Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.
Start practicing
Utilize Vault CLI and API — choose a session length
Free · No account required
Domain overview
This domain covers driving Vault from the terminal and over HTTP: logging in to auth methods, reading and writing secrets, and managing engines. Questions are scenario-based, asking you to pick the correct CLI command or API path, add a missing policy capability, or order setup steps for an engine like Transit.
Exam objectives
Authenticating with `vault login -method=userpass username=...` against the userpass auth method
Adding `delete` (and often `destroy`/`update`) capabilities to a policy for KV v2 paths
Writing KV v2 secrets with `vault kv put secret/myapp password=pass123`
Ordering Transit engine steps: enable, create key, encrypt, decrypt via CLI or API
Using `vault write secret/myapp` instead of `vault kv put` for KV v2, which bypasses versioning and metadata handling.
Forgetting that KV v2 paths include `data/` (and `metadata/`) in policies and API calls, unlike KV v1.
Assuming `read` capability alone allows deletion; `delete` must be explicitly granted in the policy.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An admin wants to list all enabled authentication methods using the Vault API. Which curl command is correct?
2A user wants to log in using the userpass auth method with username 'jdoe' and password 'p@ssw0rd'. What is the correct API endpoint and request?
3Which THREE of the following are correct about using the Vault API to read a secret from KV v2 engine?
4Which TWO of the following Vault CLI commands can be used to write data to Vault?
5A company uses Vault to manage secrets for multiple applications. A new security policy requires that all human users authenticate using LDAP and that all machine-to-machine authentication uses AppRole. An administrator has configured an LDAP auth method at 'ldap/' and an AppRole at 'approle/'. The administrator creates a role 'web-app' with a secret ID TTL of 30 days and a token TTL of 1 hour. After deploying the web application, the application successfully logs in using the AppRole role ID and secret ID, retrieves a token, and reads secrets. However, after 1 hour, the application begins receiving 'permission denied' errors when trying to read secrets. The application logs show that it is using the same token obtained during initial login. Which action should the administrator take to resolve this issue?
6Drag and drop the steps to set up Vault's Transit secrets engine for encryption/decryption into the correct order.
7Match each Vault policy capability to its permission.
8A developer wants to authenticate to Vault using LDAP credentials. Which CLI command should they use?
9An operator needs to create a token role named 'web-app' with a default TTL of 24 hours. Which API request is correct?
10A user receives 'permission denied' when running 'vault write secret/data/myapp value=123'. The user's token has a policy that includes 'path "secret/data/*" { capabilities = ["read", "list"] }'. What is the most likely cause?
11An administrator wants to mount the AWS secrets engine at 'aws' path using the API. Which request is correct?
12An operator needs to create a periodic token with a period of 36 hours. Which command should they use?
13A user wants to view information about their current token, including its policies and TTL. Which TWO CLI commands can be used?
14An operator needs to perform token lifecycle operations. Which THREE API endpoints are valid for token-related actions?
15Refer to the exhibit. A user with this policy attempts to read 'secret/data/team/admin'. What will happen?
16Refer to the exhibit. A user wants to write a secret 'db_password' with value 's3cret' to this secrets engine. Which CLI command should be used?
17An administrator wants to retrieve the value of a secret stored at the path 'kv/secret/mykey' using the Vault CLI. Which command should they use?
18A user attempts to read a secret at path 'secret/data/app' and receives a 403 Forbidden error. What is the most likely cause?
19An administrator needs to securely provide a one-time use token to a remote service using Vault response wrapping. Which CLI flag or command should they use?
20Which Vault CLI command is used to authenticate a user with a username and password to the userpass auth method?
21An administrator has created a policy file named 'app-policy.hcl'. Which command should they use to upload this policy to Vault?
22A DevOps engineer needs to create a token with a specific policy attached using the Vault API. Which API endpoint and request should they use?
23Which TWO statements are true when troubleshooting a failed Vault CLI command?
24Which THREE are benefits of using Vault response wrapping?
25The CLI command returns a 403 error. What is the most likely cause?
26A user with this policy wants to delete secrets under the 'team/' path. Which additional capability must be added?
27An administrator wants to write a secret 'myapp' with value 'password=pass123' to the KV v2 secret engine mounted at 'secret/'. Which command should they use?
28An application needs to read a secret using the Vault API after authenticating with an AppRole RoleID and SecretID. The application has already obtained a Vault token. Which API endpoint should be called to read a secret at 'secret/data/myapp' with the token?
29Which TWO of the following are valid methods to authenticate to Vault using the CLI without using a token? (Choose two.)
30Which THREE of the following are true about using the Vault API with response wrapping? (Choose three.)
31A team is migrating from a monolithic application to microservices. Each microservice needs to authenticate to Vault using its own AppRole. The security team wants to enforce that each AppRole can only read secrets from its own dedicated path (e.g., service-a can only read from 'services/service-a/*', service-b from 'services/service-b/*'). They have created the AppRoles and policies. However, during testing, they notice that service-a can read secrets from service-b's path. The administrator checks the policy for service-a and sees it has a 'capabilities' list on 'services/service-a/*' and also 'services/service-b/*' by mistake. They correct the policy, but the issue persists. What is the most likely reason that service-a still has access?
32An operator has authenticated to Vault and wants to inspect the metadata of the currently active token, including its accessor, policies, and creation time, without exposing the token's secret value. Which CLI command returns this information?
33An application authenticates to Vault using the AppRole auth method and needs to retrieve the token's remaining TTL and renewable status programmatically. The application already has a valid token and calls the lookup-self endpoint. Which response fields should it read to determine whether the token can be renewed and how long it remains valid?
34A cloud engineer is scripting against the Vault HTTP API and must authenticate, then read a KV v2 secret, using only `curl`. Which TWO request elements are required for the read to succeed? (Choose two.)
35A security engineer needs to authenticate a CI pipeline to Vault using the AppRole auth method from the CLI without a pre-existing token. The engineer has the role_id and a wrapped secret_id. Which TWO commands are required to complete the login and obtain a usable token? (Choose two.)
36A developer wants to inspect the metadata of the current Vault token, including its attached policies, TTL, and whether it is renewable, using a single CLI command. Which command should the developer run?
37A CI pipeline authenticates to Vault using the AppRole auth method and needs to obtain a token non-interactively. The pipeline has a role_id and a secret_id but cannot use an interactive login prompt. Which TWO methods can the pipeline use to authenticate and receive a token? (Choose two.)
38A Vault operator needs to enable the `userpass` auth method at the path `auth/legacy-userpass` and then create a user named `svc-backup` with a password, all from a CI script. Which single command correctly enables the auth method at that custom path?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to run the right CLI command or API call for login, KV v2 reads/writes, and engine setup, and to read a policy to spot a missing capability. The most important thing: match the command to the mount and engine version, especially KV v2's `kv put` and `data/` paths.
The Courseiva VA-003 question bank contains 38 questions in the Utilize Vault CLI and API domain, covering the 12% of the exam attributed to this domain in the official HashiCorp blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Utilize Vault CLI and API domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included