Courseiva

VA-003 Compare and configure secrets engines Practice Question

A company needs to generate short-lived, dynamic database credentials for its MySQL instances. Which secrets engine should be configured?

⚠ Common exam trap

HashiCorp often tests the distinction between static and dynamic secrets engines, and the trap here is confusing the Database secrets engine with the KV secrets engine because both can store database passwords, but only the Database engine generates them on-the-fly with automatic expiration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Database secrets engine

The Database secrets engine is specifically designed to generate short-lived, dynamic credentials for databases like MySQL. It creates unique, time-bound usernames and passwords on demand, which aligns with the requirement for temporary database access without manual credential management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KV secrets engine

    Why it's wrong here

    The KV secrets engine stores static secrets that persist until manually rotated, so it cannot produce short-lived dynamic credentials with automatic expiry. It is intended for arbitrary stored values such as API keys, and would be correct when secrets are managed rather than generated on demand.

  • ✗

    AWS secrets engine

    Why it's wrong here

    The AWS secrets engine issues IAM credentials for AWS services, not database logins for MySQL, so it cannot generate the required short-lived database credentials. It is intended for dynamically provisioning AWS access keys and similar identities, which would be correct when the target is AWS rather than a database.

  • ✓

    Database secrets engine

    Why this is correct

    The database secrets engine dynamically generates unique, short-lived MySQL credentials on demand, eliminating static passwords. It satisfies the stem's requirement for dynamic, short-lived database credentials by issuing them through a configured database role, with automatic revocation on lease expiry. Static or KV engines cannot generate per-request credentials tied to a lease.

  • ✗

    PKI secrets engine

    Why it's wrong here

    The PKI secrets engine issues X.509 certificates and private keys, not database usernames and passwords, so it cannot satisfy the MySQL credential requirement. It is designed for certificate authority duties such as TLS certificate issuance, which would be correct for securing service-to-service encryption.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.