Be able to list, renew, and revoke leases with the vault lease CLI, explain why expired leases still appear, and adjust lease TTLs on secrets engines. The key skill is knowing what actually reduces active lease counts: revocation, not waiting for expiry.
Start practicing
Manage Vault leases — choose a session length
Free · No account required
Domain overview
This domain covers Vault lease lifecycle management: listing and revoking leases, understanding why expired leases persist until cleanup, tuning lease TTLs on secrets engines, and configuring audit devices that record lease operations. Questions test whether you can reason about lease counts, TTL precedence, and audit log ordering rather than recite definitions.
Exam objectives
Using vault lease list, vault lease revoke, and vault lease renew against lease IDs
Why expired leases remain visible until Vault's expiration manager cleans them up
Tuning lease TTLs and max TTLs on secrets engines such as PKI and KV
Configuring audit devices with vault audit enable file and reading audit log entries
Assuming expired leases disappear immediately; they linger until the expiration manager revokes them, so listing shows stale entries.
Confusing lease revocation with secret deletion, or forgetting that revoking a lease can revoke child leases and tokens.
Setting a lease TTL on a secrets engine but ignoring max TTL, which caps renewals and forces re-issuance.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A DevOps team is using Vault's database secrets engine to generate dynamic credentials for a PostgreSQL database. They notice that the lease duration is set to 24 hours, but security policy requires that credentials expire after 1 hour. What should the team do to enforce the 1-hour expiration without changing the default lease TTL for all secrets?
2An organization uses Vault to issue certificates via the PKI secrets engine. They have set the default lease TTL on the PKI mount to 72h, and the role's ttl to 24h. A user requests a certificate with a requested TTL of 48h. What will be the actual TTL of the issued certificate?
3Which TWO of the following actions can reduce the number of active leases in Vault? (Select two.)
4An organization uses Vault's AWS secrets engine to generate temporary IAM credentials. The Vault administrator has set the default lease TTL on the AWS mount to 15 minutes. A developer creates a role with role TTL of 30 minutes and explicit max TTL of 1 hour. Which TWO statements are true regarding the lease behavior for credentials generated under this role?
5Drag and drop the steps to configure Vault's audit logging to a file into the correct order.
6Match each Vault term to its definition.
7An administrator notices that after revoking a specific lease, the underlying database credential is still accessible. What is the most likely cause?
8What command is used to view the remaining time on a lease?
9A Vault cluster is sealed. An operator attempts to renew a lease but gets an error. What is the most likely error?
10A developer wants to ensure that their application automatically renews its secret leases before expiration. Which approach is recommended?
11Which of the following best describes a Vault lease?
12An operator runs vault lease list and sees many expired leases. Why are expired leases still listed?
13What happens when a lease reaches its TTL?
14After a Vault migration, some leases are no longer valid and cause errors. What is the best way to force a cleanup of all leases under a specific mount without affecting other mounts?
15Which two commands can be used to manually revoke leases? (Choose two.)
16Which three statements about lease renewal are correct? (Choose three.)
17Which two of the following are valid lease operations? (Choose two.)
18A security team wants to ensure that database credentials generated by Vault are never renewed and have a fixed lifespan of 30 minutes. They configure the role with default_ttl=30m and max_ttl=30m, and set renewable=false. However, they find that some users are able to renew the leases anyway. What could be the reason?
19A Vault administrator wants to configure a role for dynamic secrets with a default TTL of 1 hour and a max TTL of 4 hours. They also want to allow renewal but only up to the max TTL. Which configuration achieves this?
20A Vault operator accidentally revoked a token that was used to lease many database credentials. What happens to the leases associated with that token?
21A Vault operator wants to manage lease durations for secrets issued by a PKI secrets engine. Which two actions can they take to affect the lease duration of certificates?
22A platform team runs a Vault cluster with a transit secrets engine mount at transit/. An application holds a token with a policy granting only "update" on transit/encrypt/orders and "read" on transit/keys/orders. The application's token has a TTL of 1h with a max_ttl of 4h, and it renews itself every 30 minutes using the token renewal endpoint. After roughly four hours of continuous operation, the application's API calls begin failing with a permission denied error even though the token was renewed successfully each time. Which Vault behavior explains this failure?
23A platform engineer has issued dynamic AWS credentials through Vault's AWS secrets engine and wants to extend the usable lifetime of that credential before it expires. Which Vault CLI command allows the engineer to request additional time on the lease?
24A security engineer is onboarding a new application team to Vault. The team needs to understand how Vault manages the lifecycle of secrets issued by the database secrets engine. The engineer explains that Vault attaches a lease to dynamic secrets and that the lease defines the secret's validity period. Which statement accurately describes the relationship between a lease and a dynamic secret?
25A security team must immediately invalidate every dynamic database credential issued under a specific role named app-readonly, across all database mounts, without knowing individual lease IDs. Which Vault command accomplishes this?
26A Vault admin needs to revoke all leases under the `database/creds/readonly` path without revoking leases from other paths. Which command should the admin use?
27A platform team runs a Vault cluster where many applications obtain dynamic AWS credentials from the aws secrets engine. During an incident, an operator needs to stop all credential usage tied to a compromised IAM role without disrupting other roles. The operator has a root token and wants to revoke every lease associated with that specific role. Which approach accomplishes this?
28An operator inspects a Vault policy and finds a rule granting read on database/creds/reporting. Applications using tokens bound to this policy can fetch credentials but receive permission denied when they attempt to extend them. Which capability must be added to the policy to allow lease renewal?
29A platform team runs Vault with a transit secrets engine mount at transit/. An application requests a new data encryption key with a 30-minute TTL, and the returned lease_id is recorded by the app. Twenty minutes later, the app calls the renew endpoint for that lease. The mount was configured with max_lease_ttl of 1h. What is the maximum TTL the lease can be extended to by this renewal?
30An operations team manages Vault leases for dynamic database credentials. They need to extend the life of an active lease without issuing a new credential, and they also want to confirm the lease's remaining time before doing so. Which two commands or operations should they use? (Choose two.)
31A Vault administrator is designing a disaster-recovery runbook for dynamic secrets and needs to document the ways leases can be terminated or cleaned up. Which two statements correctly describe lease revocation behavior in Vault? (Choose two.)
32A role in Vault's database secrets engine is configured with default_ttl=30m and max_ttl=2h. An application requests credentials and then successfully renews the lease twice, each time receiving the full default TTL. What is the longest total time the credential can remain valid from its original issue time?
33A financial services company uses Vault's PKI secrets engine to issue short-lived TLS certificates to internal services. An administrator configured the PKI role with default_ttl=24h and max_ttl=72h. A service requests a certificate with an explicit TTL of 120h. What will Vault do in this situation?
34An admin is troubleshooting a Vault cluster where some dynamic secrets leases are not being revoked after their TTL expires. The admin confirms that the TTLs are set correctly. Which Vault component is responsible for revoking expired leases?
35A Vault administrator is investigating a production incident where an application's dynamic database credentials stopped working earlier than expected, even though the lease had not reached its maximum TTL. The administrator reviews the role configuration and finds default_ttl=1h and max_ttl=24h. The application typically renews its lease every 30 minutes. Which factor most likely explains why the credentials became invalid before max_ttl was reached?
36A Vault admin wants to revoke a specific lease for a dynamic database credential. The admin has the lease ID. Which command should the admin use?
37A Vault administrator is troubleshooting a batch of revoked database credentials. An application reported that its lease stopped working even though the application had been renewing it every few minutes. Reviewing the mount configuration, the administrator sees default_lease_ttl set to 15m and max_lease_ttl set to 2h. The application log shows successful renewals until roughly the two-hour mark, after which the renew call returned an error and the credential failed. What is the most likely explanation?
38A Vault operator discovers that a service account token was compromised, and that token had created several dynamic database credentials across multiple roles. The operator needs to invalidate every lease created by that token as quickly as possible rather than waiting for each lease to expire. Which action accomplishes this?
Be able to list, renew, and revoke leases with the vault lease CLI, explain why expired leases still appear, and adjust lease TTLs on secrets engines. The key skill is knowing what actually reduces active lease counts: revocation, not waiting for expiry.
The Courseiva VA-003 question bank contains 38 questions in the Manage Vault leases domain, covering the 13% of the exam attributed to this domain in the official HashiCorp blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Manage Vault leases domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included