Bird
Raised Fist0
Terraformcloud~20 mins

Terraform's declarative approach - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Terraform Declarative Mastery
Get all challenges correct to earn this badge!
Test your skills under time pressure!
🧠 Conceptual
intermediate
2:00remaining
Understanding Terraform's Desired State

Terraform uses a declarative approach to manage infrastructure. What does Terraform primarily store and use to manage resources?

AThe desired state of infrastructure as code
BThe sequence of commands to create resources
CThe current live state of infrastructure only
DManual scripts to update resources
Attempts:
2 left
💡 Hint

Think about what Terraform compares before making changes.

❓ service_behavior
intermediate
2:00remaining
Terraform Plan Behavior

What does the terraform plan command do in Terraform's declarative workflow?

ADeletes all existing resources
BShows the changes Terraform will make to reach the desired state
CImmediately applies changes to the infrastructure
DGenerates random resource names
Attempts:
2 left
💡 Hint

It previews changes without applying them.

❓ Configuration
advanced
3:00remaining
Terraform Resource Dependency Declaration

Given the following Terraform configuration snippet, what is the correct way to declare that aws_instance.web depends on aws_security_group.web_sg?

resource "aws_security_group" "web_sg" {
  name = "web_sg"
}

resource "aws_instance" "web" {
  ami           = "ami-123456"
  instance_type = "t2.micro"
  # Where to declare dependency?
}
AAdd <code>depends_on = ["aws_security_group.web_sg"]</code> inside <code>aws_instance.web</code>
BAdd <code>depends_on = [aws_instance.web]</code> inside <code>aws_security_group.web_sg</code>
CNo need to declare; Terraform infers dependencies automatically
DAdd <code>depends_on = [aws_security_group.web_sg]</code> inside <code>aws_instance.web</code>
Attempts:
2 left
💡 Hint

Explicit dependencies use depends_on with resource references.

❓ Architecture
advanced
3:00remaining
Terraform State Management Best Practice

In a team environment, what is the best practice for managing Terraform state files to avoid conflicts and ensure consistency?

AStore state files locally on each developer's machine
BManually merge state files after each run
CUse remote state storage with locking, such as Terraform Cloud or S3 with DynamoDB locking
DDelete state files after each apply to avoid conflicts
Attempts:
2 left
💡 Hint

Think about shared access and preventing simultaneous changes.

❓ security
expert
4:00remaining
Handling Sensitive Data in Terraform

Which approach best protects sensitive data such as passwords or API keys in Terraform configurations and state files?

AUse Terraform variables marked as <code>sensitive = true</code> and store secrets in a secure secrets manager referenced via data sources
BHardcode secrets directly in Terraform configuration files for easy access
CShare secrets via email among team members to keep them private
DStore secrets in plain text in the Terraform state file without encryption
Attempts:
2 left
💡 Hint

Consider both configuration and state file security.

Practice

(1/5)
1. What does Terraform's declarative approach mean?
terraform apply will create resources based on what you specify, not how to create them.
easy
A. You describe the desired state of infrastructure, not the steps to create it.
B. You write scripts that run commands step-by-step to build infrastructure.
C. You manually create resources in the cloud console and Terraform tracks them.
D. You use Terraform only to delete resources, not create them.

Solution

  1. Step 1: Understand declarative vs imperative

    Declarative means describing the end state, while imperative means describing the steps to get there.
  2. Step 2: Apply to Terraform

    Terraform uses declarative approach by letting you write configuration files that describe what you want, not how to do it.
  3. Final Answer:

    You describe the desired state of infrastructure, not the steps to create it. -> Option A
  4. Quick Check:

    Declarative = Describe desired state [OK]
Hint: Declarative means say what, not how [OK]
Common Mistakes:
  • Confusing declarative with imperative scripting
  • Thinking Terraform runs commands step-by-step
  • Believing Terraform only deletes resources
2. Which Terraform configuration snippet correctly declares an AWS S3 bucket named "mybucket"?
easy
A. resource aws_s3_bucket mybucket { bucket_name = "mybucket" }
B. create aws_s3_bucket mybucket { name = "mybucket" }
C. aws_s3_bucket "mybucket" { bucket_name = "mybucket" }
D. resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" }

Solution

  1. Step 1: Identify correct Terraform resource syntax

    Terraform resource blocks start with 'resource', then resource type in quotes, then resource name in quotes, followed by braces with arguments.
  2. Step 2: Match correct attribute names

    The attribute to name an S3 bucket is 'bucket', not 'bucket_name'. resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" } matches correct syntax and attribute.
  3. Final Answer:

    resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" } -> Option D
  4. Quick Check:

    Correct resource block syntax = resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" } [OK]
Hint: Terraform resource blocks start with resource "type" "name" [OK]
Common Mistakes:
  • Using incorrect keywords like 'create' instead of 'resource'
  • Missing quotes around resource type or name
  • Using wrong attribute names like 'bucket_name'
3. Given this Terraform configuration:
resource "aws_instance" "example" {
  ami           = "ami-123456"
  instance_type = "t2.micro"
}

What will Terraform do when you run terraform apply for the first time?
medium
A. It will delete any existing EC2 instances named example.
B. It will only plan the changes but not create any resources.
C. It will create an AWS EC2 instance with the specified AMI and instance type.
D. It will throw a syntax error due to missing provider block.

Solution

  1. Step 1: Understand resource declaration effect

    The resource block declares an EC2 instance with given AMI and type. Terraform will create it on apply.
  2. Step 2: Consider first apply behavior

    On first apply, Terraform creates resources to match the declared state. Missing provider block is not a syntax error but requires provider configuration elsewhere.
  3. Final Answer:

    It will create an AWS EC2 instance with the specified AMI and instance type. -> Option C
  4. Quick Check:

    First apply creates declared resources [OK]
Hint: terraform apply creates resources declared first time [OK]
Common Mistakes:
  • Confusing plan with apply behavior
  • Expecting deletion instead of creation
  • Assuming missing provider block causes syntax error
4. You wrote this Terraform code:
resource "aws_s3_bucket" "bucket" {
  bucket = "mybucket"
  acl    = "public-read"
}

But Terraform apply fails with an error about bucket name already existing. What is the best fix?
medium
A. Change the bucket name to a unique one because S3 bucket names must be globally unique.
B. Remove the acl attribute to fix the error.
C. Rename the resource block from "bucket" to "mybucket".
D. Run terraform destroy before apply to clear existing buckets.

Solution

  1. Step 1: Understand S3 bucket naming rules

    S3 bucket names must be globally unique across all AWS accounts.
  2. Step 2: Analyze error cause

    The error means the bucket name "mybucket" is already taken by someone else, so Terraform cannot create it.
  3. Step 3: Choose fix

    Changing the bucket name to a unique one solves the problem. Other options do not address uniqueness.
  4. Final Answer:

    Change the bucket name to a unique one because S3 bucket names must be globally unique. -> Option A
  5. Quick Check:

    S3 bucket names must be unique globally [OK]
Hint: S3 bucket names must be unique globally [OK]
Common Mistakes:
  • Thinking acl attribute causes name conflict
  • Renaming resource block does not change bucket name
  • Destroying resources unnecessarily
5. You want to manage a set of AWS EC2 instances with Terraform declaratively. You have a list of instance names and want to create one instance per name. Which Terraform feature best fits this declarative approach?
hard
A. Manually create each instance resource block with a unique name.
B. Use a for_each meta-argument on the resource block with the list of names.
C. Write a shell script to loop and run terraform apply multiple times.
D. Use a count meta-argument with a fixed number and hardcoded names.

Solution

  1. Step 1: Understand declarative resource creation for multiple items

    Terraform's for_each lets you declare multiple instances based on a collection, matching the declarative style.
  2. Step 2: Evaluate options

    Shell scripts and manual blocks are imperative or repetitive, not declarative. Using count with hardcoded names is less flexible than for_each.
  3. Final Answer:

    Use a for_each meta-argument on the resource block with the list of names. -> Option B
  4. Quick Check:

    for_each creates resources declaratively from collections [OK]
Hint: for_each creates multiple resources declaratively [OK]
Common Mistakes:
  • Using imperative loops outside Terraform
  • Hardcoding multiple resource blocks manually
  • Using count without dynamic naming