VA-003 Assess Vault tokens Practice Question
A developer authenticates with the userpass auth method and receives a token. The developer needs to perform a sensitive operation but the token lacks the required policy. Before asking an administrator, the developer wants to determine whether their current token is permitted to update the secret at secret/data/payments. Which command should the developer run?
⚠ Common exam trap
The trap here is assuming that listing a token's policies or reading a policy file proves what the token can do on a specific path, when effective capabilities require evaluating all policies together.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault token capabilities secret/data/payments
The capabilities endpoint is designed to answer exactly this question: it returns the set of actions the current token may perform on a specified path. Running vault token capabilities against secret/data/payments reveals whether update is allowed, without reading the secret or requiring administrator involvement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault kv get secret/data/payments
Why it's wrong here
vault kv get attempts to read the secret and would either succeed or fail, but reading is a different capability than updating. A successful read does not prove the token can update the secret, and a failure does not identify which capability is missing. It also retrieves sensitive data unnecessarily when only a permission check is needed.
- ✗
vault token lookup
Why it's wrong here
vault token lookup returns metadata about a token, including its policies, TTL, renewability, and accessor, but it does not evaluate path-level permissions. Seeing the policy names attached to the token does not tell the developer which actions are allowed on secret/data/payments, because policy contents must still be interpreted against the path.
- ✓
vault token capabilities secret/data/payments
Why this is correct
vault token capabilities reports the actions the calling token is allowed to perform on the given path. Run without an explicit token argument, it evaluates the current token and returns the permitted capabilities, such as create, read, or update. This directly answers whether the developer can update the payments secret without exposing or altering any data.
- ✗
vault policy read default
Why it's wrong here
vault policy read displays the contents of a named policy in HCL, but the developer's effective permissions come from the union of all attached policies plus any path-specific rules. Reading a single policy does not reveal the combined capabilities on the payments path and may show rules unrelated to that path, leading to an incorrect conclusion.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.