VA-003 Create Vault policies • Complete Question Bank
Complete VA-003 Create Vault policies question bank — all 0 questions with answers and detailed explanations.
Refer to the exhibit.
```hcl
path "secret/data/kv-v2/engineering/*" {
capabilities = ["read", "list"]
}
path "secret/metadata/kv-v2/engineering/*" {
capabilities = ["read", "list"]
}
path "sys/policies/acl/engineering" {
capabilities = ["read"]
}
```Drag a concept onto its matching description — or click a concept then click the description.
Write a secret
Read data at a path
Write data or invoke an endpoint
Delete a secret or path
List keys under a path
# Vault policy snippet
path "transit/encrypt/app-key" {
capabilities = ["create", "update"]
}
path "transit/decrypt/app-key" {
capabilities = ["create", "update"]
}A DevOps team has configured a Vault policy to allow reading secrets from the 'secret/data/engineering' path. The policy contains:
path "secret/data/engineering/*" { capabilities = ["read", "list"]
}
However, when a user attempts to read a secret at 'secret/data/engineering/db/password', they receive a permission denied error. What is the most likely cause?
path "secret/data/engineering/*" {
capabilities = ["read", "list"]
}
path "secret/data/engineering/projects/*" {
capabilities = ["create", "update"]
}A Vault administrator is creating a policy named 'app-read' that must allow reading secrets at path 'secret/data/app/config'. The policy is written in HCL as:
path "secret/data/app/config" { capabilities = ["read"]
}
The administrator saves this to a file 'app-read.hcl' and runs `vault policy write app-read app-read.hcl`. However, when a token with this policy attempts to read the secret, it receives a 403 permission denied error. The secret exists at that path. What is the most likely cause?
Drag or tap steps into the slots.
path "secret/data/team-a/*" {
capabilities = ["read", "list"]
}
path "secret/data/team-a/admin" {
capabilities = ["deny"]
}$ vault policy read my-policy
path "secret/data/production/*" {
capabilities = ["read"]
}
path "secret/data/staging/*" {
capabilities = ["create", "update"]
}A Vault administrator is writing a policy that uses a templated path to allow each user to access their own secrets. The policy is:
path "secret/data/users/{{identity.entity.id}}/*" { capabilities = ["read", "list"]
}
When a user with entity ID "1234" attempts to read 'secret/data/users/1234/profile', they receive a permission denied error. The secret exists, and the user's token has this policy attached. What is the most likely reason for the failure?