Be able to read a Vault server config and identify the storage backend and seal type, and explain what happens to a standby node when it loses the active node. The single most important thing: distinguish the storage stanza from secrets engines, and know that standby nodes wait for the leader lease to expire before attempting to acquire leadership.
Start practicing
Explain Vault architecture — choose a session length
Free · No account required
Domain overview
This domain covers how Vault servers are deployed and operated: the storage backend, seal and unseal, HA with Consul or integrated storage, and the request path from client through the barrier to the storage layer. Questions are scenario-based, asking you to pick correct configuration stanzas, predict failover behavior, or identify a seal type from a config exhibit.
Exam objectives
The storage stanza: which backends are supported and that it is declared in the server config file
Seal and unseal mechanics, including auto-unseal via cloud KMS and recovery keys
HA coordination: active/standby roles, leader election, and redirect behavior for standby nodes
The request path: HTTP API, core, barrier encryption, and the storage backend
Confusing the storage stanza (physical backend) with a secrets engine or auth method mount, which are configured via the API, not the server config file.
Assuming a standby node takes over immediately after losing contact with the active node, rather than waiting for the leader lease to expire.
Mixing up auto-unseal seal types (e.g., AWS KMS, Azure Key Vault, Transit) or treating recovery keys as interchangeable with unseal keys.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A DevOps team is deploying Vault in a Kubernetes cluster. They want to ensure that when a pod starts, it can obtain a short-lived Vault token without human intervention. Which Vault architecture component should they use?
2A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?
3Which Vault component is responsible for encrypting data before storing it in the storage backend?
4A Vault cluster uses Integrated Storage. During a planned upgrade, the administrator wants to minimize downtime. Which upgrade strategy should be used?
5What is the purpose of the Seal/Unseal process in Vault architecture?
6Which TWO statements about Vault's Storage Backend are correct?
7A company deploys Vault in a production environment with three nodes using Integrated Storage (Raft). They have configured Performance Replication to a secondary datacenter. The primary datacenter experiences a complete outage. After restoring the primary, they promote the secondary to primary. However, they notice that some secrets written to the primary just before the outage are missing in the secondary. The replication status shows no errors. What is the most likely cause and correct action?
8A company is deploying Vault in a high-availability configuration across three data centers. They need to ensure that if the active Vault node fails, another node can take over without manual intervention. Which Vault feature should they configure?
9A Vault operator runs `vault status` and sees the output above. The Vault cluster is in production and currently unresponsive to API requests. What is the most likely cause of the unresponsiveness?
10Drag and drop the steps to configure Vault's PKI secrets engine to issue certificates into the correct order.
11Match each Vault audit device to its output destination.
12A small startup wants to run Vault in a development environment with minimal operational overhead. They need to store secrets in memory only, without any persistence. Which storage backend should they choose?
13A large enterprise runs Vault in a high-availability cluster with integrated storage (Raft). They notice that read requests are not being evenly distributed across nodes, causing some nodes to have high load. They want to offload read operations to standby nodes. What feature should they enable to achieve this?
14An organization has two Vault clusters in different geographic regions and wants to replicate secrets from the primary cluster to the secondary cluster for disaster recovery. Which Vault replication feature should they use?
15A developer wants to authenticate to Vault using a username and password without any external identity provider. Which authentication method should be enabled?
16During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access to the server and retrieves the unseal key. What is the best mitigation to prevent this scenario?
17Which TWO of the following are components of Vault's architecture? (Choose two.)
18A new Vault administrator unseals Vault using a single unseal key, but the Vault remains sealed. What is the most likely cause?
19A Vault cluster configured with auto-unseal using AWS KMS is deployed across two availability zones. After a network partition, the standby node remains sealed while the active node is unsealed and serving requests. What is the most likely reason the standby cannot unseal?
20A company is migrating from a file storage backend to Consul. Which Vault command should be used to move the data?
21A Vault cluster uses performance replication. A performance standby node is not responding to read requests. What is the most likely cause?
22A Vault cluster uses DR replication. The primary cluster fails, and the DR secondary is promoted to primary. After promotion, some secret data written to the primary shortly before the failure is missing on the new primary. What is the most likely reason?
23A company stores static secrets in Vault and requires that all data is encrypted at rest in the storage backend. Which Vault feature provides this encryption?
24After a security incident, the Vault administrator needs to change the encryption key used to encrypt data at rest. They have already rekeyed the unseal keys. What additional step is required to ensure new secrets are encrypted with a new key?
25Which TWO are core components of Vault's architecture?
26Refer to the exhibit. What seal mechanism is configured for this Vault instance?
27Refer to the exhibit. Based on the output from 'vault status', which statement is true?
28Refer to the exhibit. What operation was performed on the secret "mysecret"?
29A company requires that Vault data be continuously replicated from a primary data center to a secondary data center for disaster recovery. The secondary data center must be able to become writable in the event of a primary failure. Which Vault feature should they use?
30A Vault cluster uses Consul for HA. After a brief network partition, a standby node loses contact with the active node. What does the standby node do after a timeout?
31In a Vault HA cluster, which node is responsible for handling all write requests?
32What is the purpose of the `storage` stanza in a Vault server configuration file?
33A Vault cluster with three nodes using Integrated Storage (Raft) is healthy with one active and two standby nodes. A network partition isolates the active node. What will happen?
34A company uses Vault Enterprise with Performance Replication. The primary cluster is in us-east-1, and a secondary cluster is in eu-west-1. Clients in eu-west-1 report that they receive stale data when reading from the local secondary cluster's active node. What is the most likely cause?
35Which THREE are required for Vault to encrypt data at rest? (Choose three.)
36A Vault administrator wants to minimize the impact of a single node failure in a three-node Raft cluster. Which TWO actions will help? (Choose two.)
37Refer to the exhibit. A Vault administrator configures a three-node cluster with the above configuration on all nodes (with appropriate node_id). After starting all nodes, the administrator unseals node2 and node3. Node1 remains sealed. What will be the cluster state?
38Refer to the exhibit. A Vault administrator starts a Vault server and receives this error. What is the most likely cause?
39A company is running Vault in production with a single active node and two standby nodes using Integrated Storage. The operations team notices that after a network partition, one of the standby nodes becomes unavailable for a few minutes. Upon recovery, the node rejoins the cluster. However, the active node's performance degrades temporarily. What is the most likely cause?
40An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What is the best practice for configuring database roles to minimize the number of Vault mounts?
41A company is deploying Vault in a Kubernetes environment. Which three components are essential for a production-ready Vault on Kubernetes? (Choose three.)
42A company with strict security requirements uses Vault's Transit secrets engine to encrypt data in a microservices architecture. They have multiple applications that each require a unique encryption key. The security team wants to enforce key rotation every 30 days for all keys, and also require that keys be destroyed after they are no longer used. The application team is concerned that key rotation might cause downtime because applications need to re-encrypt data. The Vault architect needs to design a key management solution. What is the best approach?
43A DevOps team is setting up a Vault cluster for the first time. They plan to use AWS KMS for auto-unseal and Consul as the storage backend. As part of the architecture, which TWO components are essential for the Vault server to start and serve requests?
44A Vault operator deploys a single Vault server using Integrated Storage (Raft) as the storage backend. After initializing Vault, the operator notices that the server is marked as sealed and cannot serve requests. The operator has the unseal keys but wants to understand the architectural reason why Vault starts sealed after initialization. Which statement best explains why Vault is sealed immediately after initialization?
45A Vault operator is troubleshooting a newly deployed Vault server that is initialized but not yet unsealed. The operator needs to understand which component is responsible for holding the unseal keys and root token during the initialization process. Which statement accurately describes the role of the barrier in Vault's architecture?
46A Vault administrator is configuring a new Vault cluster with Integrated Storage (Raft). The administrator wants to ensure that the cluster can tolerate the failure of one node without data loss and that writes remain available. What is the minimum number of nodes required, and what is the recommended configuration for high availability?
47A Vault administrator manages a high-availability cluster with Integrated Storage (Raft) and three nodes. The cluster is healthy with one active node and two standby nodes. The administrator needs to perform a planned upgrade of the active node. Before stepping down, the administrator wants to ensure that the standby nodes are ready to take over and that no data loss occurs. Which action should the administrator take to safely transfer leadership?
48A security engineer is reviewing Vault's architecture and asks about the component that stores the actual encrypted data. Which Vault component is responsible for persisting encrypted secrets and configuration data?
49A security architect is designing a Vault deployment where the root key must never exist in plaintext outside of memory and must be split among five key holders. After initialization, the architect wants to ensure that no single administrator can unseal the vault alone. Which Vault architectural feature directly enforces this requirement?
50A Vault administrator is configuring a new Vault server and wants to ensure that audit logs capture every request and response, including the ability to detect tampering. Which Vault architectural component is responsible for providing this capability?
51A Vault operator is examining the architecture of a Vault cluster and wants to understand how client requests are routed to the active node. Which component is responsible for forwarding requests from standby nodes to the active node?
52A Vault cluster uses a Consul storage backend. During a maintenance window, the Consul cluster is taken offline for upgrades. Vault nodes remain running but become unresponsive. After Consul is restored, Vault nodes resume normal operation without manual intervention. Which Vault architectural property explains this behavior?
53A Vault administrator is configuring a new Vault server. The server will store secrets in a HashiCorp Consul cluster. The administrator writes a configuration file with the `storage` stanza pointing to Consul and starts Vault. After initialization and unsealing, the administrator notices that Vault is functioning but wants to ensure that the storage backend is highly available. Which statement about Vault's storage backend is accurate?
54A Vault administrator is explaining the role of the storage backend in Vault's architecture. A new team member asks where Vault stores its encrypted data and what the storage backend is responsible for. Which statement accurately describes the storage backend's role?
55A Vault administrator is troubleshooting a Vault cluster using integrated storage (Raft). The cluster has three nodes: node1 (active), node2 (standby), and node3 (standby). The administrator runs `vault operator raft list-peers` and sees that node3 is listed as a non-voter. What is the most likely reason for node3 being a non-voter?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to read a Vault server config and identify the storage backend and seal type, and explain what happens to a standby node when it loses the active node. The single most important thing: distinguish the storage stanza from secrets engines, and know that standby nodes wait for the leader lease to expire before attempting to acquire leadership.
The Courseiva VA-003 question bank contains 55 questions in the Explain Vault architecture domain, covering the 12% of the exam attributed to this domain in the official HashiCorp blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Explain Vault architecture domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included