Courseiva

VA-003 Compare authentication methods Practice Question

A company uses both userpass and AppRole authentication methods. They notice that tokens issued via AppRole are not properly revoked when the corresponding secret_id is deleted. Which concept explains this behavior?

⚠ Common exam trap

The trap here is that candidates mistakenly believe that deleting the authentication credential (secret_id) will cascade to revoke the token, when in fact tokens and their authentication credentials are independent after login.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tokens are independent of secret_id after login; deleting secret_id does not revoke the token.

When a token is issued via AppRole, the token is created after a successful login using a secret_id. The token itself is independent of the secret_id; deleting the secret_id does not affect the token's lifecycle. Token revocation must be performed explicitly on the token, not by removing the secret_id.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The secret_id TTL was not set, causing the token to outlive the secret_id.

    Why it's wrong here

    Deleting a secret_id does not revoke tokens already issued through it; token lifetime is governed by the token's own TTL and explicit revocation, not the secret_id's TTL. Setting a secret_id TTL controls how long that credential can be used to authenticate, which is a separate mechanism from token revocation.

  • ✗

    AppRole does not support entity aliases, so revoking the secret_id does not affect the token.

    Why it's wrong here

    AppRole does support entity aliases, so this claim is factually wrong. Token revocation depends on the token's own lease and accessor, not on entity alias support. Deleting a secret_id removes a login credential; it does not revoke tokens already minted from it.

  • ✗

    The token was created with a periodic token and cannot be revoked.

    Why it's wrong here

    Periodic tokens are renewable service tokens that must be explicitly revoked; they are not inherently unrevocable. The scenario's cause is that secret_id deletion does not cascade to issued tokens, so the token remains valid until its TTL expires or it is revoked directly via the token accessor.

  • ✓

    Tokens are independent of secret_id after login; deleting secret_id does not revoke the token.

    Why this is correct

    A SecretID is only a login credential; once exchanged for a token, that token has its own lifecycle and lease. Deleting the SecretID prevents future logins but does not revoke already-issued tokens, which require explicit revocation.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.