Courseiva

VA-003 Explain encryption as a service Practice Question

A developer wants to encrypt a string "hello" using Vault's transit engine. What must they send in the API request?

⚠ Common exam trap

HashiCorp often tests the requirement for base64 encoding of plaintext in transit engine operations, trapping candidates who assume raw bytes or ciphertext are acceptable inputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The plaintext "hello" as a base64 encoded string

E is correct because Vault's transit engine requires plaintext to be base64-encoded before encryption. The API endpoint expects the plaintext as a base64-encoded string in the `plaintext` field of the request body. This ensures binary-safe transmission and consistent encoding across different systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ciphertext of "hello"

    Why it's wrong here

    Encryption produces ciphertext, so supplying ciphertext as input is circular; the transit engine expects plaintext to encrypt. It is tempting because decrypt operations do take ciphertext, and the stem mentions encryption ambiguously. Ciphertext input belongs to the decrypt endpoint, not the encrypt endpoint.

  • ✗

    Both the key name and the ciphertext

    Why it's wrong here

    The transit encrypt endpoint requires the plaintext, base64-encoded, plus the key name; ciphertext is the output, not an input. It tempts because both key name and data are indeed sent, but the data must be the plaintext being encrypted, not the resulting ciphertext.

  • ✗

    A reference to the key

    Why it's wrong here

    The transit engine encrypts plaintext supplied in the request body; a key reference alone carries no data to encrypt. Naming the key is tempting because the key name is part of the API path, but that identifies which key to use, not the payload. A key reference suits key rotation or metadata lookups, not encryption.

  • ✗

    The plaintext "hello" in raw bytes

    Why it's wrong here

    Transit requires base64-encoded plaintext, not raw bytes; sending raw bytes causes a decoding error before encryption. Raw bytes feel natural for binary payloads, and base64 is merely their transport encoding. Base64 encoding is the correct choice whenever plaintext must survive JSON serialisation intact.

  • ✓

    The plaintext "hello" as a base64 encoded string

    Why this is correct

    The transit engine's encrypt endpoint requires the plaintext field to be base64-encoded, since the API transports binary-safe data. Sending the raw string "hello" is rejected; the base64 form is mandatory for the request to succeed.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.