Courseiva

VA-003 Compare and configure secrets engines Practice Question

A DevOps team needs to provide temporary database credentials to applications without storing long-lived passwords. Which secrets engine should they use?

⚠ Common exam trap

HashiCorp often tests the distinction between static secret storage (KV v2) and dynamic secret generation (Database engine), leading candidates to mistakenly choose KV v2 because they think of it as the default secrets engine for any credential.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Database secrets engine

The Database secrets engine is designed to generate dynamic, short-lived database credentials on demand, allowing applications to access databases without storing long-lived passwords. It creates unique credentials for each request and automatically revokes them after a configurable TTL, meeting the requirement for temporary access without persistent secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KV v2 secrets engine

    Why it's wrong here

    KV v2 stores static key-value pairs, so any password written there persists until manually rotated or deleted, directly contradicting the no-long-lived-passwords requirement. It is tempting as the default general-purpose store for configuration and static secrets, and would be correct for holding non-rotating values such as API keys or config data.

  • ✗

    PKI secrets engine

    Why it's wrong here

    PKI issues X.509 certificates and private keys with defined TTLs; it cannot create database user accounts or credentials. It is tempting because it is a dynamic secrets engine producing short-lived artefacts, which fits TLS certificate automation for services, but the stem requires temporary database logins rather than certificates.

  • ✓

    Database secrets engine

    Why this is correct

    The database secrets engine dynamically generates short-lived credentials on demand, eliminating stored passwords. It satisfies the temporary-credentials constraint by issuing unique usernames and passwords per request with a lease TTL, after which Vault automatically revokes them. This removes long-lived static secrets entirely, unlike static key-value storage.

  • ✗

    Transit secrets engine

    Why it's wrong here

    Transit performs cryptographic operations — encryption, decryption, signing — on data passed to it, but never generates database credentials. It is tempting because it removes key management from applications, which suits encryption-as-a-service scenarios, yet the stem requires dynamic, short-lived database logins that the database secrets engine alone issues.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.