You must enable and configure the correct secrets engine, then use the right path and parameters for its API. The single most important thing: know KV v2 stores data under secret/data/ and metadata under secret/metadata/, so wrong paths return 404.
Start practicing
Compare and configure secrets engines — choose a session length
Free · No account required
Domain overview
This domain covers enabling, configuring, and using Vault secrets engines: KV v1/v2 versioning, dynamic credentials for AWS/Azure/databases, transit encryption, and PKI. Questions test whether you can pick the right engine, set required role or config parameters, and explain why a read returns 404 or 403.
Exam objectives
Enabling and tuning KV v2 with versioning, metadata, and the data/ path prefix
Configuring AWS and Azure secrets engines for dynamic IAM or service principal credentials
Database secrets engine role creation and credential rotation via Vault
Transit secrets engine encryption, decryption, and key rotation operations
Reading KV v2 secrets at secret/app instead of secret/data/app, causing a 404 Not Found error
Forgetting that dynamic database roles need creation statements and connection config before use
Assuming KV v1 supports versioning or rollback; only KV v2 keeps version history
Click any question to see the full explanation and answer options, or start a focused practice session above.
A DevOps team uses Vault to store database credentials via the database secrets engine. They notice that after the default lease duration, applications receive errors when trying to connect. The team wants to ensure that applications automatically renew leases before expiration. What should they do?
2A security team wants to store static secrets like API keys in Vault. They need the secrets to be versioned and support rollback. Which secrets engine should they use?
3An organization uses the AWS secrets engine to generate IAM users dynamically. They notice that the generated IAM user is not immediately available for use in AWS. What is the most likely reason?
4A developer wants to use Vault to encrypt sensitive data before storing it in a database. They need to perform encryption and decryption operations without ever exposing the encryption key. Which secrets engine should they use?
5Which TWO of the following are valid use cases for the Transit secrets engine? (Select exactly 2.)
6Which THREE of the following are true about the KV v2 secrets engine? (Select exactly 3.)
7A financial services company runs a microservices application on Kubernetes. Each service needs to authenticate to Vault using Kubernetes auth and then read secrets from a shared KV v2 engine mounted at 'shared-kv'. The security team requires that Service-A can only read secrets under 'shared-kv/team-alpha/*' and Service-B can only read secrets under 'shared-kv/team-beta/*'. The Vault administrator has already configured the Kubernetes auth method and created roles for each service with bound service account names. However, both services are currently able to read all paths under 'shared-kv/'. The administrator wants to enforce the least privilege access. Which course of action should the administrator take?
8A company wants to securely store database credentials for a dynamic application that spins up new instances frequently. They need to ensure each instance gets a unique, time-limited username/password pair with minimal operational overhead. Which approach should they use?
9Which TWO of the following are valid methods to enable a secrets engine at a non-default path in Vault?
10Drag and drop the steps to configure Vault's database secrets engine with PostgreSQL into the correct order.
11An application needs to obtain short-lived, time-limited credentials to access an external database using username/password authentication. Which secrets engine should be used?
12An organization needs to automatically issue X.509 certificates for internal services. Which secrets engine should they use?
13A company wants to use Vault to generate IAM users dynamically for each application, following the principle of least privilege. Which secrets engine configuration should they use?
14An administrator enables the database secrets engine for PostgreSQL. After configuring the connection, running `vault write database/config/someconfig` yields error: 'x509: certificate signed by unknown authority'. What is the most likely cause?
15A security architect is designing a secrets management solution with Vault. Which THREE secrets engines are most appropriate for dynamically generating credentials for external systems?
16Refer to the exhibit. An application uses this policy to access Vault. The application is able to read database credentials from `database/creds/my-role`. However, attempts to list all roles at `database/roles/` fail. What is the most likely cause?
17A developer wants to store an API key for their application in Vault using the key-value secrets engine. They need to be able to retrieve the key and also roll back to a previous version if needed. Which secrets engine configuration should they use?
18A Vault administrator has enabled the PKI secrets engine and configured a root CA. They now need to issue certificates for multiple internal services, each with its own common name (CN). Which is the most efficient way to issue certificates while maintaining security?
19An organization uses the AWS secrets engine to generate IAM users for each application. They want to ensure that if a Vault server is compromised, the attacker cannot use the AWS secrets engine configuration to gain access to the AWS account. Which additional security measure should be implemented?
20A company needs to generate short-lived, dynamic database credentials for its MySQL instances. Which secrets engine should be configured?
21An operator wants to enable the database secrets engine at a custom path 'db-creds'. Which command should be used?
22An organization wants to encrypt data in transit and at rest using a centralized key management system. Which secrets engine is designed for encryption/decryption operations without storing data?
23A team is adopting Vault and wants to organize secrets by application and environment (e.g., production, staging). What is the best practice for secrets engine path naming?
24A DevOps engineer configures the AWS secrets engine to assume a specific IAM role for generating dynamic credentials. The engine is enabled and the root configuration is set. Which parameter is essential in the role configuration to allow assuming the IAM role?
25A developer needs to generate a new certificate for an internal web service using the PKI secrets engine. A role named 'webserver' has been created. What is the correct command to issue the certificate?
26An organization needs to store secrets with versioning support, allowing rollback to previous secret values. Which KV secrets engine version should be enabled?
27Which TWO of the following are benefits of using dynamic secrets engines (e.g., database, AWS) over static secrets?
28Which THREE steps are required to configure the database secrets engine for generating dynamic credentials?
29An operator needs to enable the KV v2 secrets engine at the path 'team-alpha'. Which command should they run?
30A development team wants to encrypt sensitive data before storing it in a database. They don't want to manage encryption keys themselves. Which secrets engine should they use?
31Refer to the exhibit. A Vault policy allows 'list' on 'secret/data/*'. A user tries to list keys under 'secret/data/' and gets a permission denied error. What is the most likely reason?
32Refer to the exhibit. A user deletes the current version of 'secret/myapp' using 'vault kv delete secret/myapp'. What happens to the version?
33A company needs to automatically generate short-lived database credentials for developers. Which secrets engine should they use?
34An organization uses the Transit secrets engine to encrypt sensitive files. They want to rotate the encryption key regularly without re-encrypting all existing files. Which feature allows this?
35A Vault operator runs 'vault secrets list' and sees 'cubbyhole/' mounted. What is the purpose of this engine?
36An operator configures a PKI role with allow_any_name=true and max_ttl=72h. A user requests a certificate with common_name='admin.example.com' and ttl=48h. What is the resulting TTL?
37An administrator configures a database secrets engine with a role that uses 'creation_statements' and 'revocation_statements'. However, when a lease expires, the database user is not revoked. What is the most likely cause?
38A DevOps team needs to provide temporary database credentials to applications without storing long-lived passwords. Which secrets engine should they use?
39An organization wants to use Vault to generate AWS IAM users with specific managed policies attached. They have configured the AWS secrets engine with the appropriate IAM credentials. What step is required to ensure each generated user gets the correct policies?
40An application is failing to decrypt data using the transit secrets engine. The ciphertext was generated with key 'my-key' version 3, but the engine currently shows key version 5. What is the most likely cause of the failure?
41After migrating from an older version of Vault, the operator wants to replace the deprecated 'generic' secrets engine with a modern alternative. Which secrets engine should be used to store static key-value pairs?
42Which TWO of the following are features of the AWS secrets engine compared to the Azure secrets engine?
43Which THREE steps are required to configure the database secrets engine for a MySQL database?
44Which TWO best practices should be followed when tuning secrets engine mounts?
45An e-commerce application integrates with Vault's transit secrets engine to encrypt sensitive customer data before storing it in a database. The operations team regularly rotates the encryption key (my-key) for compliance. Recently, after a rotation, some old ciphertexts could not be decrypted, causing data retrieval failures. The team checked the key configuration and found that the key version used for encryption (version 2) is still present, but decryption fails with an error: 'decryption key version is not available for decryption'. They verified that the ciphertext includes the key version. What is the most likely cause and resolution?
46A startup wants to use Vault to manage MySQL database credentials for their development environment. They have a single MySQL database and require that each application gets unique, short-lived credentials that are automatically rotated. The operations team enabled the database secrets engine, configured the MySQL connection, and created a role with a TTL of 1 hour. However, when an application requests credentials using the role, Vault returns an error: 'No more available leases on this role'. The team checks the role's configuration and sees that the 'max_ttl' is set to 1 hour and 'default_ttl' is also 1 hour. What is the most likely cause of this error?
47Refer to the exhibit. A user has a token with a policy that grants 'read' on 'secret/*'. The user attempts to read the secret at 'secret/data/app' using `vault kv get secret/data/app` but receives a '404 Not Found' error. The user can successfully list the engine at 'secret/' with `vault secrets list`. What is the most likely cause of the 404 error?
48A company uses Vault to store application configuration secrets for multiple teams. The Vault cluster is running in production and has the KV secrets engine enabled at the path 'secret/' using version 2. A DevOps engineer, using a Vault token with full admin access, creates a new secret at 'secret/data/team-a/app-config' using the CLI command 'vault kv put secret/team-a/app-config key=value'. The secret is intended for the CI/CD pipeline, which uses a token with a policy that grants 'read' capability on 'secret/data/*'. The pipeline is configured to read the secret by calling the Vault API at the path 'v1/secret/team-a/app-config'. The pipeline reports a 404 Not Found error. The pipeline engineer verifies that the token is valid and has the correct policy attached. All other secrets in the same path can be read successfully by the pipeline. What is the most likely cause of the 404 error?
49A platform team runs Vault 1.15 with an integrated storage backend. They have enabled the KV v2 secrets engine at the path 'apps/'. A developer deletes the secret at 'apps/data/webapp/db-creds' using `vault kv delete apps/webapp/db-creds`, then immediately reads it back with `vault kv get apps/webapp/db-creds`. What does the developer observe?
50A security engineer enables the Transit secrets engine at 'transit/' and creates an encryption key named 'payments' with `vault write -f transit/keys/payments`. The engineer then wants to rotate the key so that new data is encrypted with a new key version while existing ciphertext can still be decrypted. Which command accomplishes this without invalidating existing ciphertext?
51A cloud operations team needs Vault to issue short-lived credentials for an external MySQL database. They want Vault to create and revoke users dynamically based on a role. Which secrets engine should they enable and configure?
52An administrator is configuring a new PKI secrets engine at pki/ to issue TLS certificates for internal services. The security team requires that the intermediate CA certificate and its private key are generated inside Vault, and that the root CA remains offline. Which command should the administrator run to create the intermediate CA and generate a CSR for signing by the offline root?
53A security engineer is enabling the Transit secrets engine at the path 'transit/'. They need to encrypt data without ever exposing the plaintext key material to the application, and they want the ciphertext to be safely stored in an external database. They also require the ability to rotate the encryption key periodically without re-encrypting existing data. Which command correctly configures a new encryption key named 'orders' for this purpose?
54A security team is configuring the AWS secrets engine to issue dynamic IAM credentials. They want to allow Vault to assume an IAM role and generate temporary credentials for consumers. Which TWO configuration elements are required to enable this workflow? (Choose two.)
55A platform team wants to provide applications with short-lived AWS credentials that are automatically revoked when their lease expires, without managing long-term IAM users. They also need to allow the applications to assume a role for cross-account access. Which secrets engine should the team enable and configure?
56An organization uses the KV v2 secrets engine mounted at 'kv/'. They need to permanently delete all versions of a secret at path 'kv/apps/prod/db' and also remove all associated metadata, including custom metadata and version history. Which command should they run?
57A security engineer configures the Transit secrets engine at transit/ to encrypt application data. The application must be able to decrypt data but must not be able to create new encryption keys or rotate existing ones. Which policy snippet correctly grants only the required capability for the application's token?
58A cloud operations team needs to provide temporary, dynamically generated credentials for an AWS IAM user to a CI/CD pipeline. The credentials must be automatically revoked when the lease expires. They have configured the AWS secrets engine at 'aws/' with root credentials. Which configuration step is required to allow the pipeline to assume a specific IAM role and receive credentials?
59A platform team stores application configuration and credentials in a KV v2 secrets engine mounted at 'kv/'. A developer deleted version 3 of the secret 'kv/app/db' by running 'vault kv delete kv/app/db'. Two days later, the security team asks the developer to recover that version because it contained a valid certificate. The developer runs 'vault kv get -version=3 kv/app/db' and receives an error that the version has been deleted. What must the developer do to recover version 3?
60A database secrets engine is configured at database/ with a connection to PostgreSQL and a role named app-readonly. The role uses creation_statements to create a user with a random password and a TTL of one hour. An application retrieves credentials and uses them successfully, but after the lease expires the database user still exists and can log in. Which configuration change should the administrator make to ensure the user is removed when the lease ends?
61A cloud operations team wants to use Vault to generate dynamic credentials for an AWS RDS MySQL database. They have configured the database secrets engine and created a role named 'app-role' that maps to a database creation statement. A developer needs to obtain a username and password to connect to the database. Which command should the developer run to retrieve the dynamic credentials?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
You must enable and configure the correct secrets engine, then use the right path and parameters for its API. The single most important thing: know KV v2 stores data under secret/data/ and metadata under secret/metadata/, so wrong paths return 404.
The Courseiva VA-003 question bank contains 61 questions in the Compare and configure secrets engines domain, covering the 12% of the exam attributed to this domain in the official HashiCorp blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Compare and configure secrets engines domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included