Courseiva
Manage Vault leases →hardMultiple Choice

VA-003 Manage Vault leases Practice Question

A role in Vault's database secrets engine is configured with default_ttl=30m and max_ttl=2h. An application requests credentials and then successfully renews the lease twice, each time receiving the full default TTL. What is the longest total time the credential can remain valid from its original issue time?

⚠ Common exam trap

The trap here is multiplying the default TTL by the number of renewals or assuming renewals can continue forever, instead of recognizing max_ttl as an absolute cap from issue time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

2 hours

The max_ttl on the role is the hard ceiling on a lease's total lifetime from issuance. Renewals can extend expiration in increments up to the default TTL, but the expiration manager refuses to push past max_ttl, after which the application must obtain brand-new credentials through the creds endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    2 hours

    Why this is correct

    max_ttl caps the total lifetime of a lease regardless of how many times it is renewed. Each renewal may grant up to the default TTL, but the expiration can never be pushed beyond two hours from the original issue time, so that is the absolute ceiling for this credential.

  • ✗

    4 hours

    Why it's wrong here

    Doubling the max_ttl has no basis in Vault's lease model. Renewals extend toward the max_ttl boundary and stop there; they never accumulate beyond it. An operator expecting four hours would see renewal requests rejected once the two-hour mark is reached.

  • ✗

    1 hour 30 minutes

    Why it's wrong here

    This figure would result from three sequential 30-minute increments, but the question is about the maximum possible lifetime, not the duration reached after a fixed number of renewals. The governing constraint is max_ttl, which allows up to two hours, so this answer understates the ceiling.

  • ✗

    Unlimited, as long as the application renews before each expiry

    Why it's wrong here

    Continuous renewal does not permit indefinite use of a dynamic credential. The max_ttl setting exists precisely to force periodic reissuance, after which the secrets engine creates a new credential and revokes the old one, bounding exposure if a credential leaks.

About these practice questions

This VA-003 question is part of Courseiva's 366-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official HashiCorp exam blueprint

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.