Courseiva
Manage Vault leases →easyMultiple Choice

VA-003 Manage Vault leases Practice Question

A platform engineer has issued dynamic AWS credentials through Vault's AWS secrets engine and wants to extend the usable lifetime of that credential before it expires. Which Vault CLI command allows the engineer to request additional time on the lease?

⚠ Common exam trap

Many candidates confuse token renewal with lease renewal, assuming that renewing the token also extends the lifetime of secrets issued under it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vault lease renew <lease_id>

Leases on dynamic secrets can be extended with vault lease renew, which asks the secrets engine to grant more time within the role's max_ttl boundary. Revoking destroys the credential, renewing a token affects authentication rather than the secret, and re-writing the creds path issues a separate credential instead of extending the current one.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    vault lease renew <lease_id>

    Why this is correct

    The vault lease renew command extends the lease of a secret that was already issued. When run against an AWS secrets engine lease, Vault asks the backend to extend the credential's validity, subject to the role's max_ttl. This directly matches the engineer's goal of gaining additional usable time before the credential expires.

  • ✗

    vault token renew <token>

    Why it's wrong here

    vault token renew extends the TTL of the client token used to authenticate, not the lease of a secrets engine credential. Renewing the token does not change the AWS credential's lease expiry. The engineer's objective concerns the secret lease, so renewing the authentication token is the wrong object entirely.

  • ✗

    vault write aws/creds/my-role ttl=1h

    Why it's wrong here

    Writing to aws/creds/my-role generates a brand-new AWS credential and lease rather than extending the existing one. This leaks the old credential, which remains valid until its own lease expires, and does not match the engineer's intent to lengthen the lifetime of the credential already in hand.

  • ✗

    vault lease revoke <lease_id>

    Why it's wrong here

    vault lease revoke terminates the lease immediately and, for dynamic secrets, deletes the underlying credential at the target system. That is the opposite of extending usable lifetime. Running it here would destroy the very AWS credential the engineer wants to keep working, so it cannot satisfy the requirement.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.