VA-003 Compare and configure secrets engines Practice Question
A cloud operations team wants to use Vault to generate dynamic credentials for an AWS RDS MySQL database. They have configured the database secrets engine and created a role named 'app-role' that maps to a database creation statement. A developer needs to obtain a username and password to connect to the database. Which command should the developer run to retrieve the dynamic credentials?
⚠ Common exam trap
Many exam-takers confuse the role configuration endpoint with the credential generation endpoint, or mistakenly using the KV command for a dynamic secrets engine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault read database/creds/app-role
Dynamic database credentials are generated by reading from the 'creds' endpoint of the database secrets engine for a specific role. The 'vault read database/creds/app-role' command triggers Vault to execute the role's creation statements and return a new username and password. Other commands either configure the role, target static roles, or use the wrong secrets engine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault read database/static-creds/app-role
Why it's wrong here
The 'database/static-creds' endpoint is used for static roles, which rotate credentials for existing database users. The scenario describes a dynamic role that creates new users on demand, so the static-creds endpoint is not applicable. Using it would either fail or return credentials for a static role if one existed with that name, but it does not align with the dynamic credential workflow.
- ✗
vault kv get database/creds/app-role
Why it's wrong here
The 'vault kv get' command is used to retrieve secrets from a KV secrets engine, not from the database secrets engine. The path 'database/creds/app-role' is not a KV path; it is an endpoint provided by the database secrets engine. Using 'vault kv get' would result in an error because the KV engine is not mounted at that path. This command is inappropriate for dynamic database credentials.
- ✓
vault read database/creds/app-role
Why this is correct
The 'vault read database/creds/<role>' command generates and returns dynamic credentials for the specified role. It calls the database secrets engine's creds endpoint, which executes the role's creation statements against the database and returns a unique username and password with a limited lease. This is the standard way to obtain dynamic database credentials from Vault.
- ✗
vault write database/roles/app-role
Why it's wrong here
The 'vault write database/roles/app-role' command is used to create or update the role definition, not to generate credentials. It configures the role's parameters such as creation statements and TTL. Running this command would not return a username and password; it would only modify the role's configuration. This is a configuration operation, not a credential retrieval operation.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.