# Terraform and OpenTofu Interview Questions and Answers (with AWS Examples)

> The most common Terraform and OpenTofu interview questions for DevOps and cloud roles, with short answers on state, modules, lifecycle, secrets, AWS and CI/CD.

- Source: https://www.itwonderlab.com/terraform-interview-questions/
- Published: 2026-03-14
- Updated: 2026-03-14
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

## Terraform interview questions, grouped by topic

Short answers to the questions that appear most in DevOps, SRE and cloud engineer interviews. Each answer links to a longer guide. Everything also applies to OpenTofu.

### Basics

**What is Terraform and what problem does it solve?**
An [Infrastructure as Code](https://www.itwonderlab.com/iac/) tool that describes infrastructure in declarative [HCL](https://www.itwonderlab.com/hcl/) files, compares them with reality and creates, changes or destroys resources through provider APIs. It gives repeatable, reviewable and versioned infrastructure.

**What is the difference between declarative and imperative?**
In a declarative tool (Terraform) you describe the desired end state and the tool works out the steps. In an imperative one (a Bash script with the AWS CLI) you write the steps.

**What are the main commands?**
`init`, `validate`, `plan`, `apply` and `destroy`. See the [cheat sheet](https://www.itwonderlab.com/terraform-cheat-sheet/).

**What does `terraform init` do?**
Downloads providers and modules, configures the backend and creates `.terraform.lock.hcl`.

**What is the difference between Terraform and OpenTofu?**
OpenTofu is the open-source (MPL 2.0) fork under the Linux Foundation. Same language and providers, plus features such as state encryption. See [Terraform vs OpenTofu](https://www.itwonderlab.com/terraform-vs-opentofu/).

### State

**What is the state file and why does it matter?**
It maps your code to the real resources and stores their attributes. Without it Terraform cannot know what it manages. See [Terraform state](https://www.itwonderlab.com/terraform-state/).

**Where should you store it in a team?**
In a remote [backend](https://www.itwonderlab.com/terraform-backend/) with locking, versioning and encryption, such as S3 with `use_lockfile` (Terraform 1.10 and later, and OpenTofu), or DynamoDB for older versions. See [backends](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-backends/).

**What is state locking?**
It prevents two runs from changing the state at the same time. A stuck lock is released with `terraform force-unlock <ID>`, after checking that no run is active.

**How do you protect secrets in the state?**
Encrypted private backend, restricted access, [state encryption in OpenTofu](https://www.itwonderlab.com/terraform-state-file-encryption/), and AWS-managed secrets so the value never enters the state. See [secrets management](https://www.itwonderlab.com/terraform-secrets-management/).

**What is drift and how do you handle it?**
Differences between code and reality caused by manual changes. Detect it with a scheduled `plan`, then update the code or re-apply. See [drift](https://www.itwonderlab.com/terraform-drift/).

**How do you bring existing infrastructure under Terraform?**
`import` blocks (or `terraform import`), then run `plan` until it is clean. See [import, moved and removed](https://www.itwonderlab.com/terraform-import-moved-removed/).

### Language

**What is the difference between `count` and `for_each`?**
`count` indexes by number and recreates items when the list changes. `for_each` indexes by key. See [for_each vs count](https://www.itwonderlab.com/terraform-for-each-vs-count/).

**What is a data source?**
A read-only lookup of existing information. See [data sources](https://www.itwonderlab.com/terraform-data-sources-remote-state/).

**What are variables, locals and outputs?**
Inputs, named expressions and returned values. See [variables, outputs and locals](https://www.itwonderlab.com/terraform-variables-outputs-locals/).

**What is a `dynamic` block?**
It generates repeated nested blocks from a collection. See [dynamic blocks](https://www.itwonderlab.com/terraform-dynamic-blocks/).

**How do implicit and explicit dependencies work?**
A reference to another resource creates an implicit dependency. `depends_on` creates an explicit one. See [dependencies](https://www.itwonderlab.com/terraform-depends-on-dependencies/).

**What does the `lifecycle` block do?**
`prevent_destroy`, `create_before_destroy`, `ignore_changes`, `replace_triggered_by` and conditions. See [lifecycle](https://www.itwonderlab.com/terraform-lifecycle-meta-argument/).

**How do you write a conditional resource?**
`count = var.enabled ? 1 : 0`. See [conditionals and for expressions](https://www.itwonderlab.com/terraform-conditionals-for-expressions/).

**What are provisioners and why avoid them?**
They run scripts on a resource after creation. They are a last resort because they are not declarative and are not tracked in the plan. See [provisioners and user data](https://www.itwonderlab.com/terraform-provisioners-user-data/).

### Modules and structure

**What is a module and how do you version it?**
A reusable directory of resources with inputs and outputs. Pin the version of external modules with Git tags or registry versions. See [modules](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-modules/) and [popular AWS modules](https://www.itwonderlab.com/terraform-aws-modules-vpc-eks/).

**How do you manage several environments?**
Separate state per environment: directories, tfvars with a backend per environment, or workspaces. See [workspaces vs directories](https://www.itwonderlab.com/terraform-workspaces-vs-directories/).

**How do you organize a large project?**
Split state by layer and lifecycle. See [project structure](https://www.itwonderlab.com/terraform-project-structure/).

**How do you use several AWS regions or accounts?**
Provider aliases. See [multi-region and multi-account providers](https://www.itwonderlab.com/terraform-multi-region-provider-alias/).

### AWS and operations

**How does Terraform authenticate to AWS?**
Environment variables, shared profiles, instance roles or SSO. In CI/CD, short-lived credentials with [OIDC](https://www.itwonderlab.com/terraform-github-actions-aws-oidc/). See [the AWS provider](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-aws-provider/).

**How would you design a CI/CD pipeline for Terraform?**
Format, validate, lint and scan on pull requests, save the plan, require review, and apply the same plan from the main branch with approval. See [CI/CD](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-cicd/).

**How do you test Terraform code?**
`validate`, linters, security scanners, `terraform test` and Terratest. See [testing](https://www.itwonderlab.com/terraform-testing-opentofu-test/) and [security scanning](https://www.itwonderlab.com/terraform-security-scanning-tflint-checkov-trivy/).

**How do you rename a resource without destroying it?**
A `moved` block.

**What do you do when `apply` fails halfway?**
The state records what was created. Fix the cause and run `apply` again. See [common errors](https://www.itwonderlab.com/terraform-common-errors/).

**How do you force a resource to be recreated?**
`terraform apply -replace=<address>`. See [replace, taint and target](https://www.itwonderlab.com/terraform-replace-taint-target/).

**How do you control cost?**
Estimate in pull requests with [Infracost](https://www.itwonderlab.com/terraform-cost-estimation-infracost/) and follow [FinOps practices](https://www.itwonderlab.com/aws-cost-optimization-finops/).

### Scenario questions

**Someone changed a security group by hand. What do you do?**
Run `plan` to see the drift, decide which side is right, update the code or apply, and restrict console write access.

**A teammate's `apply` crashed and the lock remains.**
Confirm nothing is running, then `force-unlock`.

**The `plan` takes 20 minutes.**
Split the state, reduce data sources, increase `-parallelism`, and avoid `-refresh` on huge states only as a last resort.

**You need to move a resource from one state to another.**
`removed` block with `destroy = false` in the source and `import` in the target, or `terraform state mv` with `-state-out`.

For certification study, see the [Terraform Associate guide](https://www.itwonderlab.com/terraform-associate-certification-guide/).
