VA-003 Assess Vault tokens Practice Question
A company runs multiple microservices in a Kubernetes cluster. Each microservice authenticates to Vault using a service token created via the token auth method. The tokens are created with a default TTL of 72h, a max TTL of 168h, and renewable set to true. The services are configured to renew their tokens when the remaining TTL drops below 24h. Recently, some tokens have been expiring prematurely, causing service outages. Upon investigation, you find that the expired tokens were created with a role that includes explicit_max_ttl = 72h. The services see the TTL decreasing normally, but then it jumps to zero even though the services attempted renewal. What is the most likely cause and correct action?
⚠ Common exam trap
In HashiCorp Vault, the distinction between `max_ttl` (which can be extended by renewal up to the mount's limit) and `explicit_max_ttl` (which is an absolute, non-renewable cap) is crucial. Candidates often overlook that `explicit_max_ttl` overrides the renewable property, causing premature token expiration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the explicit_max_ttl setting from the role or set it to 0.
The `explicit_max_ttl` setting on the role overrides the token's renewable property. When a token has an `explicit_max_ttl` of 72h, it cannot be renewed beyond that absolute lifetime, regardless of the `renewable = true` setting. The services attempt renewal, but Vault enforces the hard limit, causing the TTL to jump to zero at the 72-hour mark. Removing `explicit_max_ttl` or setting it to 0 allows the token to be renewed up to the system's `max_ttl` (168h), preventing premature expiration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the services to renew the token when TTL drops below 48h.
Why it's wrong here
Renewal timing is not the fault: the role's explicit_max_ttl of 72h caps total token lifetime, so renewal is refused once that ceiling is reached regardless of when it is attempted. Renewing earlier is tempting because short remaining TTL often precedes expiry, but it would be correct only if renewal were failing due to a missed window.
- ✓
Remove the explicit_max_ttl setting from the role or set it to 0.
Why this is correct
explicit_max_ttl caps a token's total lifetime regardless of renewal, so tokens die at 72h even though renewal is attempted. Removing it or setting it to 0 lets the role's max_ttl govern, satisfying the stem's premature-expiry constraint.
- ✗
Increase the default TTL on the token auth mount to 168h.
Why it's wrong here
The mount's default TTL governs initial token issuance, not the renewal ceiling; the role's explicit_max_ttl of 72h still blocks renewal past that point. Raising it is tempting because default TTL appears to control token longevity, and it would be correct only if tokens were being issued with too short an initial lifetime.
- ✗
Set max_ttl on the role to 72h.
Why it's wrong here
Setting max_ttl to 72h does not remove the explicit_max_ttl cap; the role's explicit ceiling still forces expiry at 72h regardless of renewal. Raising max_ttl is the correct action when tokens must live longer, but here the explicit cap is the binding constraint.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.