VA-003 Explain Vault architecture Practice Question
A DevOps team is setting up a Vault cluster for the first time. They plan to use AWS KMS for auto-unseal and Consul as the storage backend. As part of the architecture, which TWO components are essential for the Vault server to start and serve requests?
⚠ Common exam trap
A common misconception is that the seal mechanism alone is sufficient for Vault to start, but the storage backend is equally essential because it holds the encrypted master key and all persistent data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A storage backend
Option B (a storage backend) is essential because Vault persists all data — secrets, policies, tokens, and configuration — in its storage backend, and here that is Consul; without a working storage backend Vault cannot initialize or serve requests. Option C (a configured seal mechanism) is essential because Vault must be able to unseal its master key to decrypt the barrier and become active; in this scenario the seal mechanism is AWS KMS auto-unseal, which is required for the server to reach a serving state. Option A is not required because Vault can use an internal/self-signed certificate or none at all for basic operation; a public CA cert is only needed for trusted TLS clients. Option D is incorrect because Vault generates its own encryption keys internally (e.g., the master key and barrier key) rather than requiring an externally supplied 4096-bit key. Option E is not essential because a load balancer is only for distributing traffic across multiple Vault nodes, not for a single server to start and serve requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A public CA certificate
Why it's wrong here
Vault serves requests over TLS, but a public CA certificate is not essential; an internal or self-signed certificate works, and the cluster can start without one. Public CA certificates suit externally facing endpoints where clients must trust the certificate chain without custom CA distribution.
- ✓
A storage backend
Why this is correct
Consul provides durable, highly available storage for Vault's encrypted data, and Vault cannot initialise or unseal without a configured storage backend. The stem specifies Consul as that backend, making it essential for the server to start and serve requests.
- ✓
A configured seal mechanism
Why this is correct
A configured seal mechanism is essential because Vault cannot start or serve requests while sealed. With AWS KMS auto-unseal, the seal stanza supplies the KMS key ID and region, letting Vault automatically unseal at startup without manual Shamir key entry, satisfying the stem's requirement for the server to start and serve requests.
- ✗
A 4096-bit encryption key
Why it's wrong here
A 4096-bit encryption key is not a startup prerequisite; Vault generates its own master and unseal keys, and AWS KMS supplies the auto-unseal wrapping key. Specifying key length is tempting because strong key sizes matter for cryptographic compliance, but key length is a configuration choice, not a component Vault requires to start.
- ✗
A load balancer
Why it's wrong here
A load balancer distributes client traffic but is not required for Vault to start or serve requests; a single node answers directly on its API port. Load balancers suit highly available multi-node clusters needing health-checked traffic distribution, which is an availability design choice rather than a startup dependency.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.