Courseiva

VA-003 Compare and configure secrets engines Practice Question

A security architect is designing a secrets management solution with Vault. Which THREE secrets engines are most appropriate for dynamically generating credentials for external systems?

⚠ Common exam trap

HashiCorp often tests the distinction between secrets engines that generate dynamic credentials (PKI, AWS, Database) versus those that store or process static data (KV v2, Transit), leading candidates to incorrectly select KV v2 for its familiarity or Transit for its security focus.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PKI secrets engine

The PKI secrets engine (A) is correct because it dynamically generates X.509 certificates and private keys on demand from configured roles, issuing short-lived credentials rather than storing static ones. The AWS secrets engine (C) is correct because it dynamically generates AWS IAM credentials (access key ID and secret access key) or STS tokens based on IAM policies, providing on-demand, lease-bound cloud credentials. The Database secrets engine (E) is correct because it dynamically creates unique database usernames and passwords for supported databases (e.g., MySQL, PostgreSQL) tied to a lease, eliminating shared static credentials. The KV v2 secrets engine (B) is not appropriate here because it only stores and versions static key-value secrets and does not generate credentials. The Transit secrets engine (D) is not appropriate because it provides encryption-as-a-service (encrypt/decrypt/sign/verify) and does not issue credentials for external systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PKI secrets engine

    Why this is correct

    The PKI secrets engine dynamically issues X.509 certificates with short lifetimes, satisfying the requirement for on-demand credentials for external systems. Unlike static secrets, each certificate is generated per request and expires automatically, removing manual rotation. It therefore directly addresses dynamic credential generation for external endpoints.

  • ✗

    KV v2 secrets engine

    Why it's wrong here

    KV v2 stores static key-value pairs; it never contacts an external system to mint credentials, so it cannot satisfy dynamic generation. It is tempting because it is Vault's default engine for holding secrets, and it would be the right choice when the requirement is simply storing and versioning pre-existing credentials rather than issuing short-lived ones.

  • ✓

    AWS secrets engine

    Why this is correct

    The AWS secrets engine dynamically generates IAM credentials on demand, issuing short-lived access keys tied to an assumed role rather than storing static secrets. This directly satisfies the stem's requirement for dynamic credential generation for external systems, since AWS is external to Vault and credentials expire automatically after their lease period.

  • ✗

    Transit secrets engine

    Why it's wrong here

    Transit performs encryption-as-a-service, handling cryptographic operations on data without generating credentials for external systems. It is tempting because it is a core Vault engine, and it would be correct when the requirement is centralised encryption, signing or key derivation rather than issuing database or cloud credentials.

  • ✓

    Database secrets engine

    Why this is correct

    The database secrets engine dynamically generates short-lived database credentials on demand, eliminating static passwords. It satisfies the stem's requirement for external-system credential generation by creating unique, time-bound users per request, then revoking them automatically on lease expiry. This directly addresses the constraint of dynamic credential issuance rather than static secret storage.

About these practice questions

Courseiva writes every VA-003 question from scratch — 366 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.