Courseiva
Manage Vault leases →mediumMultiple Choice

VA-003 Manage Vault leases Practice Question

A platform team runs a Vault cluster with a transit secrets engine mount at transit/. An application holds a token with a policy granting only "update" on transit/encrypt/orders and "read" on transit/keys/orders. The application's token has a TTL of 1h with a max_ttl of 4h, and it renews itself every 30 minutes using the token renewal endpoint. After roughly four hours of continuous operation, the application's API calls begin failing with a permission denied error even though the token was renewed successfully each time. Which Vault behavior explains this failure?

⚠ Common exam trap

The trap here is assuming that a successfully renewed token can be renewed forever, when in fact renewals stop extending the token once its max_ttl ceiling is reached.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The token reached its max_ttl, so renewal requests stopped extending its lifetime and the token expired, invalidating all requests made with it.

Service tokens are bounded by both a renewable TTL and an absolute max_ttl. Each renewal extends the token's lifetime only until the max_ttl ceiling is reached; beyond that point Vault refuses to extend it, and the token expires. Expiration invalidates the token immediately, so subsequent API calls authenticated with it fail with permission denied, exactly as the application observes after about four hours.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The transit secrets engine automatically revoked the token when the application exceeded its allowed number of encrypt operations per hour.

    Why it's wrong here

    The transit secrets engine does not meter client operations or revoke tokens for exceeding a request rate. Rate limiting is handled separately by Vault's request limiting features and would produce 429 responses, not permission denied errors. Nothing in the scenario describes a quota configured on the transit mount, so this mechanism cannot explain the failure.

  • ✗

    The policy attached to the token expired at the same time as the token's initial TTL and had to be reattached before further API calls could succeed.

    Why it's wrong here

    Policies in Vault are not leases and do not carry independent expiration times. A policy remains attached to a token for the token's entire lifetime, and renewing a token does not require reattaching policies. The described symptom comes from the token's own lifetime limits, not from any policy expiring separately.

  • ✓

    The token reached its max_ttl, so renewal requests stopped extending its lifetime and the token expired, invalidating all requests made with it.

    Why this is correct

    Vault tokens carry both a TTL and a max_ttl. Each successful renewal extends the token only up to the max_ttl ceiling; once that absolute lifetime is reached, Vault no longer extends the token and it expires. When the token expires, every request authenticated with it fails, which matches the permission denied errors appearing after roughly four hours of renewals.

  • ✗

    Renewing a token more than once silently converts it into a periodic token whose capabilities are stripped until it is re-authenticated.

    Why it's wrong here

    Repeated renewal never converts a normal service token into a periodic token; periodic tokens are created that way at issuance by specifying a period. Renewals also never strip capabilities from a token, because the attached policies persist unchanged. This behavior does not exist in Vault, so it cannot account for the application's errors.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.