VA-003 Compare and configure secrets engines • Timed 30 Questions
This is a timed practice session. You have 30 minutes to answer 30 questions — approximately 1 minute per question, matching real VA-003 exam pace. Answer every question before time expires.
Time remaining
30:00
Exam-pace drill
Allow 1 minute per question. On the real VA-003 exam you have approximately 72 seconds per question — this session trains you to maintain that pace under pressure.
A SaaS startup uses Vault to manage secrets for their microservices architecture. They have enabled the KV v2 secrets engine at 'secret/' and the database secrets engine at 'database/'. Developers often need to read application configuration from 'secret/app/config' and database credentials from 'database/creds/app-role'. Recently, the security team mandated that all secrets must be encrypted at rest using Vault's seal mechanism. They configured Vault to use AWS KMS as the seal. After enabling the seal, they noticed that reading from 'secret/app/config' still works, but reading from 'database/creds/app-role' returns an error: 'Error making API request: Code: 500. Errors: * 1 error occurred: * failed to decrypt data'. What is the most likely cause?
30 minute time limit — choose an answer to begin.
30 questions · 30 minute exam-pace drill.