Be able to create, inspect, renew, and revoke tokens, and explain how type, TTL, max_ttl, and policies limit a token's use. The key skill is predicting whether a token can be renewed and which policies apply at creation.
Start practicing
Assess Vault tokens — choose a session length
Free · No account required
Domain overview
This domain covers Vault token lifecycle: creation, types (service, batch), TTL and max_ttl, renewal, and policy attachment. Questions use exhibits, drag-and-drop ordering, and scenario prompts about `vault token create`, `vault token renew`, and accessor-based management to test whether you can predict token behavior and control its use.
Exam objectives
Distinguishing service tokens from batch tokens and their renewal and storage behavior
Reading a token's TTL, max_ttl, policies, and accessor via `vault token lookup`
Attaching policies at creation with `-policy` versus using token roles or periodic tokens
Ordering `vault operator init`, unseal key entry, and root token use on a new server
Assuming batch tokens can be renewed like service tokens; they are not renewable and must be recreated when they expire.
Confusing token TTL with max_ttl, so renewals fail once the token reaches its maximum lifetime.
Trying to attach policies after creation instead of using `-policy` at `vault token create` or a token role.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A DevOps team is using Vault tokens for authentication in CI/CD pipelines. They notice that tokens are often expired before the pipeline completes, causing failures. Which Vault feature should they use to address this without manual intervention?
2An application uses a Vault token with a policy that grants read access to secrets. The security team wants to ensure that if the application is compromised, the token cannot be used after a certain time even if the attacker has the token. What is the best approach?
3A developer created a token and wants to ensure that the token can only be used to read secrets from the 'secret/data/production' path. Which policy attachment approach should be used?
4A Vault administrator wants to allow a CI/CD pipeline to create short-lived tokens for deployment jobs. The pipeline itself authenticates with a periodic token. Which token type should the pipeline use to create tokens for jobs, considering the jobs need to be independent and not affected by the pipeline token's lifecycle?
5A Vault user wants to check the capabilities of their token on a specific path. Which command should they use?
6A security analyst discovers that a token used by a legacy application is still active long after the application was decommissioned. Which Vault feature should have been used to automatically expire tokens when the application is no longer running?
7An administrator wants to ensure that a token created by a user cannot be used after 24 hours, even if the user tries to renew it. What should the administrator do?
8A DevOps team is using Vault tokens with short TTLs for CI/CD jobs. They notice that some jobs fail intermittently with 'permission denied' errors even though the token policy grants the required capabilities. The token is created with a TTL of 10 minutes and renewed automatically by the client library. What is the most likely cause of the failures?
9Refer to the exhibit. A developer reports that a token they created using `vault token create -policy=my-policy -ttl=2h` is no longer working after 1 hour. The token lookup output shows the token details. What is the most likely cause?
10A token has the properties shown in the exhibit. A user attempts to use this token to write a secret to 'secret/data/myapp'. The token fails with a permission denied error. What is the most likely cause?
11Drag and drop the steps to initialize and unseal a Vault server for the first time into the correct order.
12Drag and drop the steps to perform a Vault disaster recovery using the replication feature into the correct order.
13Match each Vault auth method to its authentication mechanism.
14An administrator needs to revoke a token but wants to keep all child tokens that were created using this token as the parent. Which revocation operation should be used?
15A security audit requires tracking token usage without exposing the token value itself. Which token attribute should be logged?
16An administrator receives an access denied error when trying to use the token accessor to revoke a token. The administrator's token has the following policy capabilities: path "auth/token/revoke-accessor" { capabilities = ["create", "update"] }. What is the issue?
17A token is created with policies 'default' and 'web-app'. Later, a parent token's policy is updated to add 'logging'. The child token's policies are not updated. What will happen when the child token is used?
18Which TWO of the following are true about token accessors?
19Which TWO statements are true about batch tokens?
20A token with the above policy attempts to look up its own token by calling the accessor endpoint. What will happen?
21A security team wants to ensure that tokens can be revoked immediately if a compromised token is detected, even if the token ID is unknown. Which token feature should they use?
22An admin creates a token with TTL=48h and explicit_max_ttl=120h. The token is renewed every 24h. After 10 days, will the token still be valid?
23Which token type should be used for short-lived credentials that do not need to be renewed?
24A Vault cluster has a token with the following policy: path "secret/data/dev/*" { capabilities = ["read", "list"] }. The token is used to read a secret at "secret/data/dev/password". The read succeeds. Later, the token tries to read "secret/data/prod/password". What happens?
25What is the purpose of a token's "period" attribute?
26Where can you view a list of all active tokens in Vault?
27An application uses a periodic token with period=24h. The application renews every 12h. After 48h, the token is still valid. After 72h, the token is still valid. What is the maximum lifetime of this periodic token?
28Refer to the exhibit. A user attempts to renew the token after 20 hours. What will happen?
29Refer to the exhibit. A token has this policy. Which action can the token perform?
30A user's token was revoked by an administrator, but the user can still read secrets from a KV v1 secrets engine. What is the most likely reason?
31A DevOps engineer needs to create a token that can only read secrets under the path 'secret/engineering'. What is the recommended approach?
32A token with a policy granting 'write' on 'secret/team-alpha/*' is unable to write to 'secret/team-alpha/db-creds' in a KV v2 engine. What is the most likely cause?
33An administrator wants to audit token usage without exposing the actual token IDs to auditors. Which approach should they use?
34A user forgets to renew their token before it expires. What happens to the token and its associated leases?
35A token with a policy that explicitly denies 'read' on 'secret/engineering/private' is issued. The same token also has another policy that grants 'read' on 'secret/engineering/*'. What is the result when the token tries to read 'secret/engineering/private'?
36An administrator creates a service token with a TTL of 1 hour and a max TTL of 24 hours. The token is renewed once after 55 minutes. What happens to the token after 24 hours from creation?
37A CI/CD pipeline needs to generate thousands of short-lived tokens each day for jobs that run for at most 5 minutes. The tokens should not be renewable or revocable individually. Which token type should be used?
38A Vault operator runs 'vault token lookup s.abc123' and sees that the token type is 'service', renewable is true, but the ttl is 30m and creation_ttl is 1h. The token has num_uses set to 0. What is the most likely explanation for the discrepancy between ttl and creation_ttl?
39A developer needs to manually revoke a token but only knows its accessor. Which Vault API endpoint can be used to revoke the token using only the accessor?
40Which TWO of the following are valid uses of a token accessor? (Select exactly 2 options.)
41Refer to the exhibit. A developer tries to renew a token and receives this error. The token was created using 'vault token create -type=batch'. What is the most likely cause of this error?
42A company uses Vault to issue tokens for short-lived tasks. They have configured a token role with 'period' set to 30 minutes and 'explicit_max_ttl' set to 24 hours. Tokens are created using the role and are expected to be renewed every 30 minutes by the tasks. However, after a few renewals, the Vault audit logs show that a token was renewed but then immediately expired. The task that was using the token failed. What is the most likely reason for this behavior?
43An administrator is reviewing Vault token policies and wants to ensure that tokens created by a specific application cannot be renewed and have a fixed lifetime. Which two token configurations should be applied?
44A company runs multiple microservices in a Kubernetes cluster. Each microservice authenticates to Vault using a service token created via the token auth method. The tokens are created with a default TTL of 72h, a max TTL of 168h, and renewable set to true. The services are configured to renew their tokens when the remaining TTL drops below 24h. Recently, some tokens have been expiring prematurely, causing service outages. Upon investigation, you find that the expired tokens were created with a role that includes explicit_max_ttl = 72h. The services see the TTL decreasing normally, but then it jumps to zero even though the services attempted renewal. What is the most likely cause and correct action?
45A platform team uses Vault to issue short-lived tokens to external contractors. The security policy requires that every contractor token must be traceable back to the contractor's identity, and that a token can never be renewed beyond its initial TTL. The team creates tokens with the default settings. A contractor later reports that their token stopped working after its TTL expired, but they were able to renew it several times before that. Which token parameter should the team have configured to enforce the policy?
46An application team is using a batch token to authenticate to Vault for a long-running data processing job. The token was created with a TTL of 8 hours and no explicit max TTL. After 4 hours, the application attempts to renew the token but receives an error. What is the most likely reason for the renewal failure?
47A platform team runs a nightly batch job that authenticates to Vault with the AppRole auth method and receives a token with a 30-minute TTL. The job occasionally overruns and hits 'permission denied' errors mid-run. The team wants the token to stay valid as long as the job keeps working, without the job re-authenticating. Which token attribute should the AppRole role be configured with when the token is issued?
48A security engineer needs to create a batch token that will be used by an external system for a one-time operation. The token must be self-contained and not stored in Vault's storage backend. Which token type should be used, and what is a key limitation of that token type?
49A security engineer creates a service token with a TTL of 1 hour and a max TTL of 4 hours. The token is used by an application that renews it every 30 minutes. After 3 hours, the engineer revokes the token using its accessor. What happens to the token's child tokens?
50An operator creates a batch token for a one-time database migration. The migration finishes, and the operator wants the token to be unusable immediately, even before its TTL expires, and wants to confirm the token no longer appears in the token list. Which Vault command accomplishes this?
51A Vault administrator needs to delegate the ability to create tokens to a user without granting full administrative privileges. Which token type should the administrator create for the user to allow them to create tokens with specific policies?
52An administrator creates a token with the following parameters: `vault token create -ttl=1h -explicit-max-ttl=2h`. The token is then renewed once for 1 hour. What is the maximum remaining time the token can be renewed for after this first renewal?
53A developer authenticates with the userpass auth method and receives a token. The developer needs to perform a sensitive operation but the token lacks the required policy. Before asking an administrator, the developer wants to determine whether their current token is permitted to update the secret at secret/data/payments. Which command should the developer run?
54A security team wants to audit all tokens created by a specific authentication method. They need to list all tokens and retrieve details such as creation time, TTL, and policies. Which Vault command should they use?
55A new engineer authenticates to Vault and receives a token. The engineer's manager asks which policies are attached to that token and when it will expire, so the team can plan a permissions review. Which command should the engineer run to display this information about their own token?
56An operator runs `vault token create -policy=app -ttl=1h -explicit-max-ttl=2h` and then checks the token's properties with `vault token lookup`. The token is renewable. A developer asks whether the token can be kept alive indefinitely by renewing it every 30 minutes. What should the operator tell the developer?
57A security engineer is troubleshooting why a Vault token cannot be renewed. The token was created with a TTL of 4 hours and is renewable. After 2 hours, the engineer attempts to renew it using `vault token renew <token>` but receives the error: "lease not found". The engineer confirms the token is still valid and not expired. Which of the following is the most likely cause?
58A Vault administrator is reviewing token behaviors and needs to understand which actions are possible with a token's accessor. Which two statements about token accessors are true? (Choose two.)
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to create, inspect, renew, and revoke tokens, and explain how type, TTL, max_ttl, and policies limit a token's use. The key skill is predicting whether a token can be renewed and which policies apply at creation.
The Courseiva VA-003 question bank contains 58 questions in the Assess Vault tokens domain, covering the 13% of the exam attributed to this domain in the official HashiCorp blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Assess Vault tokens domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included