Courseiva

VA-003 Explain encryption as a service Practice Question

A company uses Vault transit to encrypt secrets. They want to periodically rotate the encryption key to comply with compliance requirements. Which TWO actions should be taken? (Choose two.)

⚠ Common exam trap

HashiCorp often tests the misconception that you must delete old key versions immediately after rotation, but the correct practice is to keep them until all ciphertext is rewrapped to avoid data loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rewrap all existing ciphertext with the new key version.

Option E is correct because Vault's transit secrets engine supports key rotation via the `rotate` endpoint (e.g., `vault write -f transit/keys/<key_name>/rotate`), which creates a new key version while retaining older versions for decrypting existing ciphertext. Option C is correct because after rotation, existing ciphertext still references older key versions, so `rewrap` (e.g., `vault write transit/rewrap/<key_name> ciphertext=<...>`) re-encrypts the data under the latest key version without exposing the plaintext, satisfying periodic rotation compliance. Option A is wrong because immediately setting `min_decryption_version` to the newest version would make ciphertext encrypted with older versions undecryptable, breaking access to existing data. Option B is wrong because exporting the key defeats the purpose of Vault transit (keys never leave Vault) and manual re-encryption is unnecessary since `rewrap` handles it. Option D is wrong because deleting old key versions would render existing ciphertext undecryptable and is not required for rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Update the min_decryption_version to the newest version immediately.

    Why it's wrong here

    This would prevent decryption of any data encrypted with older versions.

  • ✗

    Export the key and re-encrypt all data manually.

    Why it's wrong here

    Unnecessary and introduces security risk; rewrapping is sufficient.

  • ✓

    Rewrap all existing ciphertext with the new key version.

    Why this is correct

    Rewrapping re-encrypts existing ciphertext under the new key version without exposing plaintext, satisfying the compliance requirement that data previously encrypted with the retired version remains readable. Vault's `rewrap` endpoint decrypts with the old version and re-encrypts with the latest, so historical ciphertext stays accessible after rotation.

  • ✗

    Delete old key versions after rotation.

    Why it's wrong here

    Deleting old versions prematurely can cause data loss if not all data is rewrapped.

  • ✓

    Rotate the key using Vault's key rotation endpoint.

    Why this is correct

    Rotating via Vault's key rotation endpoint generates a new version of the encryption key while retaining old versions for decryption, satisfying the periodic rotation requirement. Vault's transit secrets engine supports this natively, so existing ciphertext remains decryptable and no re-encryption is forced immediately.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.