Courseiva

VA-003 Compare and configure secrets engines Practice Question

A platform team stores application configuration and credentials in a KV v2 secrets engine mounted at 'kv/'. A developer deleted version 3 of the secret 'kv/app/db' by running 'vault kv delete kv/app/db'. Two days later, the security team asks the developer to recover that version because it contained a valid certificate. The developer runs 'vault kv get -version=3 kv/app/db' and receives an error that the version has been deleted. What must the developer do to recover version 3?

⚠ Common exam trap

Many candidates confuse soft delete with permanent destruction, leading to the belief that a deleted KV v2 version can only be recovered by writing the data again or that undelete is unavailable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'vault kv undelete -versions=3 kv/app/db' to restore the deleted version.

In KV v2, a delete operation is a soft delete that marks a version as deleted but keeps the data until it is destroyed or removed by the 'delete_version_after' setting. The 'vault kv undelete' command reverses that soft delete for the specified versions, making the data readable again. Rollback and patch both create new versions instead of restoring the old one, and metadata get only returns metadata.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run 'vault kv rollback -version=3 kv/app/db' to revert the secret to version 3.

    Why it's wrong here

    'vault kv rollback' creates a new version whose data is copied from the specified version; it does not resurrect the deleted version itself. After a rollback, the secret would have a new version number (for example version 4) with the old contents, but version 3 would remain in a deleted state. This does not satisfy the requirement to recover version 3 specifically.

  • ✗

    Run 'vault kv metadata get kv/app/db' to retrieve the deleted version from metadata.

    Why it's wrong here

    'vault kv metadata get' displays metadata about the secret such as the current version, maximum versions, and deletion times, but it does not contain the actual secret data. The metadata may show that version 3 was deleted, but it cannot restore or return the secret payload. This command is informational only and cannot recover the deleted version.

  • ✓

    Run 'vault kv undelete -versions=3 kv/app/db' to restore the deleted version.

    Why this is correct

    The 'vault kv undelete' command restores soft-deleted versions of a KV v2 secret. Because a delete operation on KV v2 only marks the version as deleted rather than destroying it, running undelete with the specific version number makes version 3 readable again via 'vault kv get -version=3'. This is the designed recovery path for accidental deletes within the retention window.

  • ✗

    Run 'vault kv patch kv/app/db' to restore the missing version from the patch history.

    Why it's wrong here

    'vault kv patch' performs a partial update by merging new data with the current version, creating a new version. It has no concept of restoring a previously deleted version and does not maintain any patch history to draw from. Using patch would only modify the latest version and would not bring back the deleted version 3 data.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.