VA-003 Explain encryption as a service Practice Question
A platform team is designing an encryption-as-a-service layer with the transit secrets engine for several internal applications. They want to minimize the amount of sensitive data that reaches application memory and reduce the operational cost of rotating keys. Which TWO design choices align with how the transit engine is intended to be used? (Choose two.)
⚠ Common exam trap
The trap here is assuming that reducing Vault round-trips justifies exporting or persisting key material, when the datakey endpoint already provides a safe way to encrypt locally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Have applications call the encrypt and decrypt endpoints so plaintext never leaves the application but key material never reaches it.
The transit engine supports two complementary patterns: direct encrypt/decrypt calls that keep keys inside Vault, and envelope encryption using the datakey endpoint so bulk data is encrypted locally with a wrapped key stored alongside it. Both minimize key exposure and make rotation manageable. Exporting keys, disabling versioning, or persisting plaintext data keys all undermine those goals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Export the transit key and distribute copies to each application so they can encrypt without any runtime dependency on Vault.
Why it's wrong here
Exporting and distributing key material removes Vault from the cryptographic path, eliminating centralized policy enforcement and audit logging, and it multiplies the number of places a key can leak. Rotation also becomes manual and error-prone across every copy. This is the opposite of encryption as a service.
- ✓
Have applications call the encrypt and decrypt endpoints so plaintext never leaves the application but key material never reaches it.
Why this is correct
This is the core encryption-as-a-service pattern: the application submits plaintext to Vault and receives ciphertext, so the key stays protected inside Vault while the application retains control of its data. It also centralizes audit logging and lets policies govern which callers can encrypt or decrypt, which is exactly what the engine is designed to support.
- ✗
Disable key versioning on all keys so that rotation does not create new versions that applications must track.
Why it's wrong here
Versioning is intrinsic to how the transit engine supports rotation and decryption of historical ciphertext; disabling it is not a supported configuration and would undermine the ability to rotate safely. Applications do not need to track versions because ciphertext carries its version, so this supposed benefit does not exist.
- ✓
Generate a data key with the datakey endpoint, encrypt the payload locally with it, and store the wrapped key alongside the ciphertext.
Why this is correct
The datakey endpoint returns a plaintext data key plus a wrapped copy, enabling envelope encryption where bulk data is encrypted locally and only the small data key is protected by Vault. This reduces calls to Vault for large payloads and lets you rewrap the wrapped key on rotation without touching the bulk ciphertext, which lowers rotation cost.
- ✗
Store the plaintext data key in the application's configuration file so services can reuse it across restarts and avoid extra Vault calls.
Why it's wrong here
Persisting a plaintext data key in configuration exposes key material to anyone who can read the file, including in backups and source control, and it never benefits from rotation. The wrapped copy is what should be stored; the plaintext data key should be used transiently and discarded, which is the point of the envelope pattern.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.