VA-003 Compare authentication methods Practice Question
A company uses both userpass and AppRole authentication methods. They notice that tokens issued via AppRole are not properly revoked when the corresponding secret_id is deleted. Which concept explains this behavior?
⚠ Common exam trap
The trap here is that candidates mistakenly believe that deleting the authentication credential (secret_id) will cascade to revoke the token, when in fact tokens and their authentication credentials are independent after login.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tokens are independent of secret_id after login; deleting secret_id does not revoke the token.
When a token is issued via AppRole, the token is created after a successful login using a secret_id. The token itself is independent of the secret_id; deleting the secret_id does not affect the token's lifecycle. Token revocation must be performed explicitly on the token, not by removing the secret_id.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The secret_id TTL was not set, causing the token to outlive the secret_id.
Why it's wrong here
Deleting a secret_id does not revoke tokens already issued through it; token lifetime is governed by the token's own TTL and explicit revocation, not the secret_id's TTL. Setting a secret_id TTL controls how long that credential can be used to authenticate, which is a separate mechanism from token revocation.
- ✗
AppRole does not support entity aliases, so revoking the secret_id does not affect the token.
Why it's wrong here
AppRole does support entity aliases, so this claim is factually wrong. Token revocation depends on the token's own lease and accessor, not on entity alias support. Deleting a secret_id removes a login credential; it does not revoke tokens already minted from it.
- ✗
The token was created with a periodic token and cannot be revoked.
Why it's wrong here
Periodic tokens are renewable service tokens that must be explicitly revoked; they are not inherently unrevocable. The scenario's cause is that secret_id deletion does not cascade to issued tokens, so the token remains valid until its TTL expires or it is revoked directly via the token accessor.
- ✓
Tokens are independent of secret_id after login; deleting secret_id does not revoke the token.
Why this is correct
A SecretID is only a login credential; once exchanged for a token, that token has its own lifecycle and lease. Deleting the SecretID prevents future logins but does not revoke already-issued tokens, which require explicit revocation.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.