200-901 Application Deployment and Security Practice Question
A developer needs to retrieve a secret stored in HashiCorp Vault from a CI job. The Vault administrator has enabled the AppRole auth method. Which sequence correctly authenticates and reads the secret using the Vault HTTP API?
⚠ Common exam trap
Watch out — candidates often confuse the AppRole `secret_id`, which is an authentication credential, with a Vault client token used to authorize secret reads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
POST to `/v1/auth/approle/login` with `role_id` and `secret_id` to obtain a client token, then GET the secret path with the `X-Vault-Token` header set to that token.
AppRole is a machine-oriented auth method that exchanges a `role_id` and `secret_id` for a short-lived Vault token. That token must then be supplied on the secret read. The other options either skip authentication, misuse the `secret_id` as a token, or misunderstand how Vault secret reads work, so only the login-then-read sequence succeeds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the `secret_id` as the value of the `X-Vault-Token` header and GET the secret path.
Why it's wrong here
The `secret_id` is not a Vault token and cannot be used in the `X-Vault-Token` header. Only a token issued by an auth method, such as the one returned from an AppRole login, is valid there. Using the `secret_id` directly results in an invalid token error and exposes the credential in headers unnecessarily.
- ✓
POST to `/v1/auth/approle/login` with `role_id` and `secret_id` to obtain a client token, then GET the secret path with the `X-Vault-Token` header set to that token.
Why this is correct
AppRole authentication requires exchanging a `role_id` and `secret_id` at the login endpoint for a Vault client token. That token is then presented in the `X-Vault-Token` header on subsequent requests. This is the documented flow and correctly separates authentication from secret retrieval, making it the right sequence for the CI job.
- ✗
GET the secret path directly with a `role_id` query parameter and no token header.
Why it's wrong here
Vault does not accept `role_id` as a query parameter for reading secrets. Every secret read requires an authenticated client token in the `X-Vault-Token` header. Without a token, the request is unauthenticated and returns a permission denied error, so this sequence cannot work regardless of AppRole configuration.
- ✗
POST the `secret_id` to the secret path to unwrap it, then read the response body for the secret value.
Why it's wrong here
The `secret_id` is an AppRole credential, not a secret path payload, and Vault does not unwrap secrets by posting a `secret_id` to an arbitrary path. Secret reads use GET on the path with a token. This sequence misunderstands both the auth flow and the KV read semantics, so it would fail.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.