Be able to write and read Vault HCL policies, resolve capability conflicts across multiple policies, and match paths correctly under KV v2. The single most important thing: know that Vault grants the union of capabilities, so least privilege requires tight, non-overlapping path rules.
Start practicing
Create Vault policies — choose a session length
Free · No account required
Domain overview
This domain covers authoring HCL policies in Vault: path matching, capabilities, and least-privilege design. Questions use drag-and-drop ordering for periodic service tokens, scenario picks for policy strategy, and capability-conflict resolution when multiple policies grant different rights on the same path. You must read path globs and wildcards precisely, including KV v2's secret/data/ prefix.
Exam objectives
Writing HCL policy paths with capabilities like create, update, read, delete, list, sudo
Path matching semantics: exact paths, * glob, + single-segment wildcard, and KV v2 data/metadata prefixes
Combining multiple policies on one path, where the union of capabilities applies
Creating and using periodic service tokens with vault token create -period and renew-self
Forgetting KV v2 paths need secret/data/ for data and secret/metadata/ for list/delete, so policies silently fail to match.
Assuming a deny capability overrides other policies; Vault takes the union of capabilities, and explicit deny only wins when set on the same path.
Confusing * (matches across path segments) with + (matches exactly one segment), causing over-broad or non-matching policy rules.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Drag and drop the steps to create and use a periodic service token in Vault into the correct order.
2A security administrator wants to create a policy that allows a service to renew its own token and list its own token capabilities, but not create new tokens. Which policy statements should be included?
3A Vault policy must allow a service to read secrets from "secret/data/app" and also be able to renew its own token. Which two policy statements are necessary and sufficient for this requirement? (Select two.)
4Refer to the exhibit. A user with this policy attempts to read the secret at path "secret/data/team-a/admin". What will happen?
5Refer to the exhibit. A user with this policy tries to write a new secret to "secret/data/production/db". What will happen?
6An administrator wants to create a policy that grants the ability to list all authentication methods enabled on the Vault server. Which path and capability are required?
7A Vault policy includes the following statement: path "secret/data/+/app" { capabilities = ["read"] }. Which paths would match this policy? (Assume KV v2)
8A policy must allow a user to revoke their own token. Which endpoint and capability are required?
9A Vault cluster has several policies. One policy, "app-policy", contains: path "secret/data/app/*" { capabilities = ["create", "update"] }. Another policy, "admin-policy", includes: path "secret/data/app/db" { capabilities = ["deny"] }. A token is attached with both policies. Can the token write to "secret/data/app/db"?
10An organization is implementing Vault policies for the first time. They want to ensure that policies are easy to manage and follow the principle of least privilege. Which approach should they take when creating policies?
11A Vault administrator needs to create a policy that grants users read access only to the secrets that belong to their own team. The team membership is stored in an external identity provider and mapped to Vault entity aliases. The administrator wants to use a templated policy that references the entity's metadata. Which policy syntax accomplishes this goal?
12A developer has a policy that grants 'create' capability on path 'secret/data/team/*'. They successfully create a new secret using 'vault kv put secret/data/team/db', but when they try to update the same secret with new data, they get a permission denied error. What is the most likely cause?
13An organization is creating Vault policies to manage access to secrets across multiple application teams. According to HashiCorp best practices, which two approaches should be taken when designing policies? (Choose two.)
14A company has deployed Vault with an LDAP auth method and has created entity aliases for all users. The company uses KV v2 secrets engine mounted at 'secret/'. Each team's secrets are stored under a path like 'secret/data/team_<team_name>/'. They have multiple teams (engineering, marketing, sales). Currently, an administrator manually creates a separate policy for each team, e.g., path "secret/data/team_engineering/*" { capabilities = ["read", "list"] }. This is becoming cumbersome as new teams are added. The administrator wants to create a single policy that dynamically grants read access to the secrets path corresponding to the user's team, which is stored in the entity's metadata as 'team'. The LDAP auth method is configured to sync group memberships and map to entity aliases, and the entity metadata is correctly populated. Which approach should the administrator take?
15A company uses Vault's Kubernetes authentication method to provide secrets to pods. Pods in the 'production' namespace need to read secrets from the path 'secret/data/app/prod'. The administrator has created a Vault role that maps the service account to a policy with capabilities ['read', 'list'] on path 'secret/data/app/*'. However, pods report 'permission denied' when trying to read the secrets. The administrator verifies that the service account has the correct Vault role attached and that the Vault token is being used correctly. What is the most likely cause?
16A Vault administrator is writing a policy for a monitoring tool that must be able to list all secrets under the 'secret/metadata/finance/' path and read the metadata of individual secrets, but must not read the secret data itself. Which policy snippet correctly grants only these permissions?
17A security team needs to grant a service account the ability to read secrets from the path 'secret/data/backup' and also to update the secret at that same path. Which policy correctly implements this requirement?
18A platform team stores KV v2 secrets under the mount 'kv-prod'. They need a policy that lets an application read only the metadata (not the underlying secret values) for every path under 'kv-prod/apps/', including the ability to enumerate keys. Which policy stanza satisfies this requirement?
19A Vault administrator is creating a policy for an application that needs to read a PKI role configuration and also generate certificates using that role. The PKI secrets engine is mounted at 'pki/'. Which policy snippet grants the minimum required capabilities?
20A junior administrator writes a policy file and applies it with 'vault policy write app-read app-read.hcl'. Later, a token created against this policy can read secrets it was never meant to see. The administrator wants to confirm exactly what the policy grants before rotating credentials. Which command displays the parsed, effective rules of the stored policy?
21A security team must delegate policy management to a group of operators without giving them the ability to grant themselves capabilities on protected paths such as 'sys/*' or 'auth/token/*'. Which combination of policy rules best implements this delegation safely?
22A team maintains a shared policy that many tokens reference. An administrator needs to add a new path stanza to the policy while preserving every existing rule, without risking a typo that silently removes access. Which approach is correct?
23A Vault administrator is building a policy for an application team that needs to manage PKI certificates issued by the 'pki_int' intermediate mount. The team must be able to generate new certificates from the 'web-server' role and revoke certificates, but must not be able to modify the role, generate a root CA, or configure the mount. (Choose two.)
24An administrator is troubleshooting a policy where a token unexpectedly has permission to read 'secret/data/finance/payroll' even though the attached policy only contains a statement for 'secret/data/hr/*'. The administrator confirms the policy is attached correctly and the path is not covered by any wildcard in it. What is the most likely explanation?
25A security team needs to create a Vault policy that allows a token to read secrets under 'secret/data/finance/*' but explicitly denies access to 'secret/data/finance/salaries'. The policy must also allow listing all secrets under 'secret/data/finance/'. Which policy definition correctly achieves this?
26A Vault administrator is writing a policy that uses a templated path to allow each user to access their own secrets. The policy is: path "secret/data/users/{{identity.entity.id}}/*" { capabilities = ["read", "list"] } When a user with entity ID "1234" attempts to read 'secret/data/users/1234/profile', they receive a permission denied error. The secret exists, and the user's token has this policy attached. What is the most likely reason for the failure?
Be able to write and read Vault HCL policies, resolve capability conflicts across multiple policies, and match paths correctly under KV v2. The single most important thing: know that Vault grants the union of capabilities, so least privilege requires tight, non-overlapping path rules.
The Courseiva VA-003 question bank contains 26 questions in the Create Vault policies domain, covering the 13% of the exam attributed to this domain in the official HashiCorp blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Create Vault policies domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included