VA-003 Compare and configure secrets engines Practice Question
A cloud operations team needs Vault to issue short-lived credentials for an external MySQL database. They want Vault to create and revoke users dynamically based on a role. Which secrets engine should they enable and configure?
⚠ Common exam trap
The trap here is assuming that storing a database password in KV v2 is equivalent to dynamic credential generation, when it only provides static secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The database secrets engine
Dynamic database credentials are the core use case of the database secrets engine. It connects to the database with configured credentials, creates users per role using creation statements, and revokes them when the lease expires. KV v2 stores static secrets, Transit performs cryptographic operations, and PKI issues certificates, so none of those provide dynamic database users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The PKI secrets engine
Why it's wrong here
The PKI secrets engine issues X.509 certificates and manages a certificate authority. It produces certificates, not database user credentials. While certificates can be used for database TLS authentication, the engine does not create database users or revoke them based on leases. It is the wrong tool for generating dynamic MySQL credentials.
- ✗
The Transit secrets engine
Why it's wrong here
Transit provides encryption as a service, performing cryptographic operations on data without storing it. It does not issue database credentials or manage database users. Transit is used for encryption, decryption, signing, and related operations. It cannot create or revoke MySQL users, so it does not satisfy the scenario.
- ✗
The KV v2 secrets engine
Why it's wrong here
KV v2 stores static secrets at rest and returns them on read. It does not connect to a database or create users. While you could store a static MySQL password in KV v2, the credentials would not be short-lived or dynamically generated, and Vault would not revoke them at lease expiry. This engine does not meet the dynamic credential requirement.
- ✓
The database secrets engine
Why this is correct
The database secrets engine generates dynamic database credentials by connecting to the database and creating users based on role configuration. It supports creation and revocation statements, lease management, and multiple database plugins including MySQL. This matches the requirement for short-lived, dynamically generated credentials for an external MySQL database.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.