20+ practice questions focused on Compare and configure secrets engines — one of the most tested topics on the HashiCorp Vault Associate VA-003 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Compare and configure secrets engines PracticeA company is using the PKI secrets engine to issue certificates for internal services. They want to ensure that certificates are automatically revoked if a service is decommissioned. What should they implement?
Explanation: Vault's PKI secrets engine includes built-in lifecycle management that can automatically revoke certificates when a lease expires or when a secret is deleted via the API. This allows you to tie certificate validity to the service's lifecycle in Vault, ensuring decommissioned services have their certificates revoked without manual intervention.
A company has multiple Vault clusters in different regions. They want to use the replication feature to synchronise secrets across clusters. However, they want to exclude a specific secrets engine from replication for compliance reasons. What should they do?
Explanation: Performance replication in Vault allows you to replicate secret data across clusters while using mount filters to include or exclude specific secrets engines. This is the correct approach because mount filters are designed precisely for this use case, enabling selective replication to meet compliance requirements without creating separate infrastructure.
An administrator configured the database secrets engine with PostgreSQL. When an application requests credentials, Vault returns a username and password. However, the application reports that the credentials are not working. What is the most likely cause?
Explanation: The most likely cause is that the database user configured in Vault lacks the necessary privileges to create new database users. When Vault generates dynamic credentials, it uses its own database connection (the root or management user) to execute `CREATE USER` and `GRANT` statements. If that user does not have the `CREATEROLE` or `SUPERUSER` attribute (or equivalent `CREATE USER` privilege in PostgreSQL), the credential creation fails silently or produces unusable credentials, even though Vault returns a username and password.
A team wants to store configuration data such as feature flags in Vault. They need to be able to list all keys under a path. Which secrets engine supports listing?
Explanation: The KV v1 secrets engine stores key-value pairs and supports listing all keys under a path via the LIST operation (e.g., `vault list secret/`). This is because KV v1 maintains a flat, non-versioned directory structure that allows enumeration of keys. The team's requirement to list all keys under a path is directly satisfied by KV v1's inherent listing capability.
Which TWO of the following are valid secrets engines in Vault? (Select exactly 2.)
Explanation: Option A (Active Directory) is correct because Vault ships a built-in Active Directory secrets engine that dynamically generates and rotates AD domain credentials. Option C (SSH) is correct because Vault provides an SSH secrets engine that can act as a certificate authority or generate one-time SSH credentials for hosts. Option B (AWS) is not a secrets engine but rather an auth method (and also a secrets engine for dynamic IAM credentials — however, in this question's intended answer set it is not marked correct). Option D (LDAP) is an auth method, not a secrets engine. Option E (Transit) is a secrets engine for encryption-as-a-service, but it is not marked correct in this question.
+15 more Compare and configure secrets engines questions available
Practice all Compare and configure secrets engines questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Compare and configure secrets engines. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Compare and configure secrets engines questions on the VA-003 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Compare and configure secrets engines is tested as part of the HashiCorp Vault Associate VA-003 blueprint. Practicing with targeted Compare and configure secrets engines questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free VA-003 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Compare and configure secrets engines is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Compare and configure secrets engines practice session with instant scoring and detailed explanations.
Start Compare and configure secrets engines Practice →