Courseiva

VA-003 Compare and configure secrets engines Practice Question

A cloud operations team needs to provide temporary, dynamically generated credentials for an AWS IAM user to a CI/CD pipeline. The credentials must be automatically revoked when the lease expires. They have configured the AWS secrets engine at 'aws/' with root credentials. Which configuration step is required to allow the pipeline to assume a specific IAM role and receive credentials?

⚠ Common exam trap

The trap here is mixing up the parameters for specifying a role ARN versus attaching policies; the role_arns parameter is required to assume a role, while policy_arns is for attaching policies to generated users or sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a role in the AWS secrets engine that specifies the credential type as 'assumed_role' and provides the ARN of the IAM role.

To generate temporary credentials that assume a specific IAM role, the AWS secrets engine role must have credential_type set to 'assumed_role' and include the role_arns parameter with the ARN of the target role. This leverages AWS STS AssumeRole, producing credentials that automatically expire with the lease. Other credential types produce different kinds of credentials that do not meet the dynamic, role-assuming requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a role with credential_type=federation_token and specify the role ARN in the policy document.

    Why it's wrong here

    The federation_token credential type generates a federated token via STS GetFederationToken, which is tied to the IAM user that Vault uses, not an assumed role. It does not assume a specific IAM role and the credentials are not automatically revoked upon lease expiration in the same way. This does not meet the requirement to assume a specific IAM role.

  • ✓

    Create a role in the AWS secrets engine that specifies the credential type as 'assumed_role' and provides the ARN of the IAM role.

    Why this is correct

    For the AWS secrets engine to generate credentials that assume an IAM role, you must create a role with credential_type=assumed_role and provide the role_arns parameter. This allows Vault to call STS AssumeRole and return temporary credentials. The other options either use static credentials or incorrect parameters, and do not fulfill the dynamic credential requirement with automatic revocation.

  • ✗

    Create a role with credential_type=assumed_role and set the policy_arns parameter to the ARN of the IAM role.

    Why it's wrong here

    The policy_arns parameter is used to attach managed policies to generated IAM users or to the assumed role session, but it does not specify which role to assume. To assume a role, you must provide the role_arns parameter, not policy_arns. Using policy_arns here would result in an error or misconfiguration, as the role ARN is expected in role_arns.

  • ✗

    Create a role with credential_type=iam_user and attach a policy that allows sts:AssumeRole.

    Why it's wrong here

    Using credential_type=iam_user creates a new IAM user with access keys, not temporary assumed-role credentials. Although you could attach a policy that allows AssumeRole, the credentials themselves are long-lived IAM user keys, not temporary STS credentials. This does not meet the requirement for dynamically generated, automatically revoked credentials tied to an IAM role.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.