Courseiva
Assess Vault tokens →mediumMultiple Choice

VA-003 Assess Vault tokens Practice Question

A developer authenticates with the userpass auth method and receives a token. The developer needs to perform a sensitive operation but the token lacks the required policy. Before asking an administrator, the developer wants to determine whether their current token is permitted to update the secret at secret/data/payments. Which command should the developer run?

⚠ Common exam trap

The trap here is assuming that listing a token's policies or reading a policy file proves what the token can do on a specific path, when effective capabilities require evaluating all policies together.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault token capabilities secret/data/payments

The capabilities endpoint is designed to answer exactly this question: it returns the set of actions the current token may perform on a specified path. Running vault token capabilities against secret/data/payments reveals whether update is allowed, without reading the secret or requiring administrator involvement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault kv get secret/data/payments

    Why it's wrong here

    vault kv get attempts to read the secret and would either succeed or fail, but reading is a different capability than updating. A successful read does not prove the token can update the secret, and a failure does not identify which capability is missing. It also retrieves sensitive data unnecessarily when only a permission check is needed.

  • ✗

    vault token lookup

    Why it's wrong here

    vault token lookup returns metadata about a token, including its policies, TTL, renewability, and accessor, but it does not evaluate path-level permissions. Seeing the policy names attached to the token does not tell the developer which actions are allowed on secret/data/payments, because policy contents must still be interpreted against the path.

  • ✓

    vault token capabilities secret/data/payments

    Why this is correct

    vault token capabilities reports the actions the calling token is allowed to perform on the given path. Run without an explicit token argument, it evaluates the current token and returns the permitted capabilities, such as create, read, or update. This directly answers whether the developer can update the payments secret without exposing or altering any data.

  • ✗

    vault policy read default

    Why it's wrong here

    vault policy read displays the contents of a named policy in HCL, but the developer's effective permissions come from the union of all attached policies plus any path-specific rules. Reading a single policy does not reveal the combined capabilities on the payments path and may show rules unrelated to that path, leading to an incorrect conclusion.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.