
HashiCorp Certified:Terraform Associate
Domain 4Objective 8
4h Understand Best Practices for Managing Sensitive Data, Including Secrets Management with Vault TERRAFORM-ASSOCIATE-004 Practice Questions (Page 5)
Part of the Terraform configuration domain, which makes up ~22% of our current practice bank. HashiCorp does not publish an official question count, but from its 60-minute exam (~25–40 total, ~6–9 in this domain), expect 1–1 from this objective — we provide 76 practice questions to prepare you well beyond it. (estimate)
76questions here
16free pages
36concepts
Questions 21–25
- 21
A company must comply with a regulation that requires encryption of sensitive data at rest and in transit. They use Terraform with Vault to manage secrets. What should they verify to ensure compliance?
Select an answer first - 22
A Terraform configuration uses a Vault data source to fetch a secret and then includes that secret in an alert webhook payload. What is a best practice to follow?
Select an answer first - 23
A Terraform configuration defines a variable that holds a database password. The password is provided at runtime, but the team has noticed that the value appears in the output of terraform plan and in the apply logs. Which declaration change would prevent the value from being displayed in plan/apply output and logs?
Select an answer first - 24
How can you use a Vault secret in a provisioner without exposing it in logs?
Select an answer first - 25
In a HashiCorp Vault policy, what is the primary purpose of the `path` block and its associated capabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by HashiCorp. “TERRAFORM-ASSOCIATE-004” is a trademark of its owner, used for identification only.