Vault Enterprise Hsm Integration Practice Question
You are using Seal Wrap. If you perform a 'vault operator rekey', what happens to the keys protected by Seal Wrap?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The new KEK is generated and wrapped by the HSM.
When rekeying, Vault re-encrypts the Master Key/KEK. If Seal Wrap is enabled, the HSM is used to perform the cryptographic operations for the new key, ensuring the chain of protection remains intact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Seal Wrap is disabled and must be manually re-enabled.
Why it's wrong here
Seal Wrap settings persist through rekey operations.
- ✓
The new KEK is generated and wrapped by the HSM.
Why this is correct
Vault ensures the new KEK is cryptographically protected by the HSM.
- ✗
Seal Wrap keys are excluded from the rekey process.
Why it's wrong here
The root of trust is updated.
- ✗
The keys must be manually unwrapped and re-wrapped.
Why it's wrong here
Vault performs this automatically.
About these practice questions
Courseiva writes every Vault Enterprise question from scratch — 184 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official HashiCorp exam blueprint
This Vault Enterprise practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Vault Enterprise exam.