Courseiva
Create Vault policies →easyMultiple Choice

VA-003 Create Vault policies Practice Question

A junior administrator writes a policy file and applies it with 'vault policy write app-read app-read.hcl'. Later, a token created against this policy can read secrets it was never meant to see. The administrator wants to confirm exactly what the policy grants before rotating credentials. Which command displays the parsed, effective rules of the stored policy?

⚠ Common exam trap

The trap here is assuming the local HCL file is authoritative, when the server may hold a different version that was written earlier or overwritten by another operator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault policy read app-read

Stored policies are inspected with the dedicated policy read subcommand, which returns the server-side document as parsed, exposing any difference from the local HCL file. Listing policies only yields names, the raw sys endpoint returns an opaque string, and the capabilities subcommand requires a token and a path rather than a policy name.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vault policy list

    Why it's wrong here

    This subcommand prints only the names of the policies that exist in Vault; it returns no path stanzas or capabilities. Seeing that app-read is present tells the administrator nothing about which secrets the policy exposes, so it cannot explain the unexpected read access the investigation is trying to diagnose.

  • ✓

    vault policy read app-read

    Why this is correct

    The policy read subcommand fetches the named policy from Vault's storage and prints its contents exactly as the server has parsed and stored it. Because it reads the server-side copy rather than the local file, it reveals any drift between the HCL on disk and what is actually enforced, which is precisely what the administrator needs before rotating credentials.

  • ✗

    vault read sys/policy/app-read

    Why it's wrong here

    Reading the raw sys/policy endpoint returns the policy document as a single opaque string inside a JSON envelope, and it is the older API surface. It does display the rules, but the dedicated subcommand is the documented, human-readable way to inspect a stored policy, and the raw form is cumbersome and easy to misread during an audit.

  • ✗

    vault token capabilities app-read

    Why it's wrong here

    The capabilities subcommand expects a token identifier and a path, not a policy name, and it reports the effective capabilities a particular token holds on that path. Passing a policy name as the token argument does not reveal the policy's stanzas, so the administrator learns nothing about the granted rules from this invocation.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.