Skip to main content
CloudCareerLabs Logo CloudCareerLabs
Terraform Technical Screening Guides & Flashcard Preparation

Free Terraform Interview Questions

Technical hiring standards for systems engineers demand quick problem-solving and conceptual clarity. This guide compiles the most common screening questions, complete with structural explanations and diagnostic walkthroughs. Ace your next infrastructure engineer interview with our comprehensive guide to Terraform interview questions. We cover essential topics including remote state management, lock mechanics, resource dependency graph, state imports, dynamic blocks, and module structuring. By utilizing standard patterns, engineers can build robust, highly automated platforms.

AR
Written by Ashmit N. Rai • Co-Founder & DevOps Platform Engineer DevOps automation specialist and Infrastructure-as-Code expert.

The Terraform Core Execution Cycle & State Management

Terraform is a declarative, stateful Infrastructure as Code utility developed by HashiCorp. It reads your configuration files (.tf) and builds a dependency graph of resources to orchestrate state updates on cloud providers.

State File & Lifecycle Operations

Terraform Core Execution Cycle & State Management

1. terraform init: Initializes the workspace, downloads target provider plugins (e.g. AWS, Azure), and configures backend connections.

2. terraform plan: Performs a dry-run comparison. It queries the target cloud provider, reads active states, compares them to your code, and outputs a plan of additions (+), modifications (~), and destructions (-).

3. terraform apply: Executes the plan. It updates resources on the provider and records the final state map inside terraform.tfstate.

---

Technical Q&As (IaC Operations)

Q1: What is Terraform State Locking, why is it critical, and how do you recover from a stranded state lock in a team CI/CD pipeline?

Answer: When multiple engineers or build machines attempt to run Terraform pipelines concurrently, they risk overwriting each other's changes or corrupting the state file. To prevent this, Terraform implements State Locking:

  • Backend Support: Standard backends like Amazon S3 use an auxiliary database table (like DynamoDB) to write a lock record containing the execution ID. While active, any other pipeline execution will fail with an error.
  • Force Unlock: If a CI/CD build crashes during an apply phase, the lock record might remain stranded. To clear this lock, inspect the lock ID from the terminal error logs and run:
terraform force-unlock 

*Caution: Only force unlock if you are 100% sure that no other apply process is currently running on the resources.*

Q2: How do you handle configuration loops using 'count' vs. 'for_each'? When should you choose one over the other?

Answer: Both operators create multiple instances of a resource, but their underlying key tracking mechanisms differ:

1. count: Takes a list or number and generates resources indexed by array positions (e.g. aws_instance.web[0], aws_instance.web[1]).

  • *Problem*: If you remove an element from the middle of the input list, Terraform shifts all subsequent resource keys. During the next apply, it will attempt to destroy and recreate resources that shouldn't be touched.

2. for_each: Takes a map or set of strings and creates resources indexed by string keys (e.g. aws_subnet.private["subnet-a"], aws_subnet.private["subnet-b"]).

  • *Advantage*: Removing or adding items to the input map only affects the specific target key. The rest of the keys remain unchanged, preventing accidental resources deletions.

Q3: How do you securely handle sensitive values (like passwords or API tokens) in Terraform without hardcoding them in git repositories?

Answer: Best practices for handling secrets in IaC include:

  • Declare as Sensitive: Mark variables as sensitive to prevent Terraform from printing their values in stdout during plan and apply:
variable "db_password" {
  type      = string
  sensitive = true
}
  • Environment Variables: Populate the variable from your shell or CI/CD environment using the TF_VAR_ prefix (e.g., export TF_VAR_db_password="secret123").
  • External Secrets Managers: Use Terraform data sources to fetch secrets at runtime from systems like AWS Secrets Manager or HashiCorp Vault:
data "aws_secretsmanager_secret_version" "db_creds" {
  secret_id = "production/database/credentials"
}
# Reference using: jsondecode(data.aws_secretsmanager_secret_version.db_creds.secret_string)["password"]

---

Core Terraform Syntax & Troubleshooting

Implementing Dynamic Ingress Blocks

Use the dynamic block configuration to generate security group rule parameters programmatically, keeping your code DRY:

variable "ingress_ports" {
  type        = list(number)
  default     = [80, 443, 8080, 9000]
  description = "Allowed incoming TCP ports"
}

resource "aws_security_group" "web_firewall" {
  name        = "web-traffic-rules"
  description = "Orchestrated ingress configurations"
  vpc_id      = "vpc-01234567"

  dynamic "ingress" {
    for_each = var.ingress_ports
    content {
      from_port   = ingress.value
      to_port     = ingress.value
      protocol    = "tcp"
      cidr_blocks = ["0.0.0.0/0"]
    }
  }
}

Identifying State Drifts via CLI

If someone manually edits a resource in the AWS Console, Terraform's local state file becomes out of sync (State Drift). To check for drifts without modifying configurations:

terraform plan -detailed-exitcode

To synchronize the local state map with actual cloud reality, run:

terraform refresh

Terraform Infrastructure Engineering Interview Screening

Interactive Troubleshooting Lab

The interviewer asks: 'How would you structure a Terraform project supporting separate Dev, Staging, and Production environments without duplicate resource code?'

production_manifest.yaml
terraform {
  required_version = ">= 1.3.0"
  backend "s3" {
    bucket         = "cclabs-tfstate-prod"
    key            = "global/s3/terraform.tfstate"
    region         = "us-east-1"
    dynamodb_table = "cclabs-tflocks"
    encrypt        = true
  }
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_dynamodb_table" "locks" {
  name         = "cclabs-tflocks"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "LockID"

  attribute {
    name = "LockID"
    type = "S"
  }
}

Diagnostic & Resolution Steps

Recommended remediation commands

To resolve this system outage, follow these step-by-step diagnostic and remediation instructions: 1. Recommend using Terraform Workspace (`terraform workspace select dev/prod`) or structured folders using modules. 2. Highlight that folder structure is better for production isolation since workspaces share the same state file backend storage configuration. Here is the clean, verified configuration file or script template demonstrating how to resolve this configuration drift or deploy the service correctly:

Interview Success Benchmarks for Terraform

Core competencies & reference questions

To prepare effectively for the challenges of managing Terraform, review the key domains and common test questions detailed below. These represent actual operational tasks expected of DevOps engineers in modern software environments.

Core Question: Describe the startup lifecycle of a service in this environment.

Explain how components verify network connections, synchronize states with configuration registries, and signal health back to the control plane.

Verification Checked

Scenario Question: How do you troubleshoot socket exhaustion or API latency issues?

Detail debugging steps including connection state counts, routing analysis, scaling policies, and file handle limits.

Verification Checked

Architecture Question: Explain how this technology guarantees idempotency.

Provide details on declarative configurations, state management comparisons, and how the target engine updates only modified parameters.

Verification Checked

Frequently Asked Questions

Technical reference answers

Q: What is the difference between 'terraform plan' and 'terraform apply'?

Plan compares your configuration to state and proposed cloud modifications without editing; Apply executes the calls to achieve the state.

Q: How do you securely handle secrets in Terraform?

Use environment variables (TF_VAR_*), fetch dynamically from KeyVault/SecretsManager, and keep state files encrypted in remote backends.

Q: What is configuration drift in Terraform and how do you resolve it?

Drift is when cloud resources change outside of Terraform. Run `terraform plan` to identify and update HCL or run `terraform apply` to overwrite.

Ready to test your skills in real-time?

Take the next step in your cloud career. Access our interactive simulators, test your command-line capabilities on live terminals, run script execution pipelines, and verify your configuration files instantly.

Practice Flashcards for Terraform  →