VA-003 Assess Vault tokens Practice Question
A security analyst discovers that a token used by a legacy application is still active long after the application was decommissioned. Which Vault feature should have been used to automatically expire tokens when the application is no longer running?
⚠ Common exam trap
Many exam-takers confuse token renewal (which extends lifetime) with TTL-based expiration, or they assume manual revocation is sufficient for automated lifecycle management, missing the need for automatic expiry via TTL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set a TTL on the token
Setting a Time-To-Live (TTL) on the token ensures it automatically expires after a specified duration, even if the application is decommissioned. This prevents orphaned tokens from remaining active indefinitely, which is a security risk. Vault's TTL mechanism is designed to enforce token lifetime limits without requiring manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable token renewal to keep it alive
Why it's wrong here
Token renewal extends a token's lifetime rather than expiring it, so it cannot decommission the legacy application's credential. It is tempting because renewal suits long-running services that must stay authenticated across restarts. Here the requirement is automatic expiry once the application stops running, which periodic token renewal actively prevents.
- ✗
Use a periodic token and revoke it manually
Why it's wrong here
Periodic tokens never expire on their own and require an explicit revoke call, which a decommissioned application cannot issue. It tempts because periodic tokens suit long-running services, but the requirement is automatic expiry when the client stops, which orphan tokens or response-wrapped tokens address.
- ✓
Set a TTL on the token
Why this is correct
A token TTL enforces a maximum lifetime, after which Vault automatically revokes the token regardless of whether the legacy application still runs. This directly satisfies the requirement to expire credentials without manual intervention, closing the exposure window left when a decommissioned application's token remained active indefinitely.
- ✗
Use a batch token to limit its lifetime
Why it's wrong here
Batch tokens are designed for high-throughput, stateless workloads and cannot be renewed or looked up; they expire only at their fixed TTL, not when the application stops. It tempts because batch tokens are short-lived, but lifetime is not tied to process liveness.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.