VA-003 Explain encryption as a service Practice Question
A developer needs to encrypt a short configuration string with the Vault transit secrets engine. The transit engine is mounted at `transit/` and a key named `app-config` has already been created. Which single CLI command correctly sends the plaintext to Vault for encryption?
⚠ Common exam trap
The trap here is forgetting that transit plaintext must be base64-encoded before it is sent, not passed as a raw string or filename.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault write transit/encrypt/app-config plaintext=$(base64 -w0 config.txt)
The transit engine exposes encryption at `transit/encrypt/<key-name>`, and the payload's `plaintext` field must be base64-encoded. Supplying the correctly ordered path along with a base64-encoded value is what allows Vault to return a `ciphertext` field. The other candidates fail because they either misuse the CLI, reverse the path structure, or omit the required base64 encoding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault write transit/app-config/encrypt plaintext=config.txt
Why it's wrong here
This path reverses the key and action segments. The transit engine expects `transit/encrypt/<key-name>`, not `transit/<key-name>/encrypt`. Even if the path were corrected, passing raw file content as the plaintext parameter without base64 encoding would be rejected because Vault requires base64-encoded plaintext.
- ✓
vault write transit/encrypt/app-config plaintext=$(base64 -w0 config.txt)
Why this is correct
The transit encrypt endpoint is `transit/encrypt/<key-name>`, and the `plaintext` parameter must be base64-encoded before it is submitted. Using `base64 -w0` produces a single-line base64 value suitable for the request, so this command reaches the correct key and supplies a valid payload.
- ✗
vault encrypt transit/app-config plaintext=config.txt
Why it's wrong here
There is no top-level `vault encrypt` command in the Vault CLI; encryption is performed by writing to an API endpoint. The CLI verb must be `vault write` targeting the transit path, and the plaintext still needs base64 encoding, so this syntax would fail before any encryption occurs.
- ✗
vault write transit/encrypt/app-config plaintext=config.txt
Why it's wrong here
The path is correct, but the plaintext is not base64-encoded. Vault's transit encrypt endpoint expects the `plaintext` field to contain base64-encoded bytes, so sending a raw filename or raw string will produce a decoding error rather than a ciphertext response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.