Courseiva

VA-003 Compare and configure secrets engines Practice Question

A cloud operations team wants to use Vault to generate dynamic credentials for an AWS RDS MySQL database. They have configured the database secrets engine and created a role named 'app-role' that maps to a database creation statement. A developer needs to obtain a username and password to connect to the database. Which command should the developer run to retrieve the dynamic credentials?

⚠ Common exam trap

Many exam-takers confuse the role configuration endpoint with the credential generation endpoint, or mistakenly using the KV command for a dynamic secrets engine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault read database/creds/app-role

Dynamic database credentials are generated by reading from the 'creds' endpoint of the database secrets engine for a specific role. The 'vault read database/creds/app-role' command triggers Vault to execute the role's creation statements and return a new username and password. Other commands either configure the role, target static roles, or use the wrong secrets engine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault read database/static-creds/app-role

    Why it's wrong here

    The 'database/static-creds' endpoint is used for static roles, which rotate credentials for existing database users. The scenario describes a dynamic role that creates new users on demand, so the static-creds endpoint is not applicable. Using it would either fail or return credentials for a static role if one existed with that name, but it does not align with the dynamic credential workflow.

  • ✗

    vault kv get database/creds/app-role

    Why it's wrong here

    The 'vault kv get' command is used to retrieve secrets from a KV secrets engine, not from the database secrets engine. The path 'database/creds/app-role' is not a KV path; it is an endpoint provided by the database secrets engine. Using 'vault kv get' would result in an error because the KV engine is not mounted at that path. This command is inappropriate for dynamic database credentials.

  • ✓

    vault read database/creds/app-role

    Why this is correct

    The 'vault read database/creds/<role>' command generates and returns dynamic credentials for the specified role. It calls the database secrets engine's creds endpoint, which executes the role's creation statements against the database and returns a unique username and password with a limited lease. This is the standard way to obtain dynamic database credentials from Vault.

  • ✗

    vault write database/roles/app-role

    Why it's wrong here

    The 'vault write database/roles/app-role' command is used to create or update the role definition, not to generate credentials. It configures the role's parameters such as creation statements and TTL. Running this command would not return a username and password; it would only modify the role's configuration. This is a configuration operation, not a credential retrieval operation.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.