Courseiva

VA-003 Compare and configure secrets engines Practice Question

A cloud operations team needs Vault to issue short-lived credentials for an external MySQL database. They want Vault to create and revoke users dynamically based on a role. Which secrets engine should they enable and configure?

⚠ Common exam trap

The trap here is assuming that storing a database password in KV v2 is equivalent to dynamic credential generation, when it only provides static secrets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The database secrets engine

Dynamic database credentials are the core use case of the database secrets engine. It connects to the database with configured credentials, creates users per role using creation statements, and revokes them when the lease expires. KV v2 stores static secrets, Transit performs cryptographic operations, and PKI issues certificates, so none of those provide dynamic database users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The PKI secrets engine

    Why it's wrong here

    The PKI secrets engine issues X.509 certificates and manages a certificate authority. It produces certificates, not database user credentials. While certificates can be used for database TLS authentication, the engine does not create database users or revoke them based on leases. It is the wrong tool for generating dynamic MySQL credentials.

  • ✗

    The Transit secrets engine

    Why it's wrong here

    Transit provides encryption as a service, performing cryptographic operations on data without storing it. It does not issue database credentials or manage database users. Transit is used for encryption, decryption, signing, and related operations. It cannot create or revoke MySQL users, so it does not satisfy the scenario.

  • ✗

    The KV v2 secrets engine

    Why it's wrong here

    KV v2 stores static secrets at rest and returns them on read. It does not connect to a database or create users. While you could store a static MySQL password in KV v2, the credentials would not be short-lived or dynamically generated, and Vault would not revoke them at lease expiry. This engine does not meet the dynamic credential requirement.

  • ✓

    The database secrets engine

    Why this is correct

    The database secrets engine generates dynamic database credentials by connecting to the database and creating users based on role configuration. It supports creation and revocation statements, lease management, and multiple database plugins including MySQL. This matches the requirement for short-lived, dynamically generated credentials for an external MySQL database.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.