VA-003 Compare and configure secrets engines Practice Question
A developer wants to store an API key for their application in Vault using the key-value secrets engine. They need to be able to retrieve the key and also roll back to a previous version if needed. Which secrets engine configuration should they use?
⚠ Common exam trap
HashiCorp often tests the distinction between KV v1 and KV v2, where candidates mistakenly assume all KV engines support versioning, or confuse the Transit engine's encryption capabilities with secret storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the KV v2 secrets engine at a custom path
The KV v2 secrets engine supports versioning, allowing retrieval of previous versions and rollback capabilities. This directly meets the requirement to store an API key and revert to an older version if needed. KV v1 does not support versioning, while Transit and Database engines serve different purposes (encryption and dynamic credentials, respectively).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Transit secrets engine at a custom path
Why it's wrong here
The Transit engine performs cryptographic operations such as encryption and signing; it does not store arbitrary secrets. It suits scenarios needing encryption as a service. Storing and versioning an API key requires the KV v2 secrets engine instead.
- ✓
Enable the KV v2 secrets engine at a custom path
Why this is correct
Enabling KV v2 at a custom path satisfies the versioning requirement: KV v2 stores every write as a numbered version, so the developer can retrieve the current API key and roll back to an earlier version via the metadata endpoint. KV v1 offers no version history, making rollback impossible.
- ✗
Enable the KV v1 secrets engine at a custom path
Why it's wrong here
KV v1 stores secrets without versioning, so previous values cannot be retrieved or rolled back. KV v2 retains version history and supports rollback. KV v1 suits simple static secret storage where version history is not required.
- ✗
Enable the Database secrets engine at a custom path
Why it's wrong here
The Database engine dynamically generates short-lived database credentials; it does not store arbitrary secrets or retain versions. It suits scenarios needing leased, auto-rotated database access. Storing and rolling back an API key requires the KV v2 secrets engine.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.