VA-003 Assess Vault tokens Practice Question
A platform team uses Vault to issue short-lived tokens to external contractors. The security policy requires that every contractor token must be traceable back to the contractor's identity, and that a token can never be renewed beyond its initial TTL. The team creates tokens with the default settings. A contractor later reports that their token stopped working after its TTL expired, but they were able to renew it several times before that. Which token parameter should the team have configured to enforce the policy?
⚠ Common exam trap
The trap here is assuming that setting a max TTL alone satisfies traceability, or that periodic tokens can be used to enforce a hard lifetime limit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create the token with the display-name parameter set to the contractor's identity and an explicit max TTL equal to the initial TTL.
To enforce the policy, the token must be traceable to the contractor and must not be renewable beyond its initial TTL. The display-name parameter provides traceability by linking the token to a specific identity. An explicit max TTL set to the same value as the initial TTL caps the total lifetime, so renewals cannot extend it. Other parameters like period or no-default-policy do not satisfy both requirements simultaneously.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the token's explicit max TTL to the same value as its initial TTL.
Why it's wrong here
Setting an explicit max TTL equal to the initial TTL would indeed prevent renewal beyond that period, but it does not address the traceability requirement. The scenario asks for a parameter that enforces both the non-renewable-beyond-TTL policy and traceability to the contractor's identity, which this setting alone does not provide. The team also needs to tie the token to the contractor, so this is only part of the solution.
- ✓
Create the token with the display-name parameter set to the contractor's identity and an explicit max TTL equal to the initial TTL.
Why this is correct
The display-name parameter allows operators to associate a human-readable identity with the token, satisfying traceability. Setting an explicit max TTL equal to the initial TTL ensures that even if the token is renewed, it cannot be renewed past that maximum lifetime. Together, these settings enforce both the traceability and the non-renewal-beyond-initial-TTL requirements described in the policy.
- ✗
Set the token's period to a fixed value and enable renewal.
Why it's wrong here
Periodic tokens are designed to be renewed indefinitely as long as they are renewed within the period, which directly contradicts the requirement that a token can never be renewed beyond its initial TTL. This would allow the contractor to keep renewing the token forever, violating the policy. It also does not inherently provide traceability to the contractor's identity.
- ✗
Create the token with the no-default-policy option and attach a custom policy.
Why it's wrong here
The no-default-policy option only controls which policies are attached to the token; it does not affect renewal behavior or traceability. A custom policy could restrict actions but would not prevent the token from being renewed beyond its initial TTL. This option fails to address the core requirements of the scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.