VA-003 Assess Vault tokens Practice Question
A new engineer authenticates to Vault and receives a token. The engineer's manager asks which policies are attached to that token and when it will expire, so the team can plan a permissions review. Which command should the engineer run to display this information about their own token?
⚠ Common exam trap
The trap here is reaching for commands that list auth methods or secrets engines, which describe mount configuration rather than the attributes of a specific token.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vault token lookup
Token inspection is performed with vault token lookup, which returns the token's policies, TTL, renewability, and accessor when run against the current token. That directly supplies the policy list and expiration information needed for the review, without creating new tokens or querying unrelated auth and secrets mounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vault auth list
Why it's wrong here
vault auth list enumerates the enabled auth methods, such as userpass, approle, and kubernetes, along with their accessors and descriptions. It says nothing about which policies a particular token carries or when that token expires. It answers a configuration question about auth mounts, not a token-inspection question.
- ✓
vault token lookup
Why this is correct
vault token lookup with no argument inspects the token currently in use and returns its policies, TTL, creation time, renewability, and accessor. This gives the engineer exactly the policy list and expiry details the manager requested. It is a read-only operation that requires no special privileges beyond possessing the token.
- ✗
vault secrets list
Why it's wrong here
vault secrets list shows the enabled secrets engines and their mount paths, such as kv, transit, or database. It provides no information about token policies or TTLs. Using it would reveal mount configuration rather than the token attributes the permissions review requires, so it does not satisfy the request.
- ✗
vault token create
Why it's wrong here
vault token create issues a brand-new token with its own policies and TTL; it does not describe the existing token. Running it would add another token to the system rather than answer the review question, and the new token's attributes would not reflect the engineer's current one. It is the wrong operation entirely for an inspection task.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.