VA-003 Assess Vault tokens Practice Question
A CI/CD pipeline needs to generate thousands of short-lived tokens each day for jobs that run for at most 5 minutes. The tokens should not be renewable or revocable individually. Which token type should be used?
⚠ Common exam trap
The Vault exam often tests the distinction between token types by emphasizing 'short-lived' and 'non-renewable'—candidates may confuse batch tokens with periodic tokens because both can have short TTLs, but periodic tokens are renewable and individually revocable, while batch tokens are not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Batch tokens
Batch tokens are designed for high-volume, short-lived workloads where tokens are generated in batches and have a configurable TTL (time-to-live). They cannot be renewed or revoked individually, making them ideal for CI/CD pipelines that need thousands of tokens per day for jobs lasting at most 5 minutes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Orphan tokens
Why it's wrong here
Orphan tokens are tokens whose parent entity has been deleted, leaving them unmanaged and unrevocable; they are not an issuance type a pipeline can deliberately generate. They would be relevant when auditing or cleaning up stale credentials after a role or entity removal.
- ✗
Service tokens
Why it's wrong here
Service tokens are long-lived credentials tied to a service or application identity, designed for repeated use rather than thousands of individually issued short-lived credentials. They would be correct for a persistent service account authenticating continuously to a backend system.
- ✓
Batch tokens
Why this is correct
Batch tokens suit this pipeline because they are non-renewable and cannot be individually revoked, matching the stated constraint. They are issued by a batch token role, are not persisted to storage, and carry a fixed TTL, so thousands of short-lived five-minute job tokens can be generated cheaply without per-token lifecycle management overhead.
- ✗
Periodic tokens
Why it's wrong here
Periodic tokens are long-lived credentials issued on a fixed schedule for batch or long-running jobs, so they cannot supply thousands of distinct five-minute credentials daily. They would be correct for a recurring nightly batch process needing one stable token.
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.