Terraform Associate 004 Exam Preparation: A Practical Guide (What’s New vs 003)
The HashiCorp Certified: Terraform Associate (004) exam is the current version of HashiCorp’s entry-level Terraform certification. If you studied with 003 materials, or you’re starting from scratch, this guide covers what HashiCorp officially publishes about the exam, what’s new compared with 003, and how to prepare with hands-on labs instead of memorising flashcards. Every exam fact below comes from HashiCorp’s Terraform Associate page and its official study materials. (HashiCorp itself is now part of IBM and operates as a division of IBM Software.)
Exam at a glance
| Assessment type | Multiple choice (question types: true/false, multiple choice, multiple answer) |
| Format | Online proctored |
| Duration | 1 hour |
| Price | $70.50 USD, plus locally applicable taxes and fees; free retake not included |
| Language | English |
| Version tested | Terraform 1.12 |
| Credential expiration | 2 years |
HashiCorp publishes neither the number of questions nor the passing score. It also publishes no percentage weights for the domains. Be wary of any source that quotes exact figures for these.
Who it’s for: HashiCorp aims the exam at cloud engineers with foundational Terraform knowledge who can identify Terraform Enterprise features and tell them apart from the Community edition. The listed prerequisites are basic terminal skills and an understanding of on-premises and cloud architecture. Professional experience is recommended, but HashiCorp says practising the objectives in a personal demo environment may be enough.
What’s new in 004 vs 003
HashiCorp’s exam content list summarises the update as four new topics:
- 4f:
depends_onandcreate_before_destroylifecycle rules - 4g: validating configuration with custom conditions
- 4h: ephemeral values and write-only arguments
- 8c: organising and using HCP Terraform workspaces and projects
It also notes that the exam now tests Terraform 1.12 and includes HCP Terraform content. In the full objective list, 4h is worded as “Understand best practices for managing sensitive data, including secrets management with Vault”. So ephemeral values and write-only arguments belong to the wider topic of handling secrets, which also includes the Vault provider.
What was removed or restructured? HashiCorp doesn’t publish a “removed topics” list. Comparing the two official objective lists (HashiCorp’s 003 one-pager against the 004 page) shows three changes:
- The domains were cut from nine to eight and reordered.
- The separate 003 domain “Understand Terraform’s purpose (vs other IaC)” is gone. Its multi-cloud and state topics now sit in 1c and 2d.
- Two 003 objectives no longer appear by name: “Handle backend and cloud integration authentication methods” and “Differentiate remote state back end options”. 004 covers the local backend, state locking and configuring remote state with the
backendblock.
Treat this as a reading of the objective titles, not an official change log.
Exam objectives (004)

- Infrastructure as Code (IaC) with Terraform: what IaC is, its advantages, and multi-cloud, hybrid-cloud and service-agnostic workflows
- Terraform fundamentals: installing and versioning providers, how Terraform uses providers, using multiple providers, how Terraform uses and manages state
- Core Terraform workflow:
init,validate,plan,apply,destroy,fmt - Terraform configuration: resource vs data blocks, cross-resource references, variables and outputs, complex types, expressions and functions, resource dependencies (new), custom conditions (new), sensitive data and Vault (new)
- Terraform modules: module sources, variable scope, using modules, module versions
- Terraform state management: local backend, state locking, remote state with the
backendblock, resource drift - Maintain infrastructure with Terraform: import, inspecting state with the CLI, verbose logging
- HCP Terraform: creating infrastructure, collaboration and governance, workspaces and projects (new), CLI integration
A practical 4-week study plan
Use a free local setup. HashiCorp’s own learning path offers Get Started tutorials for AWS, Azure, GCP and Docker, and Docker is the easiest option if you don’t want a cloud bill. The content list states that provider-specific knowledge isn’t required for the exam.
- Week 1, fundamentals and workflow (domains 1–3). Write a configuration with two providers, pin their versions, and look at
.terraform.lock.hcl. Runinit,fmt,validate,plan,applyanddestroyuntil you can predict what each one does. - Week 2, configuration in depth (domain 4). Practise variables with complex types, outputs,
forexpressions and functions, and data sources. New-topic labs: adddepends_onfor a hidden dependency and see how the plan changes. Setlifecycle { create_before_destroy = true }on a resource and force a replacement. Write a variablevalidationblock, a resourceprecondition/postconditionand acheckblock, then compare how each one fails. Work through the official sensitive-data and ephemeral-value material. - Week 3, modules, state and maintenance (domains 5–7). Build a local module and use one from the registry, pinning its version. Move state to a remote backend, refactor with
movedandremovedblocks, simulate drift and fix it with refresh-only mode, import an existing resource, and inspect state withterraform state listandterraform show. Turn onTF_LOG. - Week 4, HCP Terraform and practice exams (domain 8). Create a free HCP Terraform organisation if you can, run
terraform login, migrate state, group workspaces into a project, use variable sets and run triggers, and read about teams, policies and drift detection. Finish with timed practice runs.
Common traps
- Secrets in state: HashiCorp’s own sample question confirms that usernames and passwords referenced in configuration, even through variables, end up in plain text in the state file. Know which features avoid persisting values; that’s where the new ephemeral and write-only topics come in.
- Refresh behaviour:
planandapplyrefresh state by default.validate,stateandoutputdon’t. - Auto-loaded variables:
terraform.tfvarsin the working directory is loaded automatically, soplanandplan -var-file=terraform.tfvarsboth use it. - Overusing
depends_on: Terraform infers most dependencies from references.depends_onis for dependencies Terraform can’t see. - Two kinds of workspace: HCP Terraform workspaces (and projects) are not the same thing as CLI workspaces in a local working directory.
- Edition features: HashiCorp expects you to tell HCP Terraform and Enterprise features apart from the Community edition.
Practise under exam conditions
An hour goes quickly when the questions are scenario-based. Once your labs are done, take timed mock exams with the Terraform Associate (004) practice exam on Testimea, or start with the Terraform Associate practice exam trial. For your next step after the Associate, see the Terraform Authoring and Operations Advanced practice exam. Before exam day, also review HashiCorp’s official sample questions and learning path.
Exam-day mindset
HashiCorp says its questions are “not intended to trick you” and that the exam tests your Terraform knowledge, “not how well you spell or how good you are at identifying obscure details.” So read each scenario for what Terraform would actually do, and don’t hunt for wording tricks. Multiple-answer questions tell you how many options to select, so count before you submit. The exam is online proctored, so run through the delivery platform’s ID, system and room requirements well before your appointment.
Renewal and recertification
The credential expires after 2 years. If you hold an unexpired 004 credential, you can extend it in three ways:
- pass the Terraform Infrastructure Engineer Professional exam
- pass the AWS or Azure version of Terraform Authoring and Operations Advanced
- retake 004 starting 6 months before expiration
If you hold an unexpired 002 or 003 credential, passing the Professional or Advanced exam extends it. Passing 004 in the 6 months before expiration instead gives you a new, separate credential, and the original expiration date doesn’t change. If your credential has already expired, you pass the current version at any time.
FAQ
Which Terraform version does 004 test?
Terraform 1.12.
How long is the exam and how much does it cost?
It lasts 1 hour and costs $70.50 USD plus local taxes and fees. A free retake isn’t included.
Can I take it at a test center?
HashiCorp lists the format as online proctored only.
Are my 003 study materials still useful?
Mostly. The core workflow, modules, state and HCP Terraform basics carry over. Add the four new topics (4f, 4g, 4h, 8c) and make sure your materials reflect Terraform 1.12.
Do I need cloud-provider knowledge?
No. HashiCorp says provider-specific knowledge isn’t necessary, although its tutorials use cloud providers as examples.
How many questions are there, and what’s the passing score?
HashiCorp doesn’t publish either.
