VA-003 Explain Vault architecture Practice Question
A company is running Vault in production with a single active node and two standby nodes using Integrated Storage. The operations team notices that after a network partition, one of the standby nodes becomes unavailable for a few minutes. Upon recovery, the node rejoins the cluster. However, the active node's performance degrades temporarily. What is the most likely cause?
⚠ Common exam trap
HashiCorp often tests the misconception that a reconnecting standby node triggers a leadership election or a full data sync, when in reality Raft uses snapshot installation to efficiently catch up followers, which can cause temporary performance degradation on the active node.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The standby node's recovery caused Raft snapshot installation, leading to temporary I/O load on the active node.
When a standby node reconnects after a network partition, the Raft consensus protocol may require the node to catch up on missed log entries. If the log gap is large, the active node initiates a snapshot installation, which involves reading and sending a compressed snapshot of the Raft state. This process causes significant I/O and CPU load on the active node, temporarily degrading its performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The standby node caused a leadership election upon reconnection.
Why it's wrong here
A standby rejoining cannot trigger an election: only a voter holding a current term can stand, and the active node retains leadership throughout. It is tempting because partitions are commonly associated with elections, and it would be correct if the cluster had lost quorum and the active node had actually stepped down.
- ✗
The standby node was not using a seal wrapping key, causing re-encryption of all data.
Why it's wrong here
Seal wrapping protects the unseal key during auto-unseal; it has no bearing on data encryption, and Integrated Storage never re-encrypts the entire dataset on a standby's return. It is tempting because seal wrapping sounds security-critical, and it would matter if the node were configuring auto-unseal with a KMS.
- ✓
The standby node's recovery caused Raft snapshot installation, leading to temporary I/O load on the active node.
Why this is correct
Raft snapshot installation is the mechanism: a partitioned standby that falls behind the leader's log must receive a full snapshot on rejoin. Applying that snapshot forces the active node to read and stream state, creating temporary disk I/O contention that degrades its performance.
- ✗
The standby node forced a full data sync from the active node, consuming resources.
Why it's wrong here
A standby that merely rejoins catches up through incremental log shipping; a full snapshot transfer occurs only when its log index has fallen outside the retained log range. It is tempting because resyncs do consume I/O, and it would be correct if the node had been offline long enough for the active node to truncate its logs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.