Check:

    Immutable attribute change causes replacement = D [OK]
Hint: Immutable attribute changes cause resource replacement [OK]
Common Mistakes:
  • Thinking Terraform updates name in place
  • Assuming name can be duplicated
  • Believing plan will fail on name change