VA-003 Utilize Vault CLI and API Practice Question
A developer wants to inspect the metadata of the current Vault token, including its attached policies, TTL, and whether it is renewable, using a single CLI command. Which command should the developer run?
⚠ Common exam trap
The trap here is reaching for `vault token renew` to see TTL, when renewal mutates the token and does not list policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault token lookup
The `vault token lookup` command retrieves metadata for the calling token when no token argument is supplied, exposing fields like `policies`, `ttl`, `renewable`, and `accessor`. It is a read-only operation with no side effects, unlike renewal. Commands such as `vault auth list` or `vault token capabilities` serve entirely different purposes and cannot report the token's policies and TTL.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault token renew
Why it's wrong here
`vault token renew` extends the token's lease and returns updated TTL information, but its purpose is renewal, not inspection. Running it has a side effect on the token's lifetime and does not enumerate attached policies. It is the wrong tool when the goal is read-only metadata review.
- ✗
vault auth list
Why it's wrong here
`vault auth list` enumerates the auth methods enabled on the Vault server, such as approle or userpass. It does not describe the current token, its policies, or its TTL. This command is used for administrative review of auth mounts, not for inspecting a client token.
- ✗
vault token capabilities
Why it's wrong here
`vault token capabilities` evaluates whether a token has a specific capability on a given path, returning a permission like read or deny. It does not display token metadata such as policies, TTL, or renewability. It requires a path argument and answers an authorization question, not a token-inspection question.
- ✓
vault token lookup
Why this is correct
`vault token lookup` with no argument inspects the calling token and returns its accessor, policies, TTL, renewable status, and other metadata. This matches the developer's need to see policies, TTL, and renewability in one command. It is the standard CLI command for examining the current token's properties.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.