Courseiva

VA-003 Utilize Vault CLI and API Practice Question

A cloud engineer is scripting against the Vault HTTP API and must authenticate, then read a KV v2 secret, using only `curl`. Which TWO request elements are required for the read to succeed? (Choose two.)

⚠ Common exam trap

The trap here is reusing the KV v1 path shape or assuming a custom header like `X-Vault-Request` is needed, when KV v2 reads go through the `data` endpoint with only the token header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A GET to the path `/v1/secret/data/apps/web/config`.

API reads require a valid token in the `X-Vault-Token` header and, for KV v2, a GET to the `/v1/<mount>/data/<path>` endpoint. The token authorizes the call against policy, while the data endpoint routes to the versioned secret store. Namespace and request-marker headers are situational and not required for a root-namespace read.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A GET to the path `/v1/secret/data/apps/web/config`.

    Why this is correct

    For KV v2, reading data uses the `/v1/<mount>/data/<path>` endpoint with the HTTP GET method. The `/v1` prefix and the `data` segment are both required; hitting the metadata or mount-root path returns metadata or a 404 instead of the secret payload. This endpoint is what the CLI calls under the hood.

  • ✗

    The header `X-Vault-Request: true` on the request.

    Why it's wrong here

    `X-Vault-Request` is not an authentication or required header for reading secrets; it is not used to authorize API calls. Vault authorizes based on the token, so this header would not enable the read and omitting it does not cause a 403 for this scenario.

  • ✗

    A POST to the path `/v1/secret/apps/web/config` with a JSON body.

    Why it's wrong here

    In KV v2 the legacy `/v1/<mount>/<path>` path no longer serves reads; that path belongs to KV v1. A POST without the `data` segment targets the wrong endpoint and would not return the stored secret, so this request shape fails against a v2 mount.

  • ✗

    The header `X-Vault-Namespace: root` on the request.

    Why it's wrong here

    `X-Vault-Namespace` selects an enterprise namespace and is only needed when the secret lives in a non-root namespace. In the default root namespace it is unnecessary, and adding it does not grant authorization; the token header and correct data endpoint are what matter for this read.

  • ✓

    The header `X-Vault-Token: <token>` on the request.

    Why this is correct

    The Vault API authenticates requests with the `X-Vault-Token` header carrying a valid client token. Without it, the API returns a 403 permission denied for protected paths. This header is the standard mechanism for passing a Vault token to the HTTP API and is required for the read to be authorized.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.