Courseiva
Assess Vault tokens →mediumMultiple Choice

VA-003 Assess Vault tokens Practice Question

A security analyst discovers that a token used by a legacy application is still active long after the application was decommissioned. Which Vault feature should have been used to automatically expire tokens when the application is no longer running?

⚠ Common exam trap

Many exam-takers confuse token renewal (which extends lifetime) with TTL-based expiration, or they assume manual revocation is sufficient for automated lifecycle management, missing the need for automatic expiry via TTL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set a TTL on the token

Setting a Time-To-Live (TTL) on the token ensures it automatically expires after a specified duration, even if the application is decommissioned. This prevents orphaned tokens from remaining active indefinitely, which is a security risk. Vault's TTL mechanism is designed to enforce token lifetime limits without requiring manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable token renewal to keep it alive

    Why it's wrong here

    Token renewal extends a token's lifetime rather than expiring it, so it cannot decommission the legacy application's credential. It is tempting because renewal suits long-running services that must stay authenticated across restarts. Here the requirement is automatic expiry once the application stops running, which periodic token renewal actively prevents.

  • ✗

    Use a periodic token and revoke it manually

    Why it's wrong here

    Periodic tokens never expire on their own and require an explicit revoke call, which a decommissioned application cannot issue. It tempts because periodic tokens suit long-running services, but the requirement is automatic expiry when the client stops, which orphan tokens or response-wrapped tokens address.

  • ✓

    Set a TTL on the token

    Why this is correct

    A token TTL enforces a maximum lifetime, after which Vault automatically revokes the token regardless of whether the legacy application still runs. This directly satisfies the requirement to expire credentials without manual intervention, closing the exposure window left when a decommissioned application's token remained active indefinitely.

  • ✗

    Use a batch token to limit its lifetime

    Why it's wrong here

    Batch tokens are designed for high-throughput, stateless workloads and cannot be renewed or looked up; they expire only at their fixed TTL, not when the application stops. It tempts because batch tokens are short-lived, but lifetime is not tied to process liveness.

About these practice questions

One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.